<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions
	xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd"
	xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5"
	xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
	xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5"
	xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
      <oval:product_name>Marcus OVAL Generator</oval:product_name>
      <oval:schema_version>5.5</oval:schema_version>
      <oval:timestamp>2012-05-19T04:05:49</oval:timestamp>
  </generator>
  <definitions>
<definition id="oval:org.opensuse.security:def:20040801" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0801</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2004-0801" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0801" source="CVE"/>
	<description>
	Unknown vulnerability in foomatic-rip in Foomatic before 3.0.2 allows local users or remote attackers with access to CUPS to execute arbitrary commands.
	</description>
 </metadata>
<!-- 997ad18a4f4706edd462cae443e492f0 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009070056" comment="hplip-hpijs less than 3.9.8-3.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070057" comment="hplip less than 3.9.8-3.7.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20054881" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-4881</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2005-4881" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4881" source="CVE"/>
	<description>
	The netlink subsystem in the Linux kernel 2.4.x before 2.4.37.6 and 2.6.x before 2.6.13-rc1 does not initialize certain padding fields in structures, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors, related to the (1) tc_fill_qdisc, (2) tcf_fill_node, (3) neightbl_fill_info, (4) neightbl_fill_param_info, (5) neigh_fill_info, (6) rtnetlink_fill_ifinfo, (7) rtnetlink_fill_iwinfo, (8) vif_delete, (9) ipmr_destroy_unres, (10) ipmr_cache_alloc_unres, (11) ipmr_cache_resolve, (12) inet6_fill_ifinfo, (13) tca_get_fill, (14) tca_action_flush, (15) tcf_add_notify, (16) tc_dump_action, (17) cbq_dump_police, (18) __nlmsg_put, (19) __rta_fill, (20) __rta_reserve, (21) inet6_fill_prefix, (22) rsvp_dump, and (23) cbq_dump_ovl functions.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 114b9cf953db7d4a1a91082495d33414 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056549" comment="kernel-default-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056511" comment="kernel-xen-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056550" comment="kernel-xen-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056512" comment="kernel-xen less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- a3c4f0428e25dca1993e5018e76d6758 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056549" comment="kernel-default-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056519" comment="kernel-pae-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056552" comment="kernel-pae-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056520" comment="kernel-pae less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056511" comment="kernel-xen-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056550" comment="kernel-xen-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056512" comment="kernel-xen less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20054890" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-4890</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2005-4890" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4890" source="CVE"/>
	<description>
	** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.
	</description>
 </metadata>
<!-- 398c4e6a90a6b6fe88e0b53589b8003b -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009072288" comment="coreutils-lang less than 6.12-32.26.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009072290" comment="coreutils less than 6.12-32.26.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20067246" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2006-7246</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2006-7246" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-7246" source="CVE"/>
	<description>
	** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 470bd49885d23715755d7bb4f880b3c2 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009071988" comment="NetworkManager-glib less than 0.7.1_git20090811-3.9.9.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009071989" comment="NetworkManager-gnome less than 0.7.1-5.15.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009071990" comment="NetworkManager less than 0.7.1_git20090811-3.9.9.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009072007" comment="wpa_supplicant-gui less than 0.6.9-4.5.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009071991" comment="wpa_supplicant less than 0.6.9-4.5.4"/>
		</criteria>
	</criteria>
	<!-- c7f58cba030474918054f80ae9b9d8f5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009072967" comment="NetworkManager-gnome less than 0.7.1-5.15.11.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20067250" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2006-7250</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP2</platform>
	</affected>
	<reference ref_id="CVE-2006-7250" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-7250" source="CVE"/>
	<description>
	The mime_hdr_cmp function in crypto/asn1/asn_mime.c in OpenSSL 0.9.8t and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted S/MIME message.
	</description>
 </metadata>
<!-- 5c8a36f85c32f7d2796329c6695e45e9 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009073445" comment="libopenssl0_9_8-32bit less than 0.9.8j-0.32.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009073447" comment="libopenssl0_9_8 less than 0.9.8j-0.32.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009073449" comment="openssl less than 0.9.8j-0.32.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20070045" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2007-0045</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2007-0045" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0045" source="CVE"/>
	<description>
	Multiple cross-site scripting (XSS) vulnerabilities in Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, for Mozilla Firefox, Microsoft Internet Explorer 6 SP1, Google Chrome, Opera 8.5.4 build 770, and Opera 9.10.8679 on Windows allow remote attackers to inject arbitrary JavaScript and conduct other attacks via a .pdf URL with a javascript: or res: URI with (1) FDF, (2) XML, and (3) XFDF AJAX parameters, or (4) an arbitrarily named name=URI anchor identifier, aka "Universal XSS (UXSS)."
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- ce38af327adaced851154dd69b821772 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055730" comment="acroread_ja less than 8.1.7-0.1.1"/>
	</criteria>
	<!-- da542e714548e7606e770f4fa3ce65f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055727" comment="acroread less than 8.1.7-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20070048" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2007-0048</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2007-0048" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0048" source="CVE"/>
	<description>
	Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, when used with Internet Explorer, Google Chrome, or Opera, allows remote attackers to cause a denial of service (memory consumption) via a long sequence of # (hash) characters appended to a PDF URL, related to a "cross-site scripting issue."
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- ce38af327adaced851154dd69b821772 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055730" comment="acroread_ja less than 8.1.7-0.1.1"/>
	</criteria>
	<!-- da542e714548e7606e770f4fa3ce65f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055727" comment="acroread less than 8.1.7-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20076725" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2007-6725</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2007-6725" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6725" source="CVE"/>
	<description>
	The CCITTFax decoding filter in Ghostscript 8.60, 8.61, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF file that triggers a buffer underflow in the cf_decode_2d function.
	</description>
 </metadata>
<!-- ab7a3ecdd7f2b22db74d66fd6e23832b -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032106" comment="ghostscript-fonts-other less than 8.62-32.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032107" comment="ghostscript-fonts-rus less than 8.62-32.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032108" comment="ghostscript-fonts-std less than 8.62-32.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032109" comment="ghostscript-library less than 8.62-32.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032110" comment="ghostscript-omni less than 8.62-32.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032111" comment="ghostscript-x11 less than 8.62-32.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032112" comment="libgimpprint less than 4.2.7-32.25.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20083443" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-3443</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-3443" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3443" source="CVE"/>
	<description>
	The regular expression engine (regex.c) in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows remote attackers to cause a denial of service (infinite loop and crash) via multiple long requests to a Ruby socket, related to memory allocation failure, and as demonstrated against Webrick.
	</description>
 </metadata>
<!-- c8369586b31bf86da2231acd00ad8f78 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053194" comment="ruby less than 1.8.7.p72-5.22.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20083655" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-3655</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-3655" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3655" source="CVE"/>
	<description>
	Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not properly restrict access to critical variables and methods at various safe levels, which allows context-dependent attackers to bypass intended access restrictions via (1) untrace_var, (2) $PROGRAM_NAME, and (3) syslog at safe level 4, and (4) insecure methods at safe levels 1 through 3.
	</description>
 </metadata>
<!-- c8369586b31bf86da2231acd00ad8f78 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053194" comment="ruby less than 1.8.7.p72-5.22.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20083656" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-3656</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-3656" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3656" source="CVE"/>
	<description>
	Algorithmic complexity vulnerability in the WEBrick::HTTPUtils.split_header_value function in WEBrick::HTTP::DefaultFileHandler in WEBrick in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted HTTP request that is processed by a backtracking regular expression.
	</description>
 </metadata>
<!-- c8369586b31bf86da2231acd00ad8f78 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053194" comment="ruby less than 1.8.7.p72-5.22.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20083657" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-3657</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-3657" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3657" source="CVE"/>
	<description>
	The dl module in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not check "taintness" of inputs, which allows context-dependent attackers to bypass safe levels and execute dangerous functions by accessing a library using DL.dlopen.
	</description>
 </metadata>
<!-- c8369586b31bf86da2231acd00ad8f78 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053194" comment="ruby less than 1.8.7.p72-5.22.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20083790" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-3790</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-3790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3790" source="CVE"/>
	<description>
	The REXML module in Ruby 1.8.6 through 1.8.6-p287, 1.8.7 through 1.8.7-p72, and 1.9 allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML document with recursively nested entities, aka an "XML entity explosion."
	</description>
 </metadata>
<!-- c8369586b31bf86da2231acd00ad8f78 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053194" comment="ruby less than 1.8.7.p72-5.22.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20083834" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-3834</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2008-3834" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3834" source="CVE"/>
	<description>
	The dbus_signature_validate function in the D-bus library (libdbus) before 1.2.4 allows remote attackers to cause a denial of service (application abort) via a message containing a malformed signature, which triggers a failed assertion error.
	</description>
 </metadata>
<!-- 54eee4e87a0d78b170de796964bdfc46 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009067850" comment="dbus-1-32bit less than 1.2.10-3.17.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009067851" comment="dbus-1-x11 less than 1.2.10-3.17.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009067853" comment="dbus-1 less than 1.2.10-3.17.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20083905" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-3905</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-3905" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3905" source="CVE"/>
	<description>
	resolv.rb in Ruby 1.8.5 and earlier, 1.8.6 before 1.8.6-p287, 1.8.7 before 1.8.7-p72, and 1.9 r18423 and earlier uses sequential transaction IDs and constant source ports for DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447.
	</description>
 </metadata>
<!-- c8369586b31bf86da2231acd00ad8f78 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053194" comment="ruby less than 1.8.7.p72-5.22.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20083916" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-3916</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2008-3916" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3916" source="CVE"/>
	<description>
	Heap-based buffer overflow in the strip_escapes function in signal.c in GNU ed before 1.0 allows context-dependent or user-assisted attackers to execute arbitrary code via a long filename.  NOTE: since ed itself does not typically run with special privileges, this issue only crosses privilege boundaries when ed is invoked as a third-party component.
	</description>
 </metadata>
<!-- db1a7237caafa1fc9b7316fc8540dbaf -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009065506" comment="ed less than 0.2-1001.30.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20084311" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-4311</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-4311" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4311" source="CVE"/>
	<description>
	The default configuration of system.conf in D-Bus (aka DBus) before 1.2.6 omits the send_type attribute in certain rules, which allows local users to bypass intended access restrictions by (1) sending messages, related to send_requested_reply; and possibly (2) receiving messages, related to receive_requested_reply.
	</description>
 </metadata>
<!-- 9743b3e1bf7258cd935101dc92d337cb -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032116" comment="dbus-1-32bit less than 1.2.10-3.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032118" comment="dbus-1 less than 1.2.10-3.9.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20084316" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-4316</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-4316" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4316" source="CVE"/>
	<description>
	Multiple integer overflows in glib/gbase64.c in GLib before 2.20 allow context-dependent attackers to execute arbitrary code via a long string that is converted either (1) from or (2) to a base64 representation.
	</description>
 </metadata>
<!-- 5e189989237df74cc60cee5f9491bdc4 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009050748" comment="glib2-devel less than 2.18.2-7.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032120" comment="glib2-lang less than 2.18.2-7.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032121" comment="glib2 less than 2.18.2-7.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032122" comment="libgio-2_0-0-32bit less than 2.18.2-7.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032124" comment="libgio-2_0-0 less than 2.18.2-7.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009050749" comment="libgio-fam less than 2.18.2-7.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032125" comment="libglib-2_0-0-32bit less than 2.18.2-7.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032127" comment="libglib-2_0-0 less than 2.18.2-7.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032128" comment="libgmodule-2_0-0-32bit less than 2.18.2-7.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032130" comment="libgmodule-2_0-0 less than 2.18.2-7.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032131" comment="libgobject-2_0-0-32bit less than 2.18.2-7.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032133" comment="libgobject-2_0-0 less than 2.18.2-7.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032134" comment="libgthread-2_0-0-32bit less than 2.18.2-7.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032136" comment="libgthread-2_0-0 less than 2.18.2-7.7.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20084456" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-4456</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-4456" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4456" source="CVE"/>
	<description>
	Cross-site scripting (XSS) vulnerability in the command-line client in MySQL 5.0.26 through 5.0.45, and other versions including versions later than 5.0.45, when the --html option is enabled, allows attackers to inject arbitrary web script or HTML by placing it in a database cell, which might be accessed by this client when composing an HTML document.  NOTE: as of 20081031, the issue has not been fixed in MySQL 5.0.67.
	</description>
 </metadata>
<!-- 6b4ffc010711f4a40d2054f5fc473cc7 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009054286" comment="libmysqlclient15-32bit less than 5.0.67-13.16.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054288" comment="libmysqlclient15 less than 5.0.67-13.16.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054294" comment="libmysqlclient_r15-32bit less than 5.0.67-13.16.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054289" comment="libmysqlclient_r15 less than 5.0.67-13.16.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054291" comment="mysql-client less than 5.0.67-13.16.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054292" comment="mysql less than 5.0.67-13.16.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20084546" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-4546</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2008-4546" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4546" source="CVE"/>
	<description>
	Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows remote web servers to cause a denial of service (NULL pointer dereference and browser crash) by returning a different response when an HTTP request is sent a second time, as demonstrated by two responses that provide SWF files with different SWF version numbers.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 9fed1ac7d6ac263f8b42cb8e24927e67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
	<!-- dc5e2e29ebe98d9444b78ef5643bf4f1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20084776" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-4776</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2008-4776" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4776" source="CVE"/>
	<description>
	libgadu before 1.8.2 allows remote servers to cause a denial of service (crash) via a contact description with a large length, which triggers a buffer over-read.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2fb2523f388f4f507725821f053b7b30 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009065196" comment="kdenetwork4-filesharing less than 4.3.5-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065197" comment="kget less than 4.3.5-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065198" comment="kopete less than 4.3.5-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065204" comment="kppp less than 4.3.5-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065199" comment="krdc less than 4.3.5-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065200" comment="krfb less than 4.3.5-0.4.1"/>
		</criteria>
	</criteria>
	<!-- fb44440d868c7c3b0efae521994af0a4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009065165" comment="kde4-kget less than 4.1.3-7.9.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065166" comment="kde4-knewsticker less than 4.1.3-7.9.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065167" comment="kde4-kopete less than 4.1.3-7.9.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065186" comment="kde4-kppp less than 4.1.3-7.9.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065168" comment="kde4-krdc less than 4.1.3-7.9.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065169" comment="kde4-krfb less than 4.1.3-7.9.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065170" comment="kdenetwork4-filesharing less than 4.1.3-7.9.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20084989" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-4989</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-4989" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4989" source="CVE"/>
	<description>
	The _gnutls_x509_verify_certificate function in lib/x509/verify.c in libgnutls in GnuTLS before 2.6.1 trusts certificate chains in which the last certificate is an arbitrary trusted, self-signed certificate, which allows man-in-the-middle attackers to insert a spoofed certificate for any Distinguished Name (DN).
	</description>
 </metadata>
<!-- e280121d3f2f9a8553bbbfef193309bf -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032137" comment="gnutls less than 2.4.1-24.16.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032138" comment="libgnutls26-32bit less than 2.4.1-24.16.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032140" comment="libgnutls26 less than 2.4.1-24.16.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20085077" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-5077</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2008-5077" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5077" source="CVE"/>
	<description>
	OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys.
	</description>
 </metadata>
<!-- 79f88b4366b267744a8056a0b1669fb3 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009069583" comment="compat-openssl097g-32bit less than 0.9.7g-146.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009069584" comment="compat-openssl097g less than 0.9.7g-146.20.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20085718" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-5718</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-5718" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5718" source="CVE"/>
	<description>
	The papd daemon in Netatalk before 2.0.4-beta2, when using certain variables in a pipe command for the print file, allows remote attackers to execute arbitrary commands via shell metacharacters in a print request, as demonstrated using a crafted Title.
	</description>
 </metadata>
<!-- 78484450b4ae093fcf8a006e0a44521d -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009051556" comment="netatalk less than 2.0.3-1.4"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20085913" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-5913</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2008-5913" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5913" source="CVE"/>
	<description>
	The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses a random number generator that is seeded only once per browser session, which makes it easier for remote attackers to track a user, or trick a user into acting upon a spoofed pop-up message, by calculating the seed value, related to a "temporary footprint" and an "in-session phishing attack."
	</description>
 </metadata>
<!-- f9b2b1aaa535612c1bff26161e7cb381 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009061668" comment="MozillaFirefox-translations less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061192" comment="MozillaFirefox less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070643" comment="mozilla-xulrunner191-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070716" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070644" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070718" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061669" comment="mozilla-xulrunner191-translations less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061670" comment="mozilla-xulrunner191 less than 1.9.1.10-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20086218" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-6218</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2008-6218" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-6218" source="CVE"/>
	<description>
	Memory leak in the png_handle_tEXt function in pngrutil.c in libpng before 1.2.33 rc02 and 1.4.0 beta36 allows context-dependent attackers to cause a denial of service (memory exhaustion) via a crafted PNG file.
	</description>
 </metadata>
<!-- 5b292f48bbbe6202317380a339315fad -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009069826" comment="libpng-devel less than 1.2.31-5.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009069805" comment="libpng12-0-32bit less than 1.2.31-5.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009069807" comment="libpng12-0 less than 1.2.31-5.25.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20086514" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-6514</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-6514" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-6514" source="CVE"/>
	<description>
	The Expo plugin in Compiz Fusion 0.7.8 allows local users with physical access to drag the screen saver aside and access the locked desktop by using Expo mouse shortcuts, a related issue to CVE-2007-3920.
	</description>
 </metadata>
<!-- 3255413f6c35a42c4c6584634a87df94 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059198" comment="compiz-fusion-plugins-main less than 0.7.8-10.14.2"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20086679" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-6679</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-6679" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-6679" source="CVE"/>
	<description>
	Buffer overflow in the BaseFont writer module in Ghostscript 8.62, and possibly other versions, allows remote attackers to cause a denial of service (ps2pdf crash) and possibly execute arbitrary code via a crafted Postscript file.
	</description>
 </metadata>
<!-- ab7a3ecdd7f2b22db74d66fd6e23832b -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032106" comment="ghostscript-fonts-other less than 8.62-32.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032107" comment="ghostscript-fonts-rus less than 8.62-32.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032108" comment="ghostscript-fonts-std less than 8.62-32.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032109" comment="ghostscript-library less than 8.62-32.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032110" comment="ghostscript-omni less than 8.62-32.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032111" comment="ghostscript-x11 less than 8.62-32.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032112" comment="libgimpprint less than 4.2.7-32.25.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20086680" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-6680</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-6680" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-6680" source="CVE"/>
	<description>
	libclamav/pe.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (crash) via a crafted EXE file that triggers a divide-by-zero error.
	</description>
 </metadata>
<!-- e036f8c1ee8c76653c4e246982056c02 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032190" comment="clamav less than 0.95-0.2.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20087159" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-7159</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-7159" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-7159" source="CVE"/>
	<description>
	The silc_asn1_encoder function in lib/silcasn1/silcasn1_encode.c in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.8 allows remote attackers to overwrite a stack location and possibly execute arbitrary code via a crafted OID value, related to incorrect use of a %lu format string.
	</description>
 </metadata>
<!-- 8a79c9ab49ac9cd9f5e479fbeeb03404 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054843" comment="silc-toolkit less than 1.1.7-7.23.2"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20087160" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-7160</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-7160" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-7160" source="CVE"/>
	<description>
	The silc_http_server_parse function in lib/silchttp/silchttpserver.c in the internal HTTP server in silcd in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.9 allows remote attackers to overwrite a stack location and possibly execute arbitrary code via a crafted Content-Length header, related to incorrect use of a %lu format string.
	</description>
 </metadata>
<!-- 8a79c9ab49ac9cd9f5e479fbeeb03404 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054843" comment="silc-toolkit less than 1.1.7-7.23.2"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20087247" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-7247</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-7247" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-7247" source="CVE"/>
	<description>
	sql/sql_table.cc in MySQL 5.0.x through 5.0.88, 5.1.x through 5.1.41, and 6.0 before 6.0.9-alpha, when the data home directory contains a symlink to a different filesystem, allows remote authenticated users to bypass intended access restrictions by calling CREATE TABLE with a (1) DATA DIRECTORY or (2) INDEX DIRECTORY argument referring to a subdirectory that requires following this symlink.
	</description>
 </metadata>
<!-- 920486ef8624fdf8d628849a50561aa6 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060043" comment="libmysqlclient15-32bit less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060045" comment="libmysqlclient15 less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060134" comment="libmysqlclient_r15-32bit less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060046" comment="libmysqlclient_r15 less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060048" comment="mysql-client less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060049" comment="mysql less than 5.0.67-13.17.7"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20087270" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-7270</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2008-7270" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-7270" source="CVE"/>
	<description>
	OpenSSL before 0.9.8j, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the use of a disabled cipher via vectors involving sniffing network traffic to discover a session identifier, a different vulnerability than CVE-2010-4180.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- b2240bd1cc1b86d466bf4511cb5287fd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064298" comment="libopenssl0_9_8-32bit less than 0.9.8h-30.22.22.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064300" comment="libopenssl0_9_8 less than 0.9.8h-30.22.22.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064302" comment="openssl less than 0.9.8h-30.22.22.1"/>
		</criteria>
	</criteria>
	<!-- d4275070c6d35e2cd6ce91e877bc91e7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064303" comment="libopenssl0_9_8-32bit less than 0.9.8h-30.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064305" comment="libopenssl0_9_8 less than 0.9.8h-30.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064307" comment="openssl less than 0.9.8h-30.28.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090037" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0037</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0037" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0037" source="CVE"/>
	<description>
	The redirect implementation in curl and libcurl 5.11 through 7.19.3, when CURLOPT_FOLLOWLOCATION is enabled, accepts arbitrary Location values, which might allow remote HTTP servers to (1) trigger arbitrary requests to intranet servers, (2) read or overwrite arbitrary files via a redirect to a file: URL, or (3) execute arbitrary commands via a redirect to an scp: URL.
	</description>
 </metadata>
<!-- 4b5434075393861d396c976f9f14744f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032191" comment="curl less than 7.19.0-11.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032192" comment="libcurl4-32bit less than 7.19.0-11.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032194" comment="libcurl4 less than 7.19.0-11.21.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090040" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0040</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0040" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0040" source="CVE"/>
	<description>
	The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file that triggers a free of an uninitialized pointer in (1) the png_read_png function, (2) pCAL chunk handling, or (3) setup of 16-bit gamma tables.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 533cd9a6d7b1cabc1aceb3ab6070dba5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009051705" comment="libpng-devel less than 1.2.31-5.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032195" comment="libpng12-0-32bit less than 1.2.31-5.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032197" comment="libpng12-0 less than 1.2.31-5.11.1"/>
		</criteria>
	</criteria>
	<!-- 64ea6139df28e916c5f627ff6f4b6b83 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032198" comment="MozillaFirefox-translations less than 3.0.7-1.1.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032199" comment="MozillaFirefox less than 3.0.7-1.1.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032200" comment="mozilla-xulrunner190-32bit less than 1.9.0.7-1.1.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009051707" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.7-1.1.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032201" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.7-1.1.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009051709" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.7-1.1.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032202" comment="mozilla-xulrunner190-translations less than 1.9.0.7-1.1.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032204" comment="mozilla-xulrunner190 less than 1.9.0.7-1.1.4"/>
		</criteria>
	</criteria>
	<!-- 652fce5693522ba240a0007464788f7d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009051712" comment="libpng-devel less than 1.2.31-7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032205" comment="libpng12-0-32bit less than 1.2.31-7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032207" comment="libpng12-0 less than 1.2.31-7.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090114" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0114</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0114" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0114" source="CVE"/>
	<description>
	Unspecified vulnerability in the Settings Manager in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87, and possibly other versions, allows remote attackers to trick a user into visiting an arbitrary URL via unknown vectors, related to "a potential Clickjacking issue variant."
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 114396a426b755abae95f7d91f8ba5b8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009051789" comment="flash-player less than 10.0.22.87-1.1"/>
	</criteria>
	<!-- 92b70d704f9216e04ab21e4e394c9329 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009051791" comment="flash-player less than 10.0.22.87-1.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090146" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0146</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0146" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0146" source="CVE"/>
	<description>
	Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2SymbolDict::setBitmap and (2) JBIG2Stream::readSymbolDictSeg.
	</description>
 </metadata>
<!-- f27d99aa7f35ddbc6bc5e4ac681ee974 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032208" comment="libpoppler4 less than 0.10.1-1.30.5"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090147" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0147</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0147" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0147" source="CVE"/>
	<description>
	Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2Stream::readSymbolDictSeg, (2) JBIG2Stream::readSymbolDictSeg, and (3) JBIG2Stream::readGenericBitmap.
	</description>
 </metadata>
<!-- f27d99aa7f35ddbc6bc5e4ac681ee974 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032208" comment="libpoppler4 less than 0.10.1-1.30.5"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090153" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0153</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0153" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0153" source="CVE"/>
	<description>
	International Components for Unicode (ICU) 4.0, 3.6, and other 3.x versions, as used in Apple Mac OS X 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Fedora 9 and 10, and possibly other operating systems, does not properly handle invalid byte sequences during Unicode conversion, which might allow remote attackers to conduct cross-site scripting (XSS) attacks.
	</description>
 </metadata>
<!-- 563cdc75b14ef0a824e09ace54d4dfac -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053708" comment="icu less than 4.0-7.22.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053693" comment="libicu less than 4.0-7.22.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090159" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0159</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0159" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0159" source="CVE"/>
	<description>
	Stack-based buffer overflow in the cookedprint function in ntpq/ntpq.c in ntpq in NTP before 4.2.4p7-RC2 allows remote NTP servers to execute arbitrary code via a crafted response.
	</description>
 </metadata>
<!-- d95ed4c45d984fda65f18722242769a5 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032209" comment="ntp-doc less than 4.2.4p6-1.17.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032210" comment="ntp less than 4.2.4p6-1.17.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090163" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0163</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0163" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0163" source="CVE"/>
	<description>
	Integer overflow in the TIFF image decoding routines in CUPS 1.3.9 and earlier allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a crafted TIFF image, which is not properly handled by the (1) _cupsImageReadTIFF function in the imagetops filter and (2) imagetoraster filter, leading to a heap-based buffer overflow.
	</description>
 </metadata>
<!-- 22d7a0746f9c204f5ecc1395385739f7 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032211" comment="cups-client less than 1.3.9-8.15.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032212" comment="cups-libs-32bit less than 1.3.9-8.15.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032214" comment="cups-libs less than 1.3.9-8.15.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032215" comment="cups less than 1.3.9-8.15.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090165" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0165</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0165" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0165" source="CVE"/>
	<description>
	Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, as used in Poppler and other products, when running on Mac OS X, has unspecified impact, related to "g*allocn."
	</description>
 </metadata>
<!-- f27d99aa7f35ddbc6bc5e4ac681ee974 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032208" comment="libpoppler4 less than 0.10.1-1.30.5"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090166" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0166</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0166" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0166" source="CVE"/>
	<description>
	The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a free of uninitialized memory.
	</description>
 </metadata>
<!-- f27d99aa7f35ddbc6bc5e4ac681ee974 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032208" comment="libpoppler4 less than 0.10.1-1.30.5"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090186" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0186</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0186" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0186" source="CVE"/>
	<description>
	Integer overflow in libsndfile 1.0.18, as used in Winamp and other products, allows context-dependent attackers to execute arbitrary code via crafted description chunks in a CAF audio file, leading to a heap-based buffer overflow.
	</description>
 </metadata>
<!-- b9a52ff0fc093ef2c5d7b985b5d8445a -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032216" comment="libsndfile-32bit less than 1.0.17-172.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032218" comment="libsndfile less than 1.0.17-172.13.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090193" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0193</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0193" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0193" source="CVE"/>
	<description>
	Heap-based buffer overflow in Adobe Acrobat Reader 9 before 9.1, 8 before 8.1.4, and 7 before 7.1.1 allows remote attackers to execute arbitrary code via a PDF file with a malformed JBIG2 symbol dictionary segment, a different vulnerability than CVE-2009-1061 and CVE-2009-1062.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 65a9509d5ccaa91e4e59902a72dca480 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009051906" comment="acroread_ja less than 8.1.4-0.1.1"/>
	</criteria>
	<!-- a04133df2de1f0d9def205bcbd21d423 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009051908" comment="acroread less than 8.1.4-0.9.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090196" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0196</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0196" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0196" source="CVE"/>
	<description>
	Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol_dict.c) in the JBIG2 decoding library (jbig2dec) in Ghostscript 8.64, and probably earlier versions, allows remote attackers to execute arbitrary code via a PDF file with a JBIG2 symbol dictionary segment with a large run length value.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 821fdfa281de6b75cdc24c1e4f935e7e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032219" comment="ghostscript-fonts-other less than 8.62-32.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032220" comment="ghostscript-fonts-rus less than 8.62-32.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032221" comment="ghostscript-fonts-std less than 8.62-32.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032222" comment="ghostscript-library less than 8.62-32.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032223" comment="ghostscript-omni less than 8.62-32.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032224" comment="ghostscript-x11 less than 8.62-32.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032225" comment="libgimpprint less than 4.2.7-32.23.1"/>
		</criteria>
	</criteria>
	<!-- ab7a3ecdd7f2b22db74d66fd6e23832b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032106" comment="ghostscript-fonts-other less than 8.62-32.25.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032107" comment="ghostscript-fonts-rus less than 8.62-32.25.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032108" comment="ghostscript-fonts-std less than 8.62-32.25.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032109" comment="ghostscript-library less than 8.62-32.25.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032110" comment="ghostscript-omni less than 8.62-32.25.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032111" comment="ghostscript-x11 less than 8.62-32.25.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032112" comment="libgimpprint less than 4.2.7-32.25.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090198" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0198</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0198" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0198" source="CVE"/>
	<description>
	Heap-based buffer overflow in the JBIG2 filter in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted PDF file that contains JBIG2 text region segments with Huffman encoding.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- afe186fd3bad60212fb8d8d8b51e1454 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009051914" comment="acroread less than 8.1.6-0.1.1"/>
	</criteria>
	<!-- d585d11ae44add7af85ddd5eccb6818d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054066" comment="acroread_ja less than 8.1.6-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090200" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0200</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0200" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0200" source="CVE"/>
	<description>
	Integer underflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrary code via crafted records in the document table of a Word document, leading to a heap-based buffer overflow.
	</description>
 </metadata>
<!-- a9bd052827d214256bfa24cd42e76d80 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009054735" comment="OpenOffice_org-LanguageTool-de less than 0.9.9-2.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054736" comment="OpenOffice_org-LanguageTool-en less than 0.9.9-2.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054737" comment="OpenOffice_org-LanguageTool-es less than 0.9.9-2.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054738" comment="OpenOffice_org-LanguageTool-fr less than 0.9.9-2.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054739" comment="OpenOffice_org-LanguageTool-it less than 0.9.9-2.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054740" comment="OpenOffice_org-LanguageTool-nl less than 0.9.9-2.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054741" comment="OpenOffice_org-LanguageTool-pl less than 0.9.9-2.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054742" comment="OpenOffice_org-LanguageTool-sv less than 0.9.9-2.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054743" comment="OpenOffice_org-LanguageTool less than 0.9.9-2.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054744" comment="OpenOffice_org-base-drivers-postgresql less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054745" comment="OpenOffice_org-base-extensions less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054654" comment="OpenOffice_org-base less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054746" comment="OpenOffice_org-calc-extensions less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054657" comment="OpenOffice_org-calc less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054659" comment="OpenOffice_org-components less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054747" comment="OpenOffice_org-draw-extensions less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054660" comment="OpenOffice_org-draw less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054662" comment="OpenOffice_org-filters-optional less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054663" comment="OpenOffice_org-filters less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054664" comment="OpenOffice_org-gnome less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054665" comment="OpenOffice_org-help-ar less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054666" comment="OpenOffice_org-help-cs less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054667" comment="OpenOffice_org-help-da less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054668" comment="OpenOffice_org-help-de less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054669" comment="OpenOffice_org-help-en-GB less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054670" comment="OpenOffice_org-help-en-US-devel less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054671" comment="OpenOffice_org-help-en-US less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054672" comment="OpenOffice_org-help-es less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054673" comment="OpenOffice_org-help-fr less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054748" comment="OpenOffice_org-help-gu-IN less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054749" comment="OpenOffice_org-help-hi-IN less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054674" comment="OpenOffice_org-help-hu less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054675" comment="OpenOffice_org-help-it less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054676" comment="OpenOffice_org-help-ja less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054750" comment="OpenOffice_org-help-ko less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054677" comment="OpenOffice_org-help-nl less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054678" comment="OpenOffice_org-help-pl less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054679" comment="OpenOffice_org-help-pt-BR less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054680" comment="OpenOffice_org-help-pt less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054681" comment="OpenOffice_org-help-ru less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054682" comment="OpenOffice_org-help-sv less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054683" comment="OpenOffice_org-help-zh-CN less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054684" comment="OpenOffice_org-help-zh-TW less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054685" comment="OpenOffice_org-icon-themes less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054751" comment="OpenOffice_org-impress-extensions less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054687" comment="OpenOffice_org-impress less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054688" comment="OpenOffice_org-kde less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054689" comment="OpenOffice_org-l10n-af less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054690" comment="OpenOffice_org-l10n-ar less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054691" comment="OpenOffice_org-l10n-ca less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054692" comment="OpenOffice_org-l10n-cs less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054693" comment="OpenOffice_org-l10n-da less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054694" comment="OpenOffice_org-l10n-de less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054695" comment="OpenOffice_org-l10n-el less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054696" comment="OpenOffice_org-l10n-en-GB less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054697" comment="OpenOffice_org-l10n-es less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054699" comment="OpenOffice_org-l10n-extras less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054700" comment="OpenOffice_org-l10n-fi less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054701" comment="OpenOffice_org-l10n-fr less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054752" comment="OpenOffice_org-l10n-gu-IN less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054753" comment="OpenOffice_org-l10n-hi-IN less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054702" comment="OpenOffice_org-l10n-hu less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054703" comment="OpenOffice_org-l10n-it less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054704" comment="OpenOffice_org-l10n-ja less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054754" comment="OpenOffice_org-l10n-ko less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054705" comment="OpenOffice_org-l10n-nb less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054706" comment="OpenOffice_org-l10n-nl less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054707" comment="OpenOffice_org-l10n-nn less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054708" comment="OpenOffice_org-l10n-pl less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054709" comment="OpenOffice_org-l10n-pt-BR less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054710" comment="OpenOffice_org-l10n-pt less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054711" comment="OpenOffice_org-l10n-ru less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054712" comment="OpenOffice_org-l10n-sk less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054713" comment="OpenOffice_org-l10n-sv less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054714" comment="OpenOffice_org-l10n-xh less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054715" comment="OpenOffice_org-l10n-zh-CN less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054716" comment="OpenOffice_org-l10n-zh-TW less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054717" comment="OpenOffice_org-l10n-zu less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054719" comment="OpenOffice_org-libs-core less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054721" comment="OpenOffice_org-libs-extern less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054723" comment="OpenOffice_org-libs-gui less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054724" comment="OpenOffice_org-mailmerge less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054725" comment="OpenOffice_org-math less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054726" comment="OpenOffice_org-mono less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054727" comment="OpenOffice_org-officebean less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054728" comment="OpenOffice_org-pyuno less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054731" comment="OpenOffice_org-ure less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054755" comment="OpenOffice_org-writer-extensions less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054733" comment="OpenOffice_org-writer less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054734" comment="OpenOffice_org less than 3.1.1.1-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090201" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0201</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0201" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0201" source="CVE"/>
	<description>
	Heap-based buffer overflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrary code via unspecified records in a crafted Word document, related to "table parsing."
	</description>
 </metadata>
<!-- a9bd052827d214256bfa24cd42e76d80 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009054735" comment="OpenOffice_org-LanguageTool-de less than 0.9.9-2.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054736" comment="OpenOffice_org-LanguageTool-en less than 0.9.9-2.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054737" comment="OpenOffice_org-LanguageTool-es less than 0.9.9-2.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054738" comment="OpenOffice_org-LanguageTool-fr less than 0.9.9-2.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054739" comment="OpenOffice_org-LanguageTool-it less than 0.9.9-2.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054740" comment="OpenOffice_org-LanguageTool-nl less than 0.9.9-2.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054741" comment="OpenOffice_org-LanguageTool-pl less than 0.9.9-2.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054742" comment="OpenOffice_org-LanguageTool-sv less than 0.9.9-2.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054743" comment="OpenOffice_org-LanguageTool less than 0.9.9-2.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054744" comment="OpenOffice_org-base-drivers-postgresql less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054745" comment="OpenOffice_org-base-extensions less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054654" comment="OpenOffice_org-base less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054746" comment="OpenOffice_org-calc-extensions less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054657" comment="OpenOffice_org-calc less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054659" comment="OpenOffice_org-components less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054747" comment="OpenOffice_org-draw-extensions less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054660" comment="OpenOffice_org-draw less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054662" comment="OpenOffice_org-filters-optional less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054663" comment="OpenOffice_org-filters less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054664" comment="OpenOffice_org-gnome less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054665" comment="OpenOffice_org-help-ar less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054666" comment="OpenOffice_org-help-cs less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054667" comment="OpenOffice_org-help-da less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054668" comment="OpenOffice_org-help-de less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054669" comment="OpenOffice_org-help-en-GB less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054670" comment="OpenOffice_org-help-en-US-devel less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054671" comment="OpenOffice_org-help-en-US less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054672" comment="OpenOffice_org-help-es less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054673" comment="OpenOffice_org-help-fr less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054748" comment="OpenOffice_org-help-gu-IN less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054749" comment="OpenOffice_org-help-hi-IN less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054674" comment="OpenOffice_org-help-hu less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054675" comment="OpenOffice_org-help-it less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054676" comment="OpenOffice_org-help-ja less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054750" comment="OpenOffice_org-help-ko less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054677" comment="OpenOffice_org-help-nl less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054678" comment="OpenOffice_org-help-pl less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054679" comment="OpenOffice_org-help-pt-BR less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054680" comment="OpenOffice_org-help-pt less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054681" comment="OpenOffice_org-help-ru less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054682" comment="OpenOffice_org-help-sv less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054683" comment="OpenOffice_org-help-zh-CN less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054684" comment="OpenOffice_org-help-zh-TW less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054685" comment="OpenOffice_org-icon-themes less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054751" comment="OpenOffice_org-impress-extensions less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054687" comment="OpenOffice_org-impress less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054688" comment="OpenOffice_org-kde less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054689" comment="OpenOffice_org-l10n-af less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054690" comment="OpenOffice_org-l10n-ar less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054691" comment="OpenOffice_org-l10n-ca less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054692" comment="OpenOffice_org-l10n-cs less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054693" comment="OpenOffice_org-l10n-da less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054694" comment="OpenOffice_org-l10n-de less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054695" comment="OpenOffice_org-l10n-el less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054696" comment="OpenOffice_org-l10n-en-GB less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054697" comment="OpenOffice_org-l10n-es less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054699" comment="OpenOffice_org-l10n-extras less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054700" comment="OpenOffice_org-l10n-fi less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054701" comment="OpenOffice_org-l10n-fr less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054752" comment="OpenOffice_org-l10n-gu-IN less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054753" comment="OpenOffice_org-l10n-hi-IN less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054702" comment="OpenOffice_org-l10n-hu less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054703" comment="OpenOffice_org-l10n-it less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054704" comment="OpenOffice_org-l10n-ja less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054754" comment="OpenOffice_org-l10n-ko less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054705" comment="OpenOffice_org-l10n-nb less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054706" comment="OpenOffice_org-l10n-nl less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054707" comment="OpenOffice_org-l10n-nn less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054708" comment="OpenOffice_org-l10n-pl less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054709" comment="OpenOffice_org-l10n-pt-BR less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054710" comment="OpenOffice_org-l10n-pt less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054711" comment="OpenOffice_org-l10n-ru less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054712" comment="OpenOffice_org-l10n-sk less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054713" comment="OpenOffice_org-l10n-sv less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054714" comment="OpenOffice_org-l10n-xh less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054715" comment="OpenOffice_org-l10n-zh-CN less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054716" comment="OpenOffice_org-l10n-zh-TW less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054717" comment="OpenOffice_org-l10n-zu less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054719" comment="OpenOffice_org-libs-core less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054721" comment="OpenOffice_org-libs-extern less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054723" comment="OpenOffice_org-libs-gui less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054724" comment="OpenOffice_org-mailmerge less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054725" comment="OpenOffice_org-math less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054726" comment="OpenOffice_org-mono less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054727" comment="OpenOffice_org-officebean less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054728" comment="OpenOffice_org-pyuno less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054731" comment="OpenOffice_org-ure less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054755" comment="OpenOffice_org-writer-extensions less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054733" comment="OpenOffice_org-writer less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054734" comment="OpenOffice_org less than 3.1.1.1-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090217" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0217</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0217" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0217" source="CVE"/>
	<description>
	The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.2; (4) XML Security Library before 1.2.12; (5) IBM WebSphere Application Server Versions 6.0 through 6.0.2.33, 6.1 through 6.1.0.23, and 7.0 through 7.0.0.1; (6) Sun JDK and JRE Update 14 and earlier; (7) Microsoft .NET Framework 3.0 through 3.0 SP2, 3.5, and 4.0; and other products uses a parameter that defines an HMAC truncation length (HMACOutputLength) but does not require a minimum for this length, which allows attackers to spoof HMAC-based signatures and bypass authentication by specifying a truncation length with a small number of bits.
	</description>
 </metadata>
<!-- b3f5b1e481a1ae74918748c80997e6c7 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009058823" comment="OpenOffice_org-LanguageTool-de less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058824" comment="OpenOffice_org-LanguageTool-en less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058825" comment="OpenOffice_org-LanguageTool-es less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058826" comment="OpenOffice_org-LanguageTool-fr less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058827" comment="OpenOffice_org-LanguageTool-it less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058828" comment="OpenOffice_org-LanguageTool-nl less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058829" comment="OpenOffice_org-LanguageTool-pl less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058830" comment="OpenOffice_org-LanguageTool-sv less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058831" comment="OpenOffice_org-LanguageTool less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058832" comment="OpenOffice_org-base-drivers-postgresql less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058833" comment="OpenOffice_org-base-extensions less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058741" comment="OpenOffice_org-base less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058834" comment="OpenOffice_org-calc-extensions less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058744" comment="OpenOffice_org-calc less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058746" comment="OpenOffice_org-components less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058835" comment="OpenOffice_org-draw-extensions less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058747" comment="OpenOffice_org-draw less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058749" comment="OpenOffice_org-filters-optional less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058750" comment="OpenOffice_org-filters less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058751" comment="OpenOffice_org-gnome less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058752" comment="OpenOffice_org-help-ar less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058753" comment="OpenOffice_org-help-cs less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058754" comment="OpenOffice_org-help-da less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058755" comment="OpenOffice_org-help-de less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058756" comment="OpenOffice_org-help-en-GB less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058757" comment="OpenOffice_org-help-en-US-devel less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058758" comment="OpenOffice_org-help-en-US less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058759" comment="OpenOffice_org-help-es less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058760" comment="OpenOffice_org-help-fr less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058836" comment="OpenOffice_org-help-gu-IN less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058837" comment="OpenOffice_org-help-hi-IN less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058761" comment="OpenOffice_org-help-hu less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058762" comment="OpenOffice_org-help-it less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058763" comment="OpenOffice_org-help-ja less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058838" comment="OpenOffice_org-help-ko less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058764" comment="OpenOffice_org-help-nl less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058765" comment="OpenOffice_org-help-pl less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058766" comment="OpenOffice_org-help-pt-BR less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058767" comment="OpenOffice_org-help-pt less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058768" comment="OpenOffice_org-help-ru less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058769" comment="OpenOffice_org-help-sv less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058770" comment="OpenOffice_org-help-zh-CN less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058771" comment="OpenOffice_org-help-zh-TW less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058772" comment="OpenOffice_org-icon-themes less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058839" comment="OpenOffice_org-impress-extensions less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058774" comment="OpenOffice_org-impress less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058775" comment="OpenOffice_org-kde less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058776" comment="OpenOffice_org-l10n-af less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058777" comment="OpenOffice_org-l10n-ar less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058778" comment="OpenOffice_org-l10n-ca less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058779" comment="OpenOffice_org-l10n-cs less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058780" comment="OpenOffice_org-l10n-da less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058781" comment="OpenOffice_org-l10n-de less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058782" comment="OpenOffice_org-l10n-el less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058783" comment="OpenOffice_org-l10n-en-GB less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058784" comment="OpenOffice_org-l10n-es less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058786" comment="OpenOffice_org-l10n-extras less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058787" comment="OpenOffice_org-l10n-fi less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058788" comment="OpenOffice_org-l10n-fr less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058840" comment="OpenOffice_org-l10n-gu-IN less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058841" comment="OpenOffice_org-l10n-hi-IN less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058789" comment="OpenOffice_org-l10n-hu less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058790" comment="OpenOffice_org-l10n-it less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058791" comment="OpenOffice_org-l10n-ja less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058842" comment="OpenOffice_org-l10n-ko less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058792" comment="OpenOffice_org-l10n-nb less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058793" comment="OpenOffice_org-l10n-nl less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058794" comment="OpenOffice_org-l10n-nn less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058795" comment="OpenOffice_org-l10n-pl less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058796" comment="OpenOffice_org-l10n-pt-BR less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058797" comment="OpenOffice_org-l10n-pt less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058798" comment="OpenOffice_org-l10n-ru less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058799" comment="OpenOffice_org-l10n-sk less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058800" comment="OpenOffice_org-l10n-sv less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058801" comment="OpenOffice_org-l10n-xh less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058802" comment="OpenOffice_org-l10n-zh-CN less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058803" comment="OpenOffice_org-l10n-zh-TW less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058804" comment="OpenOffice_org-l10n-zu less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058806" comment="OpenOffice_org-libs-core less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058808" comment="OpenOffice_org-libs-extern less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058810" comment="OpenOffice_org-libs-gui less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058811" comment="OpenOffice_org-mailmerge less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058812" comment="OpenOffice_org-math less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058813" comment="OpenOffice_org-mono less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058814" comment="OpenOffice_org-officebean less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058815" comment="OpenOffice_org-openclipart less than 3-1.25.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058816" comment="OpenOffice_org-pyuno less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058819" comment="OpenOffice_org-ure less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058843" comment="OpenOffice_org-writer-extensions less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058821" comment="OpenOffice_org-writer less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058822" comment="OpenOffice_org less than 3.2.0.7-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090365" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0365</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0365" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0365" source="CVE"/>
	<description>
	nm-applet.conf in GNOME NetworkManager before 0.7.0.99 contains an incorrect deny setting, which allows local users to discover (1) network connection passwords and (2) pre-shared keys via calls to the GetSecrets method in the dbus request handler.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2ea93e592a2bf790a1f60781d2f5f480 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032226" comment="NetworkManager-glib less than 0.7.0.r4359-15.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032227" comment="NetworkManager less than 0.7.0.r4359-15.1"/>
		</criteria>
	</criteria>
	<!-- 370c86c183ea8f4fcc6f26ff78c1fda2 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032228" comment="NetworkManager-glib less than 0.7.0.r4359-15.9.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032229" comment="NetworkManager less than 0.7.0.r4359-15.9.2"/>
		</criteria>
	</criteria>
	<!-- 9f38610f6d41c74c097b899f66ccd986 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032230" comment="NetworkManager-gnome less than 0.7.0.r1053-11.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090368" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0368</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0368" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0368" source="CVE"/>
	<description>
	OpenSC before 0.11.7 allows physically proximate attackers to bypass intended PIN requirements and read private data objects via a (1) low level APDU command or (2) debugging tool, as demonstrated by reading the 4601 or 4701 file with the opensc-explorer or opensc-tool program.
	</description>
 </metadata>
<!-- f428517b5568622c232d45f50621c1f0 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032231" comment="libopensc2-32bit less than 0.11.6-5.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032233" comment="libopensc2 less than 0.11.6-5.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032234" comment="opensc-32bit less than 0.11.6-5.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032236" comment="opensc less than 0.11.6-5.25.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090509" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0509</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0509" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0509" source="CVE"/>
	<description>
	Heap-based buffer overflow in the JBIG2 filter in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 allows remote attackers to execute arbitrary code via a crafted file that triggers memory corruption.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- afe186fd3bad60212fb8d8d8b51e1454 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009051914" comment="acroread less than 8.1.6-0.1.1"/>
	</criteria>
	<!-- d585d11ae44add7af85ddd5eccb6818d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054066" comment="acroread_ja less than 8.1.6-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090510" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0510</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0510" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0510" source="CVE"/>
	<description>
	Heap-based buffer overflow in the JBIG2 filter in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-0511, CVE-2009-0512, CVE-2009-0888, and CVE-2009-0889.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- afe186fd3bad60212fb8d8d8b51e1454 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009051914" comment="acroread less than 8.1.6-0.1.1"/>
	</criteria>
	<!-- d585d11ae44add7af85ddd5eccb6818d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054066" comment="acroread_ja less than 8.1.6-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090511" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0511</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0511" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0511" source="CVE"/>
	<description>
	Heap-based buffer overflow in the JBIG2 filter in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-0510, CVE-2009-0512, CVE-2009-0888, and CVE-2009-0889.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- afe186fd3bad60212fb8d8d8b51e1454 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009051914" comment="acroread less than 8.1.6-0.1.1"/>
	</criteria>
	<!-- d585d11ae44add7af85ddd5eccb6818d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054066" comment="acroread_ja less than 8.1.6-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090512" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0512</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0512" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0512" source="CVE"/>
	<description>
	Heap-based buffer overflow in the JBIG2 filter in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-0510, CVE-2009-0511, CVE-2009-0888, and CVE-2009-0889.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- afe186fd3bad60212fb8d8d8b51e1454 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009051914" comment="acroread less than 8.1.6-0.1.1"/>
	</criteria>
	<!-- d585d11ae44add7af85ddd5eccb6818d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054066" comment="acroread_ja less than 8.1.6-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090519" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0519</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0519" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0519" source="CVE"/>
	<description>
	Unspecified vulnerability in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a crafted Shockwave Flash (aka .swf) file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 114396a426b755abae95f7d91f8ba5b8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009051789" comment="flash-player less than 10.0.22.87-1.1"/>
	</criteria>
	<!-- 92b70d704f9216e04ab21e4e394c9329 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009051791" comment="flash-player less than 10.0.22.87-1.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090520" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0520</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0520" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0520" source="CVE"/>
	<description>
	Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 does not properly remove references to destroyed objects during Shockwave Flash file processing, which allows remote attackers to execute arbitrary code via a crafted file, related to a "buffer overflow issue."
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 114396a426b755abae95f7d91f8ba5b8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009051789" comment="flash-player less than 10.0.22.87-1.1"/>
	</criteria>
	<!-- 92b70d704f9216e04ab21e4e394c9329 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009051791" comment="flash-player less than 10.0.22.87-1.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090521" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0521</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0521" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0521" source="CVE"/>
	<description>
	Untrusted search path vulnerability in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 on Linux allows local users to obtain sensitive information or gain privileges via a crafted library in a directory contained in the RPATH.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 114396a426b755abae95f7d91f8ba5b8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009051789" comment="flash-player less than 10.0.22.87-1.1"/>
	</criteria>
	<!-- 92b70d704f9216e04ab21e4e394c9329 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009051791" comment="flash-player less than 10.0.22.87-1.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090547" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0547</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0547" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0547" source="CVE"/>
	<description>
	Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text within a signed-data blob, not the copy of the e-mail text displayed to the user, which allows remote attackers to spoof a signature by modifying the latter copy, a different vulnerability than CVE-2008-5077.
	</description>
 </metadata>
<!-- c7c8e33671ac7994fac1b1913560d9bd -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009058657" comment="evolution-data-server-32bit less than 2.24.1.1-11.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058658" comment="evolution-data-server-lang less than 2.24.1.1-11.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058660" comment="evolution-data-server less than 2.24.1.1-11.12.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090578" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0578</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0578" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0578" source="CVE"/>
	<description>
	GNOME NetworkManager before 0.7.0.99 does not properly verify privileges for dbus (1) modify and (2) delete requests, which allows local users to change or remove the network connections of arbitrary users via unspecified vectors related to org.freedesktop.NetworkManagerUserSettings and at_console.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2ea93e592a2bf790a1f60781d2f5f480 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032226" comment="NetworkManager-glib less than 0.7.0.r4359-15.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032227" comment="NetworkManager less than 0.7.0.r4359-15.1"/>
		</criteria>
	</criteria>
	<!-- 370c86c183ea8f4fcc6f26ff78c1fda2 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032228" comment="NetworkManager-glib less than 0.7.0.r4359-15.9.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032229" comment="NetworkManager less than 0.7.0.r4359-15.9.2"/>
		</criteria>
	</criteria>
	<!-- 9f38610f6d41c74c097b899f66ccd986 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032230" comment="NetworkManager-gnome less than 0.7.0.r1053-11.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090581" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0581</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0581" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0581" source="CVE"/>
	<description>
	Memory leak in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allows context-dependent attackers to cause a denial of service (memory consumption and application crash) via a crafted image file.
	</description>
 </metadata>
<!-- ebee4d79b9b0e20a4c4571ee016948ba -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032237" comment="lcms less than 1.17-77.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032238" comment="liblcms1-32bit less than 1.17-77.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032240" comment="liblcms1 less than 1.17-77.12.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090582" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0582</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0582" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0582" source="CVE"/>
	<description>
	The ntlm_challenge function in the NTLM SASL authentication mechanism in camel/camel-sasl-ntlm.c in Camel in Evolution Data Server (aka evolution-data-server) 2.24.5 and earlier, and 2.25.92 and earlier 2.25.x versions, does not validate whether a certain length value is consistent with the amount of data in a challenge packet, which allows remote mail servers to read information from the process memory of a client, or cause a denial of service (client crash), via an NTLM authentication type 2 packet with a length value that exceeds the amount of packet data.
	</description>
 </metadata>
<!-- fe91f45fff42c9cf641b26e271a0e279 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032241" comment="evolution-data-server-32bit less than 2.24.1.1-11.8.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032242" comment="evolution-data-server-lang less than 2.24.1.1-11.8.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032244" comment="evolution-data-server less than 2.24.1.1-11.8.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052199" comment="evolution-lang less than 2.24.1.1-15.8.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052202" comment="evolution-pilot less than 2.24.1.1-15.8.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052200" comment="evolution less than 2.24.1.1-15.8.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032245" comment="gtkhtml2-lang less than 3.24.1.1-3.23.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032246" comment="gtkhtml2 less than 3.24.1.1-3.23.2"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090583" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0583</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0583" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0583" source="CVE"/>
	<description>
	Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.
	</description>
 </metadata>
<!-- cdf7326a6fdf5b963b028d581e2fa57a -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032247" comment="ghostscript-fonts-other less than 8.62-32.22.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032248" comment="ghostscript-fonts-rus less than 8.62-32.22.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032249" comment="ghostscript-fonts-std less than 8.62-32.22.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032250" comment="ghostscript-library less than 8.62-32.22.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032251" comment="ghostscript-omni less than 8.62-32.22.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032252" comment="ghostscript-x11 less than 8.62-32.22.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032253" comment="libgimpprint less than 4.2.7-32.22.2"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090584" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0584</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0584" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0584" source="CVE"/>
	<description>
	icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code by using a device file for processing a crafted image file associated with large integer values for certain sizes, related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.
	</description>
 </metadata>
<!-- cdf7326a6fdf5b963b028d581e2fa57a -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032247" comment="ghostscript-fonts-other less than 8.62-32.22.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032248" comment="ghostscript-fonts-rus less than 8.62-32.22.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032249" comment="ghostscript-fonts-std less than 8.62-32.22.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032250" comment="ghostscript-library less than 8.62-32.22.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032251" comment="ghostscript-omni less than 8.62-32.22.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032252" comment="ghostscript-x11 less than 8.62-32.22.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032253" comment="libgimpprint less than 4.2.7-32.22.2"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090586" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0586</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0586" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0586" source="CVE"/>
	<description>
	Integer overflow in the gst_vorbis_tag_add_coverart function (gst-libs/gst/tag/gstvorbistag.c) in vorbistag in gst-plugins-base (aka gstreamer-plugins-base) before 0.10.23 in GStreamer allows context-dependent attackers to execute arbitrary code via a crafted COVERART tag that is converted from a base64 representation, which triggers a heap-based buffer overflow.
	</description>
 </metadata>
<!-- 7f766637f1633ea89ce72f52ede1a845 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032254" comment="gstreamer-0_10-plugins-base-32bit less than 0.10.21-2.36.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032256" comment="gstreamer-0_10-plugins-base-lang less than 0.10.21-2.36.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032258" comment="gstreamer-0_10-plugins-base less than 0.10.21-2.36.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032259" comment="libgstinterfaces-0_10-0-32bit less than 0.10.21-2.36.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032261" comment="libgstinterfaces-0_10-0 less than 0.10.21-2.36.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090587" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0587</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0587" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0587" source="CVE"/>
	<description>
	Multiple integer overflows in Evolution Data Server (aka evolution-data-server) before 2.24.5 allow context-dependent attackers to execute arbitrary code via a long string that is converted to a base64 representation in (1) addressbook/libebook/e-vcard.c in evc or (2) camel/camel-mime-utils.c in libcamel.
	</description>
 </metadata>
<!-- c7c8e33671ac7994fac1b1913560d9bd -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009058657" comment="evolution-data-server-32bit less than 2.24.1.1-11.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058658" comment="evolution-data-server-lang less than 2.24.1.1-11.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058660" comment="evolution-data-server less than 2.24.1.1-11.12.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090590" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0590</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2009-0590" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0590" source="CVE"/>
	<description>
	The ASN1_STRING_print_ex function in OpenSSL before 0.9.8k allows remote attackers to cause a denial of service (invalid memory access and application crash) via vectors that trigger printing of a (1) BMPString or (2) UniversalString with an invalid encoded length.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2f80f91b648dcd2ec32e230ff4cf94b5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032262" comment="libopenssl0_9_8-32bit less than 0.9.8h-30.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032264" comment="libopenssl0_9_8 less than 0.9.8h-30.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032266" comment="openssl less than 0.9.8h-30.12.1"/>
		</criteria>
	</criteria>
	<!-- 79f88b4366b267744a8056a0b1669fb3 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009069583" comment="compat-openssl097g-32bit less than 0.9.7g-146.20.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009069584" comment="compat-openssl097g less than 0.9.7g-146.20.1"/>
		</criteria>
	</criteria>
	<!-- ed5058ffbfbf1571826a73620feb03b6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009052275" comment="compat-openssl097g-32bit less than 0.9.7g-146.15.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052276" comment="compat-openssl097g less than 0.9.7g-146.15.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090591" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0591</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0591" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0591" source="CVE"/>
	<description>
	The CMS_verify function in OpenSSL 0.9.8h through 0.9.8j, when CMS is enabled, does not properly handle errors associated with malformed signed attributes, which allows remote attackers to repudiate a signature that originally appeared to be valid but was actually invalid.
	</description>
 </metadata>
<!-- 2f80f91b648dcd2ec32e230ff4cf94b5 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032262" comment="libopenssl0_9_8-32bit less than 0.9.8h-30.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032264" comment="libopenssl0_9_8 less than 0.9.8h-30.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032266" comment="openssl less than 0.9.8h-30.12.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090642" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0642</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0642" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0642" source="CVE"/>
	<description>
	ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check the return value from the OCSP_basic_verify function, which might allow remote attackers to successfully present an invalid X.509 certificate, possibly involving a revoked certificate.
	</description>
 </metadata>
<!-- c8369586b31bf86da2231acd00ad8f78 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053194" comment="ruby less than 1.8.7.p72-5.22.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090652" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0652</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0652" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0652" source="CVE"/>
	<description>
	The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird before 2.0.0.21; and SeaMonkey before 1.1.15 does not include box-drawing characters, which allows remote attackers to spoof URLs and conduct phishing attacks, as demonstrated by homoglyphs of the / (slash) and ? (question mark) characters in a subdomain of a .cn domain name, a different vulnerability than CVE-2005-0233.  NOTE: some third parties claim that 3.0.6 is not affected, but much older versions perhaps are affected.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8d58759fa070160f1f7d27df1de3a166 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032267" comment="MozillaFirefox-translations less than 3.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032268" comment="MozillaFirefox less than 3.0.9-0.1.1"/>
		</criteria>
	</criteria>
	<!-- fab01148f9c2f94e57e7070118a7818e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032269" comment="mozilla-xulrunner190-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052298" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032270" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052299" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032271" comment="mozilla-xulrunner190-translations less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032273" comment="mozilla-xulrunner190 less than 1.9.0.9-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090658" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0658</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0658" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0658" source="CVE"/>
	<description>
	Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitrary code via a crafted PDF document, related to a non-JavaScript function call and possibly an embedded JBIG2 image stream, as exploited in the wild in February 2009 by Trojan.Pidief.E.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 65a9509d5ccaa91e4e59902a72dca480 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009051906" comment="acroread_ja less than 8.1.4-0.1.1"/>
	</criteria>
	<!-- a04133df2de1f0d9def205bcbd21d423 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009051908" comment="acroread less than 8.1.4-0.9.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090676" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0676</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0676" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0676" source="CVE"/>
	<description>
	The sock_getsockopt function in net/core/sock.c in the Linux kernel before 2.6.28.6 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel memory via an SO_BSDCOMPAT getsockopt request.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8b684f8048b88ef832b80e585ff96805 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032276" comment="kernel-default-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052310" comment="kernel-default-extra less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032277" comment="kernel-default less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032281" comment="kernel-source less than 2.6.27.21-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032282" comment="kernel-syms less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032285" comment="kernel-xen-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052320" comment="kernel-xen-extra less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032286" comment="kernel-xen less than 2.6.27.21-0.1.2"/>
		</criteria>
	</criteria>
	<!-- ab571c76de3bf9c7bafb83437a2d83aa -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032276" comment="kernel-default-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052310" comment="kernel-default-extra less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032277" comment="kernel-default less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032289" comment="kernel-pae-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052312" comment="kernel-pae-extra less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032290" comment="kernel-pae less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032281" comment="kernel-source less than 2.6.27.21-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032282" comment="kernel-syms less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032285" comment="kernel-xen-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052320" comment="kernel-xen-extra less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032286" comment="kernel-xen less than 2.6.27.21-0.1.2"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090688" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0688</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0688" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0688" source="CVE"/>
	<description>
	Multiple buffer overflows in the CMU Cyrus SASL library before 2.1.23 might allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via strings that are used as input to the sasl_encode64 function in lib/saslutil.c.
	</description>
 </metadata>
<!-- 381af186b7a4cd4e07f677ae4bb568f8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032293" comment="cyrus-sasl-32bit less than 2.1.22-182.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032294" comment="cyrus-sasl-crammd5-32bit less than 2.1.22-182.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032296" comment="cyrus-sasl-crammd5 less than 2.1.22-182.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052332" comment="cyrus-sasl-digestmd5-32bit less than 2.1.22-182.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032297" comment="cyrus-sasl-digestmd5 less than 2.1.22-182.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032298" comment="cyrus-sasl-gssapi-32bit less than 2.1.22-182.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032300" comment="cyrus-sasl-gssapi less than 2.1.22-182.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032304" comment="cyrus-sasl-plain-32bit less than 2.1.22-182.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032306" comment="cyrus-sasl-plain less than 2.1.22-182.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032308" comment="cyrus-sasl less than 2.1.22-182.20.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090689" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0689</title>
	<affected family="unix">
		<platform>SLE 11 DESKTOP Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0689" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0689" source="CVE"/>
	<description>
	Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD 4.5, Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4, K-Meleon 1.5.3, SeaMonkey 1.1.8, and other products, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large precision value in the format argument to a printf function, which triggers incorrect memory allocation and a heap-based buffer overflow during conversion to a floating-point number.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04c6e38838a85fc92531b3e56904b052 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055940" comment="mozilla-xulrunner190-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055953" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055941" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055955" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055942" comment="mozilla-xulrunner190-translations less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055944" comment="mozilla-xulrunner190 less than 1.9.0.15-0.1.2"/>
		</criteria>
	</criteria>
	<!-- 0bf04a4aa83105c91a9211d8cc21a404 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057158" comment="kdelibs4-core less than 4.1.3-8.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057159" comment="kdelibs4 less than 4.1.3-8.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057162" comment="libkde4 less than 4.1.3-8.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057165" comment="libkdecore4 less than 4.1.3-8.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057166" comment="utempter-32bit less than 0.5.5-106.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057168" comment="utempter less than 0.5.5-106.18"/>
		</criteria>
	</criteria>
	<!-- 49179a9289fbe778bc2320690c17d088 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055945" comment="MozillaFirefox-translations less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055946" comment="MozillaFirefox less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055947" comment="mozilla-xulrunner191-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055966" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055948" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055968" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055949" comment="mozilla-xulrunner191-translations less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055951" comment="mozilla-xulrunner191 less than 1.9.1.4-2.1.3"/>
		</criteria>
	</criteria>
	<!-- 5d7c99e519a95f9108d35c51b0c854c5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056567" comment="kdelibs3-default-style less than 3.5.10-23.27.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056569" comment="kdelibs3 less than 3.5.10-23.27.1"/>
		</criteria>
	</criteria>
	<!-- ea83feacee19ffa926f0205c68b1bb6b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056065" comment="mozilla-nspr-32bit less than 4.8.2-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056067" comment="mozilla-nspr less than 4.8.2-1.1.1"/>
		</criteria>
	</criteria>
	<!-- f2377272fe27726ada5a22ead971d6aa -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059215" comment="MozillaThunderbird-translations less than 2.0.0.24-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059216" comment="MozillaThunderbird less than 2.0.0.24-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090692" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0692</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0692" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0692" source="CVE"/>
	<description>
	Stack-based buffer overflow in the script_write_params method in client/dhclient.c in ISC DHCP dhclient 4.1 before 4.1.0p1, 4.0 before 4.0.1p1, 3.1 before 3.1.2p1, 3.0, and 2.0 allows remote DHCP servers to execute arbitrary code via a crafted subnet-mask option.
	</description>
 </metadata>
<!-- 8344cd148acb6a76268d2b1462cf9a03 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053395" comment="dhcp-client less than 3.1.1-7.13.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090696" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0696</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0696" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0696" source="CVE"/>
	<description>
	The dns_db_findrdataset function in db.c in named in ISC BIND 9.4 before 9.4.3-P3, 9.5 before 9.5.1-P3, and 9.6 before 9.6.1-P1, when configured as a master server, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an ANY record in the prerequisite section of a crafted dynamic update message, as exploited in the wild in July 2009.
	</description>
 </metadata>
<!-- 2effd341d6971e49515add75df350e14 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053622" comment="bind-libs-32bit less than 9.5.0P2-20.3.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053624" comment="bind-libs less than 9.5.0P2-20.3.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053625" comment="bind-utils less than 9.5.0P2-20.3.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090698" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0698</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0698" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0698" source="CVE"/>
	<description>
	Integer overflow in the 4xm demuxer (demuxers/demux_4xm.c) in xine-lib 1.1.16.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a 4X movie file with a large current_track value, a similar issue to CVE-2009-0385.
	</description>
 </metadata>
<!-- 63ca8fca1175eb8463fa2877528b3f22 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009052409" comment="libxine1-gnome-vfs less than 1.1.15-23.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052410" comment="libxine1-pulse less than 1.1.15-23.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052411" comment="libxine1 less than 1.1.15-23.1.2"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090723" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0723</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0723" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0723" source="CVE"/>
	<description>
	Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow.  NOTE: some of these details are obtained from third party information.
	</description>
 </metadata>
<!-- ebee4d79b9b0e20a4c4571ee016948ba -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032237" comment="lcms less than 1.17-77.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032238" comment="liblcms1-32bit less than 1.17-77.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032240" comment="liblcms1 less than 1.17-77.12.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090733" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0733</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0733" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0733" source="CVE"/>
	<description>
	Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file associated with a large integer value for the (1) input or (2) output channel, related to the ReadLUT_A2B and ReadLUT_B2A functions.
	</description>
 </metadata>
<!-- ebee4d79b9b0e20a4c4571ee016948ba -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032237" comment="lcms less than 1.17-77.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032238" comment="liblcms1-32bit less than 1.17-77.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032240" comment="liblcms1 less than 1.17-77.12.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090755" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0755</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0755" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0755" source="CVE"/>
	<description>
	The FormWidgetChoice::loadDefaults function in Poppler before 0.10.4 allows remote attackers to cause a denial of service (crash) via a PDF file with an invalid Form Opt entry.
	</description>
 </metadata>
<!-- f27d99aa7f35ddbc6bc5e4ac681ee974 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032208" comment="libpoppler4 less than 0.10.1-1.30.5"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090756" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0756</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0756" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0756" source="CVE"/>
	<description>
	The JBIG2Stream::readSymbolDictSeg function in Poppler before 0.10.4 allows remote attackers to cause a denial of service (crash) via a PDF file that triggers a parsing error, which is not properly handled by JBIG2SymbolDict::~JBIG2SymbolDict and triggers an invalid memory dereference.
	</description>
 </metadata>
<!-- f27d99aa7f35ddbc6bc5e4ac681ee974 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032208" comment="libpoppler4 less than 0.10.1-1.30.5"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090758" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0758</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0758" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0758" source="CVE"/>
	<description>
	The originates_from_local_legacy_unicast_socket function in avahi-core/server.c in avahi-daemon 0.6.23 does not account for the network byte order of a port number when processing incoming multicast packets, which allows remote attackers to cause a denial of service (network bandwidth and CPU consumption) via a crafted legacy unicast mDNS query packet that triggers a multicast packet storm.
	</description>
 </metadata>
<!-- e62a04513f7f4a262e1c7a10a38b46e8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009057520" comment="avahi-lang less than 0.6.23-11.14.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057521" comment="avahi less than 0.6.23-11.14.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057522" comment="libavahi-client3-32bit less than 0.6.23-11.14.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057524" comment="libavahi-client3 less than 0.6.23-11.14.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057525" comment="libavahi-common3-32bit less than 0.6.23-11.14.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057527" comment="libavahi-common3 less than 0.6.23-11.14.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057528" comment="libavahi-core5 less than 0.6.23-11.14.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057529" comment="libdns_sd-32bit less than 0.6.23-11.14.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057531" comment="libdns_sd less than 0.6.23-11.14.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090771" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0771</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0771" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0771" source="CVE"/>
	<description>
	The layout engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain vectors that trigger memory corruption and assertion failures.
	</description>
 </metadata>
<!-- 64ea6139df28e916c5f627ff6f4b6b83 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032198" comment="MozillaFirefox-translations less than 3.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032199" comment="MozillaFirefox less than 3.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032200" comment="mozilla-xulrunner190-32bit less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009051707" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032201" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009051709" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032202" comment="mozilla-xulrunner190-translations less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032204" comment="mozilla-xulrunner190 less than 1.9.0.7-1.1.4"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090772" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0772</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0772" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0772" source="CVE"/>
	<description>
	The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to nsCSSStyleSheet::GetOwnerNode, events, and garbage collection, which triggers memory corruption.
	</description>
 </metadata>
<!-- 64ea6139df28e916c5f627ff6f4b6b83 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032198" comment="MozillaFirefox-translations less than 3.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032199" comment="MozillaFirefox less than 3.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032200" comment="mozilla-xulrunner190-32bit less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009051707" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032201" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009051709" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032202" comment="mozilla-xulrunner190-translations less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032204" comment="mozilla-xulrunner190 less than 1.9.0.7-1.1.4"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090773" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0773</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0773" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0773" source="CVE"/>
	<description>
	The JavaScript engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a splice of an array that contains "some non-set elements," which causes jsarray.cpp to pass an incorrect argument to the ResizeSlots function, which triggers memory corruption; (2) vectors related to js_DecompileValueGenerator, jsopcode.cpp, __defineSetter__, and watch, which triggers an assertion failure or a segmentation fault; and (3) vectors related to gczeal, __defineSetter__, and watch, which triggers a hang.
	</description>
 </metadata>
<!-- 64ea6139df28e916c5f627ff6f4b6b83 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032198" comment="MozillaFirefox-translations less than 3.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032199" comment="MozillaFirefox less than 3.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032200" comment="mozilla-xulrunner190-32bit less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009051707" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032201" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009051709" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032202" comment="mozilla-xulrunner190-translations less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032204" comment="mozilla-xulrunner190 less than 1.9.0.7-1.1.4"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090774" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0774</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0774" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0774" source="CVE"/>
	<description>
	The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to gczeal, a different vulnerability than CVE-2009-0773.
	</description>
 </metadata>
<!-- 64ea6139df28e916c5f627ff6f4b6b83 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032198" comment="MozillaFirefox-translations less than 3.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032199" comment="MozillaFirefox less than 3.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032200" comment="mozilla-xulrunner190-32bit less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009051707" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032201" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009051709" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032202" comment="mozilla-xulrunner190-translations less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032204" comment="mozilla-xulrunner190 less than 1.9.0.7-1.1.4"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090775" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0775</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0775" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0775" source="CVE"/>
	<description>
	Double free vulnerability in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to execute arbitrary code via "cloned XUL DOM elements which were linked as a parent and child," which are not properly handled during garbage collection.
	</description>
 </metadata>
<!-- 64ea6139df28e916c5f627ff6f4b6b83 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032198" comment="MozillaFirefox-translations less than 3.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032199" comment="MozillaFirefox less than 3.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032200" comment="mozilla-xulrunner190-32bit less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009051707" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032201" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009051709" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032202" comment="mozilla-xulrunner190-translations less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032204" comment="mozilla-xulrunner190 less than 1.9.0.7-1.1.4"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090776" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0776</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0776" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0776" source="CVE"/>
	<description>
	nsIRDFService in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to bypass the same-origin policy and read XML data from another domain via a cross-domain redirect.
	</description>
 </metadata>
<!-- 64ea6139df28e916c5f627ff6f4b6b83 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032198" comment="MozillaFirefox-translations less than 3.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032199" comment="MozillaFirefox less than 3.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032200" comment="mozilla-xulrunner190-32bit less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009051707" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032201" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009051709" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032202" comment="mozilla-xulrunner190-translations less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032204" comment="mozilla-xulrunner190 less than 1.9.0.7-1.1.4"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090777" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0777</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0777" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0777" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 decode invisible characters when they are displayed in the location bar, which causes an incorrect address to be displayed and makes it easier for remote attackers to spoof URLs and conduct phishing attacks.
	</description>
 </metadata>
<!-- 64ea6139df28e916c5f627ff6f4b6b83 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032198" comment="MozillaFirefox-translations less than 3.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032199" comment="MozillaFirefox less than 3.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032200" comment="mozilla-xulrunner190-32bit less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009051707" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032201" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009051709" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032202" comment="mozilla-xulrunner190-translations less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032204" comment="mozilla-xulrunner190 less than 1.9.0.7-1.1.4"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090789" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0789</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2009-0789" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0789" source="CVE"/>
	<description>
	OpenSSL before 0.9.8k on WIN64 and certain other platforms does not properly handle a malformed ASN.1 structure, which allows remote attackers to cause a denial of service (invalid memory access and application crash) by placing this structure in the public key of a certificate, as demonstrated by an RSA public key.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2f80f91b648dcd2ec32e230ff4cf94b5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032262" comment="libopenssl0_9_8-32bit less than 0.9.8h-30.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032264" comment="libopenssl0_9_8 less than 0.9.8h-30.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032266" comment="openssl less than 0.9.8h-30.12.1"/>
		</criteria>
	</criteria>
	<!-- 79f88b4366b267744a8056a0b1669fb3 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009069583" comment="compat-openssl097g-32bit less than 0.9.7g-146.20.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009069584" comment="compat-openssl097g less than 0.9.7g-146.20.1"/>
		</criteria>
	</criteria>
	<!-- ed5058ffbfbf1571826a73620feb03b6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009052275" comment="compat-openssl097g-32bit less than 0.9.7g-146.15.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052276" comment="compat-openssl097g less than 0.9.7g-146.15.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090791" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0791</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0791" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0791" source="CVE"/>
	<description>
	Multiple integer overflows in Xpdf 2.x and 3.x and Poppler 0.x, as used in the pdftops filter in CUPS 1.1.17, 1.1.22, and 1.3.7, GPdf, and kdegraphics KPDF, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF file that triggers a heap-based buffer overflow, possibly related to (1) Decrypt.cxx, (2) FoFiTrueType.cxx, (3) gmem.c, (4) JBIG2Stream.cxx, and (5) PSOutputDev.cxx in pdftops/. NOTE: the JBIG2Stream.cxx vector may overlap CVE-2009-1179.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 3e6bf6b6d5045a1a9a76d6199d51adab -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054103" comment="xpdf-tools less than 3.02-138.26.1"/>
	</criteria>
	<!-- bde2b755a6dc83d88dd11394793d4482 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057042" comment="libpoppler-glib4 less than 0.10.1-1.31.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057043" comment="libpoppler-qt4-3 less than 0.10.1-1.31.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057044" comment="libpoppler4 less than 0.10.1-1.31.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090792" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0792</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0792" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0792" source="CVE"/>
	<description>
	Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.  NOTE: this issue exists because of an incomplete fix for CVE-2009-0583.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 821fdfa281de6b75cdc24c1e4f935e7e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032219" comment="ghostscript-fonts-other less than 8.62-32.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032220" comment="ghostscript-fonts-rus less than 8.62-32.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032221" comment="ghostscript-fonts-std less than 8.62-32.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032222" comment="ghostscript-library less than 8.62-32.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032223" comment="ghostscript-omni less than 8.62-32.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032224" comment="ghostscript-x11 less than 8.62-32.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032225" comment="libgimpprint less than 4.2.7-32.23.1"/>
		</criteria>
	</criteria>
	<!-- ab7a3ecdd7f2b22db74d66fd6e23832b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032106" comment="ghostscript-fonts-other less than 8.62-32.25.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032107" comment="ghostscript-fonts-rus less than 8.62-32.25.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032108" comment="ghostscript-fonts-std less than 8.62-32.25.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032109" comment="ghostscript-library less than 8.62-32.25.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032110" comment="ghostscript-omni less than 8.62-32.25.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032111" comment="ghostscript-x11 less than 8.62-32.25.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032112" comment="libgimpprint less than 4.2.7-32.25.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090799" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0799</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0799" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0799" source="CVE"/>
	<description>
	The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers an out-of-bounds read.
	</description>
 </metadata>
<!-- f27d99aa7f35ddbc6bc5e4ac681ee974 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032208" comment="libpoppler4 less than 0.10.1-1.30.5"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090800" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0800</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0800" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0800" source="CVE"/>
	<description>
	Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file.
	</description>
 </metadata>
<!-- f27d99aa7f35ddbc6bc5e4ac681ee974 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032208" comment="libpoppler4 less than 0.10.1-1.30.5"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090835" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0835</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0835" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0835" source="CVE"/>
	<description>
	The __secure_computing function in kernel/seccomp.c in the seccomp subsystem in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform, when CONFIG_SECCOMP is enabled, does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass intended access restrictions via crafted syscalls that are misinterpreted as (a) stat or (b) chmod, a related issue to CVE-2009-0342 and CVE-2009-0343.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8b684f8048b88ef832b80e585ff96805 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032276" comment="kernel-default-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052310" comment="kernel-default-extra less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032277" comment="kernel-default less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032281" comment="kernel-source less than 2.6.27.21-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032282" comment="kernel-syms less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032285" comment="kernel-xen-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052320" comment="kernel-xen-extra less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032286" comment="kernel-xen less than 2.6.27.21-0.1.2"/>
		</criteria>
	</criteria>
	<!-- ab571c76de3bf9c7bafb83437a2d83aa -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032276" comment="kernel-default-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052310" comment="kernel-default-extra less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032277" comment="kernel-default less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032289" comment="kernel-pae-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052312" comment="kernel-pae-extra less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032290" comment="kernel-pae less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032281" comment="kernel-source less than 2.6.27.21-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032282" comment="kernel-syms less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032285" comment="kernel-xen-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052320" comment="kernel-xen-extra less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032286" comment="kernel-xen less than 2.6.27.21-0.1.2"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090844" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0844</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0844" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0844" source="CVE"/>
	<description>
	The get_input_token function in the SPNEGO implementation in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote attackers to cause a denial of service (daemon crash) and possibly obtain sensitive information via a crafted length value that triggers a buffer over-read.
	</description>
 </metadata>
<!-- 077b202d02c16bdd595a5ac0beb7479b -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032313" comment="krb5-32bit less than 1.6.3-133.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032316" comment="krb5-client less than 1.6.3-133.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032319" comment="krb5 less than 1.6.3-133.25.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090845" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0845</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0845" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0845" source="CVE"/>
	<description>
	The spnego_gss_accept_sec_context function in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3, when SPNEGO is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via invalid ContextFlags data in the reqFlags field in a negTokenInit token.
	</description>
 </metadata>
<!-- 077b202d02c16bdd595a5ac0beb7479b -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032313" comment="krb5-32bit less than 1.6.3-133.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032316" comment="krb5-client less than 1.6.3-133.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032319" comment="krb5 less than 1.6.3-133.25.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090846" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0846</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0846" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0846" source="CVE"/>
	<description>
	The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via vectors involving an invalid DER encoding that triggers a free of an uninitialized pointer.
	</description>
 </metadata>
<!-- 077b202d02c16bdd595a5ac0beb7479b -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032313" comment="krb5-32bit less than 1.6.3-133.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032316" comment="krb5-client less than 1.6.3-133.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032319" comment="krb5 less than 1.6.3-133.25.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090847" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0847</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0847" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0847" source="CVE"/>
	<description>
	The asn1buf_imbed function in the ASN.1 decoder in MIT Kerberos 5 (aka krb5) 1.6.3, when PK-INIT is used, allows remote attackers to cause a denial of service (application crash) via a crafted length value that triggers an erroneous malloc call, related to incorrect calculations with pointer arithmetic.
	</description>
 </metadata>
<!-- 077b202d02c16bdd595a5ac0beb7479b -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032313" comment="krb5-32bit less than 1.6.3-133.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032316" comment="krb5-client less than 1.6.3-133.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032319" comment="krb5 less than 1.6.3-133.25.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090901" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0901</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0901" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0901" source="CVE"/>
	<description>
	The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold, and Visual C++ 2005 SP1 and 2008 Gold and SP1; and Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2; does not prevent VariantClear calls on an uninitialized VARIANT, which allows remote attackers to execute arbitrary code via a malformed stream to an ATL (1) component or (2) control, related to ATL headers and error handling, aka "ATL Uninitialized Object Vulnerability."
	</description>
 </metadata>
<!-- 0ed97f904ab5337b5e08c83e789c22d2 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053711" comment="flash-player less than 10.0.32.18-0.1.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090922" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0922</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0922" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0922" source="CVE"/>
	<description>
	PostgreSQL before 8.3.7, 8.2.13, 8.1.17, 8.0.21, and 7.4.25 allows remote authenticated users to cause a denial of service (stack consumption and crash) by triggering a failure in the conversion of a localized error message to a client-specified encoding, as demonstrated using mismatched encoding conversion requests.
	</description>
 </metadata>
<!-- f8418e967ead7b81dedf9dca5a5fd222 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032322" comment="postgresql-libs-32bit less than 8.3.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032324" comment="postgresql-libs less than 8.3.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032326" comment="postgresql less than 8.3.7-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090927" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0927</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0927" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0927" source="CVE"/>
	<description>
	Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to execute arbitrary code via a crafted argument to the getIcon method of a Collab object, a different vulnerability than CVE-2009-0658.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 65a9509d5ccaa91e4e59902a72dca480 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009051906" comment="acroread_ja less than 8.1.4-0.1.1"/>
	</criteria>
	<!-- a04133df2de1f0d9def205bcbd21d423 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009051908" comment="acroread less than 8.1.4-0.9.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090928" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0928</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0928" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0928" source="CVE"/>
	<description>
	Heap-based buffer overflow in Adobe Acrobat Reader and Acrobat Professional 7.1.0, 8.1.3, 9.0.0, and other versions allows remote attackers to execute arbitrary code via a PDF file containing a JBIG2 stream with a size inconsistency related to an unspecified table.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 65a9509d5ccaa91e4e59902a72dca480 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009051906" comment="acroread_ja less than 8.1.4-0.1.1"/>
	</criteria>
	<!-- a04133df2de1f0d9def205bcbd21d423 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009051908" comment="acroread less than 8.1.4-0.9.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090945" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0945</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0945" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0945" source="CVE"/>
	<description>
	Array index error in the insertItemBefore method in WebKit, as used in Apple Safari before 3.2.3 and 4 Public Beta, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Google Chrome Stable before 1.0.154.65, and possibly other products allows remote attackers to execute arbitrary code via a document with a SVGPathList data structure containing a negative index in the (1) SVGTransformList, (2) SVGStringList, (3) SVGNumberList, (4) SVGPathSegList, (5) SVGPointList, or (6) SVGLengthList SVGList object, which triggers memory corruption.
	</description>
 </metadata>
<!-- c980cdd57955d1f78a74976fd2c23c32 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056137" comment="libqt4-32bit less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056138" comment="libqt4-qt3support-32bit less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056140" comment="libqt4-qt3support less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056141" comment="libqt4-sql-32bit less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056215" comment="libqt4-sql-sqlite-32bit less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056142" comment="libqt4-sql-sqlite less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056144" comment="libqt4-sql less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056145" comment="libqt4-x11-32bit less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056147" comment="libqt4-x11 less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056149" comment="libqt4 less than 4.4.3-12.11.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090946" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0946</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0946" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0946" source="CVE"/>
	<description>
	Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.
	</description>
 </metadata>
<!-- 12988c12cb970710f31eeb8ab8363bee -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032327" comment="freetype2-32bit less than 2.3.7-25.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052520" comment="freetype2-devel less than 2.3.7-25.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032329" comment="freetype2 less than 2.3.7-25.9.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091044" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1044</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1044" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1044" source="CVE"/>
	<description>
	Mozilla Firefox 3.0.7 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors related to the _moveToEdgeShift XUL tree method, which triggers garbage collection on objects that are still in use, as demonstrated by Nils during a PWN2OWN competition at CanSecWest 2009.
	</description>
 </metadata>
<!-- 272bd7f6089e8316b21585826776f472 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032330" comment="MozillaFirefox-translations less than 3.0.8-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032331" comment="MozillaFirefox less than 3.0.8-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032332" comment="mozilla-xulrunner190-32bit less than 1.9.0.8-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052541" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.8-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032333" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.8-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052543" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.8-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032334" comment="mozilla-xulrunner190-translations less than 1.9.0.8-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032336" comment="mozilla-xulrunner190 less than 1.9.0.8-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091061" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1061</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1061" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1061" source="CVE"/>
	<description>
	Unspecified vulnerability in Adobe Acrobat Reader 9 before 9.1, 8 before 8.1.4, and 7 before 7.1.1 might allow remote attackers to execute arbitrary code via unknown attack vectors related to JBIG2 and "input validation," a different vulnerability than CVE-2009-0193 and CVE-2009-1062.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 65a9509d5ccaa91e4e59902a72dca480 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009051906" comment="acroread_ja less than 8.1.4-0.1.1"/>
	</criteria>
	<!-- a04133df2de1f0d9def205bcbd21d423 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009051908" comment="acroread less than 8.1.4-0.9.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091062" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1062</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1062" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1062" source="CVE"/>
	<description>
	Adobe Acrobat Reader 9 before 9.1, 8 before 8.1.4, and 7 before 7.1.1 might allow remote attackers to trigger memory corruption and possibly execute arbitrary code via unknown attack vectors related to JBIG2, a different vulnerability than CVE-2009-0193 and CVE-2009-1061.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 65a9509d5ccaa91e4e59902a72dca480 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009051906" comment="acroread_ja less than 8.1.4-0.1.1"/>
	</criteria>
	<!-- a04133df2de1f0d9def205bcbd21d423 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009051908" comment="acroread less than 8.1.4-0.9.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091072" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1072</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1072" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1072" source="CVE"/>
	<description>
	nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash option.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8b684f8048b88ef832b80e585ff96805 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032276" comment="kernel-default-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052310" comment="kernel-default-extra less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032277" comment="kernel-default less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032281" comment="kernel-source less than 2.6.27.21-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032282" comment="kernel-syms less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032285" comment="kernel-xen-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052320" comment="kernel-xen-extra less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032286" comment="kernel-xen less than 2.6.27.21-0.1.2"/>
		</criteria>
	</criteria>
	<!-- ab571c76de3bf9c7bafb83437a2d83aa -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032276" comment="kernel-default-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052310" comment="kernel-default-extra less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032277" comment="kernel-default less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032289" comment="kernel-pae-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052312" comment="kernel-pae-extra less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032290" comment="kernel-pae less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032281" comment="kernel-source less than 2.6.27.21-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032282" comment="kernel-syms less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032285" comment="kernel-xen-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052320" comment="kernel-xen-extra less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032286" comment="kernel-xen less than 2.6.27.21-0.1.2"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091093" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1093</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1093" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1093" source="CVE"/>
	<description>
	LdapCtx in the LDAP service in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; SDK and JRE 1.3.1_24 and earlier; and 1.4.2_19 and earlier does not close the connection when initialization fails, which allows remote attackers to cause a denial of service (LDAP service hang).
	</description>
 </metadata>
<!-- 3c82d19b21fda3ba8795ae3acfbbfb1f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009052567" comment="java-1_6_0-sun-alsa less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052568" comment="java-1_6_0-sun-demo less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052569" comment="java-1_6_0-sun-jdbc less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052570" comment="java-1_6_0-sun-plugin less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052571" comment="java-1_6_0-sun-src less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052572" comment="java-1_6_0-sun less than 1.6.0.u13-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091094" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1094</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1094" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1094" source="CVE"/>
	<description>
	Unspecified vulnerability in the LDAP implementation in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; SDK and JRE 1.3.1_24 and earlier; and 1.4.2_19 and earlier allows remote LDAP servers to execute arbitrary code via unknown vectors related to serialized data.
	</description>
 </metadata>
<!-- 3c82d19b21fda3ba8795ae3acfbbfb1f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009052567" comment="java-1_6_0-sun-alsa less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052568" comment="java-1_6_0-sun-demo less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052569" comment="java-1_6_0-sun-jdbc less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052570" comment="java-1_6_0-sun-plugin less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052571" comment="java-1_6_0-sun-src less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052572" comment="java-1_6_0-sun less than 1.6.0.u13-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091095" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1095</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1095" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1095" source="CVE"/>
	<description>
	Integer overflow in unpack200 in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via a JAR file with crafted Pack200 headers.
	</description>
 </metadata>
<!-- 3c82d19b21fda3ba8795ae3acfbbfb1f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009052567" comment="java-1_6_0-sun-alsa less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052568" comment="java-1_6_0-sun-demo less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052569" comment="java-1_6_0-sun-jdbc less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052570" comment="java-1_6_0-sun-plugin less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052571" comment="java-1_6_0-sun-src less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052572" comment="java-1_6_0-sun less than 1.6.0.u13-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091096" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1096</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1096" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1096" source="CVE"/>
	<description>
	Buffer overflow in unpack200 in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via a JAR file with crafted Pack200 headers.
	</description>
 </metadata>
<!-- 3c82d19b21fda3ba8795ae3acfbbfb1f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009052567" comment="java-1_6_0-sun-alsa less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052568" comment="java-1_6_0-sun-demo less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052569" comment="java-1_6_0-sun-jdbc less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052570" comment="java-1_6_0-sun-plugin less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052571" comment="java-1_6_0-sun-src less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052572" comment="java-1_6_0-sun less than 1.6.0.u13-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091097" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1097</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1097" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1097" source="CVE"/>
	<description>
	Multiple buffer overflows in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allow remote attackers to access files or execute arbitrary code via (1) a crafted PNG image that triggers an integer overflow during memory allocation for display on the splash screen, aka CR 6804996; and (2) a crafted GIF image from which unspecified values are used in calculation of offsets, leading to object-pointer corruption, aka CR 6804997.
	</description>
 </metadata>
<!-- 3c82d19b21fda3ba8795ae3acfbbfb1f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009052567" comment="java-1_6_0-sun-alsa less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052568" comment="java-1_6_0-sun-demo less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052569" comment="java-1_6_0-sun-jdbc less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052570" comment="java-1_6_0-sun-plugin less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052571" comment="java-1_6_0-sun-src less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052572" comment="java-1_6_0-sun less than 1.6.0.u13-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091098" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1098</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1098" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1098" source="CVE"/>
	<description>
	Buffer overflow in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; 1.4.2_19 and earlier; and 1.3.1_24 and earlier allows remote attackers to access files or execute arbitrary code via a crafted GIF image, aka CR 6804998.
	</description>
 </metadata>
<!-- 3c82d19b21fda3ba8795ae3acfbbfb1f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009052567" comment="java-1_6_0-sun-alsa less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052568" comment="java-1_6_0-sun-demo less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052569" comment="java-1_6_0-sun-jdbc less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052570" comment="java-1_6_0-sun-plugin less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052571" comment="java-1_6_0-sun-src less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052572" comment="java-1_6_0-sun less than 1.6.0.u13-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091099" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1099</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1099" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1099" source="CVE"/>
	<description>
	Integer signedness error in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via crafted glyph descriptions in a Type1 font, which bypasses a signed comparison and triggers a buffer overflow.
	</description>
 </metadata>
<!-- 3c82d19b21fda3ba8795ae3acfbbfb1f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009052567" comment="java-1_6_0-sun-alsa less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052568" comment="java-1_6_0-sun-demo less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052569" comment="java-1_6_0-sun-jdbc less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052570" comment="java-1_6_0-sun-plugin less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052571" comment="java-1_6_0-sun-src less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052572" comment="java-1_6_0-sun less than 1.6.0.u13-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091100" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1100</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1100" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1100" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allow remote attackers to cause a denial of service (disk consumption) via vectors related to temporary font files and (1) "limits on Font creation," aka CR 6522586, and (2) another unspecified vector, aka CR 6632886.
	</description>
 </metadata>
<!-- 3c82d19b21fda3ba8795ae3acfbbfb1f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009052567" comment="java-1_6_0-sun-alsa less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052568" comment="java-1_6_0-sun-demo less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052569" comment="java-1_6_0-sun-jdbc less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052570" comment="java-1_6_0-sun-plugin less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052571" comment="java-1_6_0-sun-src less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052572" comment="java-1_6_0-sun less than 1.6.0.u13-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091101" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1101</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1101" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1101" source="CVE"/>
	<description>
	Unspecified vulnerability in the lightweight HTTP server implementation in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allows remote attackers to cause a denial of service (probably resource consumption) for a JAX-WS service endpoint via a connection without any data, which triggers a file descriptor "leak."
	</description>
 </metadata>
<!-- 3c82d19b21fda3ba8795ae3acfbbfb1f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009052567" comment="java-1_6_0-sun-alsa less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052568" comment="java-1_6_0-sun-demo less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052569" comment="java-1_6_0-sun-jdbc less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052570" comment="java-1_6_0-sun-plugin less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052571" comment="java-1_6_0-sun-src less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052572" comment="java-1_6_0-sun less than 1.6.0.u13-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091102" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1102</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1102" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1102" source="CVE"/>
	<description>
	Unspecified vulnerability in the Virtual Machine in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allows remote attackers to access files and execute arbitrary code via unknown vectors related to "code generation."
	</description>
 </metadata>
<!-- 3c82d19b21fda3ba8795ae3acfbbfb1f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009052567" comment="java-1_6_0-sun-alsa less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052568" comment="java-1_6_0-sun-demo less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052569" comment="java-1_6_0-sun-jdbc less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052570" comment="java-1_6_0-sun-plugin less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052571" comment="java-1_6_0-sun-src less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052572" comment="java-1_6_0-sun less than 1.6.0.u13-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091103" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1103</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1103" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1103" source="CVE"/>
	<description>
	Unspecified vulnerability in the Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; 1.4.2_19 and earlier; and 1.3.1_24 and earlier allows remote attackers to access files and execute arbitrary code via unknown vectors related to "deserializing applets," aka CR 6646860.
	</description>
 </metadata>
<!-- 3c82d19b21fda3ba8795ae3acfbbfb1f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009052567" comment="java-1_6_0-sun-alsa less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052568" comment="java-1_6_0-sun-demo less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052569" comment="java-1_6_0-sun-jdbc less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052570" comment="java-1_6_0-sun-plugin less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052571" comment="java-1_6_0-sun-src less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052572" comment="java-1_6_0-sun less than 1.6.0.u13-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091104" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1104</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1104" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1104" source="CVE"/>
	<description>
	The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; and 1.4.2_19 and earlier does not prevent Javascript that is loaded from the localhost from connecting to other ports on the system, which allows user-assisted attackers to bypass intended access restrictions via LiveConnect, aka CR 6724331.  NOTE: this vulnerability can be leveraged with separate cross-site scripting (XSS) vulnerabilities for remote attack vectors.
	</description>
 </metadata>
<!-- 3c82d19b21fda3ba8795ae3acfbbfb1f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009052567" comment="java-1_6_0-sun-alsa less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052568" comment="java-1_6_0-sun-demo less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052569" comment="java-1_6_0-sun-jdbc less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052570" comment="java-1_6_0-sun-plugin less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052571" comment="java-1_6_0-sun-src less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052572" comment="java-1_6_0-sun less than 1.6.0.u13-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091105" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1105</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1105" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1105" source="CVE"/>
	<description>
	The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12, 11, and 10 allows user-assisted remote attackers to cause a trusted applet to run in an older JRE version, which can be used to exploit vulnerabilities in that older version, aka CR 6706490.
	</description>
 </metadata>
<!-- 3c82d19b21fda3ba8795ae3acfbbfb1f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009052567" comment="java-1_6_0-sun-alsa less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052568" comment="java-1_6_0-sun-demo less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052569" comment="java-1_6_0-sun-jdbc less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052570" comment="java-1_6_0-sun-plugin less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052571" comment="java-1_6_0-sun-src less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052572" comment="java-1_6_0-sun less than 1.6.0.u13-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091106" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1106</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1106" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1106" source="CVE"/>
	<description>
	The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12, 11, and 10 does not properly parse crossdomain.xml files, which allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unknown vectors, aka CR 6798948.
	</description>
 </metadata>
<!-- 3c82d19b21fda3ba8795ae3acfbbfb1f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009052567" comment="java-1_6_0-sun-alsa less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052568" comment="java-1_6_0-sun-demo less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052569" comment="java-1_6_0-sun-jdbc less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052570" comment="java-1_6_0-sun-plugin less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052571" comment="java-1_6_0-sun-src less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052572" comment="java-1_6_0-sun less than 1.6.0.u13-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091107" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1107</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1107" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1107" source="CVE"/>
	<description>
	The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier, and 5.0 Update 17 and earlier, allows remote attackers to trick a user into trusting a signed applet via unknown vectors that misrepresent the security warning dialog, related to a "Swing JLabel HTML parsing vulnerability," aka CR 6782871.
	</description>
 </metadata>
<!-- 3c82d19b21fda3ba8795ae3acfbbfb1f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009052567" comment="java-1_6_0-sun-alsa less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052568" comment="java-1_6_0-sun-demo less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052569" comment="java-1_6_0-sun-jdbc less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052570" comment="java-1_6_0-sun-plugin less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052571" comment="java-1_6_0-sun-src less than 1.6.0.u13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052572" comment="java-1_6_0-sun less than 1.6.0.u13-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091169" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1169</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1169" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1169" source="CVE"/>
	<description>
	The txMozillaXSLTProcessor::TransformToDoc function in Mozilla Firefox before 3.0.8 and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XML file with a crafted XSLT transform.
	</description>
 </metadata>
<!-- 272bd7f6089e8316b21585826776f472 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032330" comment="MozillaFirefox-translations less than 3.0.8-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032331" comment="MozillaFirefox less than 3.0.8-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032332" comment="mozilla-xulrunner190-32bit less than 1.9.0.8-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052541" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.8-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032333" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.8-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052543" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.8-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032334" comment="mozilla-xulrunner190-translations less than 1.9.0.8-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032336" comment="mozilla-xulrunner190 less than 1.9.0.8-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091179" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1179</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1179" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1179" source="CVE"/>
	<description>
	Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file.
	</description>
 </metadata>
<!-- f27d99aa7f35ddbc6bc5e4ac681ee974 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032208" comment="libpoppler4 less than 0.10.1-1.30.5"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091180" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1180</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1180" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1180" source="CVE"/>
	<description>
	The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file that triggers a free of invalid data.
	</description>
 </metadata>
<!-- f27d99aa7f35ddbc6bc5e4ac681ee974 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032208" comment="libpoppler4 less than 0.10.1-1.30.5"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091181" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1181</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1181" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1181" source="CVE"/>
	<description>
	The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a NULL pointer dereference.
	</description>
 </metadata>
<!-- f27d99aa7f35ddbc6bc5e4ac681ee974 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032208" comment="libpoppler4 less than 0.10.1-1.30.5"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091182" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1182</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1182" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1182" source="CVE"/>
	<description>
	Multiple buffer overflows in the JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file.
	</description>
 </metadata>
<!-- f27d99aa7f35ddbc6bc5e4ac681ee974 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032208" comment="libpoppler4 less than 0.10.1-1.30.5"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091183" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1183</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1183" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1183" source="CVE"/>
	<description>
	The JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted PDF file.
	</description>
 </metadata>
<!-- f27d99aa7f35ddbc6bc5e4ac681ee974 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032208" comment="libpoppler4 less than 0.10.1-1.30.5"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091185" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1185</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1185" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1185" source="CVE"/>
	<description>
	udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.
	</description>
 </metadata>
<!-- f2a20a677f8f07b34c3543e781db446f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032337" comment="libvolume_id1 less than 128-13.2.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032338" comment="udev less than 128-13.2.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091189" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1189</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2009-1189" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1189" source="CVE"/>
	<description>
	The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) in D-Bus (aka DBus) before 1.2.14 uses incorrect logic to validate a basic type, which allows remote attackers to spoof a signature via a crafted key.  NOTE: this is due to an incorrect fix for CVE-2008-3834.
	</description>
 </metadata>
<!-- 54eee4e87a0d78b170de796964bdfc46 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009067850" comment="dbus-1-32bit less than 1.2.10-3.17.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009067851" comment="dbus-1-x11 less than 1.2.10-3.17.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009067853" comment="dbus-1 less than 1.2.10-3.17.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091192" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1192</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1192" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1192" source="CVE"/>
	<description>
	The (1) agp_generic_alloc_page and (2) agp_generic_alloc_pages functions in drivers/char/agp/generic.c in the agp subsystem in the Linux kernel before 2.6.30-rc3 do not zero out pages that may later be available to a user-space process, which allows local users to obtain sensitive information by reading these pages.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 80db93c687bbdeb62c79f877c742f4bb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032356" comment="kernel-pae-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032341" comment="kernel-pae-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032357" comment="kernel-pae less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032360" comment="kernel-xen-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032342" comment="kernel-xen-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032361" comment="kernel-xen less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 9e40eecb7327c57e210599e2f65e0e81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032360" comment="kernel-xen-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032342" comment="kernel-xen-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032361" comment="kernel-xen less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091194" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1194</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1194" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1194" source="CVE"/>
	<description>
	Integer overflow in the pango_glyph_string_set_size function in pango/glyphstring.c in Pango before 1.24 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long glyph string that triggers a heap-based buffer overflow, as demonstrated by a long document.location value in Firefox.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- a9f9ebf1fe153fd04f53f3b5b237c97d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032362" comment="pango-32bit less than 1.22.1-3.17.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052779" comment="pango-devel less than 1.22.1-3.17.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032365" comment="pango less than 1.22.1-3.17.3"/>
		</criteria>
	</criteria>
	<!-- cdb08e2f6996992396d9c5cfd1a06c5d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057910" comment="pango-32bit less than 1.22.1-3.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057945" comment="pango-devel less than 1.22.1-3.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057913" comment="pango less than 1.22.1-3.18.1"/>
		</criteria>
	</criteria>
	<!-- d3be5c712e2e2706b7b11ecd08d9e22f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053589" comment="MozillaFirefox-translations less than 3.0.12-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053590" comment="MozillaFirefox less than 3.0.12-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053591" comment="mozilla-xulrunner190-32bit less than 1.9.0.12-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053597" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.12-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053592" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.12-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053599" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.12-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053593" comment="mozilla-xulrunner190-translations less than 1.9.0.12-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053595" comment="mozilla-xulrunner190 less than 1.9.0.12-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091210" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1210</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1210" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1210" source="CVE"/>
	<description>
	Format string vulnerability in the PROFINET/DCP (PN-DCP) dissector in Wireshark 1.0.6 and earlier allows remote attackers to execute arbitrary code via a PN-DCP packet with format string specifiers in the station name.  NOTE: some of these details are obtained from third party information.
	</description>
 </metadata>
<!-- 9af723e66556cd28d89b219f9e202d7e -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032366" comment="wireshark less than 1.0.5-1.26.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091241" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1241</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1241" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1241" source="CVE"/>
	<description>
	Unspecified vulnerability in ClamAV before 0.95 allows remote attackers to bypass detection of malware via a modified RAR archive.
	</description>
 </metadata>
<!-- e036f8c1ee8c76653c4e246982056c02 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032190" comment="clamav less than 0.95-0.2.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091242" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1242</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1242" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1242" source="CVE"/>
	<description>
	The vmx_set_msr function in arch/x86/kvm/vmx.c in the VMX implementation in the KVM subsystem in the Linux kernel before 2.6.29.1 on the i386 platform allows guest OS users to cause a denial of service (OOPS) by setting the EFER_LME (aka "Long mode enable") bit in the Extended Feature Enable Register (EFER) model-specific register, which is specific to the x86_64 platform.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 80db93c687bbdeb62c79f877c742f4bb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032356" comment="kernel-pae-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032341" comment="kernel-pae-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032357" comment="kernel-pae less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032360" comment="kernel-xen-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032342" comment="kernel-xen-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032361" comment="kernel-xen less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 9e40eecb7327c57e210599e2f65e0e81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032360" comment="kernel-xen-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032342" comment="kernel-xen-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032361" comment="kernel-xen less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091252" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1252</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1252" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1252" source="CVE"/>
	<description>
	Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd in NTP before 4.2.4p7 and 4.2.5 before 4.2.5p74, when OpenSSL and autokey are enabled, allows remote attackers to execute arbitrary code via a crafted packet containing an extension field.
	</description>
 </metadata>
<!-- d95ed4c45d984fda65f18722242769a5 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032209" comment="ntp-doc less than 4.2.4p6-1.17.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032210" comment="ntp less than 4.2.4p6-1.17.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091265" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1265</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1265" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1265" source="CVE"/>
	<description>
	Integer overflow in rose_sendmsg (sys/net/af_rose.c) in the Linux kernel 2.6.24.4, and other versions before 2.6.30-rc1, might allow remote attackers to obtain sensitive information via a large length value, which causes "garbage" memory to be sent.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 80db93c687bbdeb62c79f877c742f4bb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032356" comment="kernel-pae-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032341" comment="kernel-pae-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032357" comment="kernel-pae less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032360" comment="kernel-xen-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032342" comment="kernel-xen-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032361" comment="kernel-xen less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 9e40eecb7327c57e210599e2f65e0e81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032360" comment="kernel-xen-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032342" comment="kernel-xen-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032361" comment="kernel-xen less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091266" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1266</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1266" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1266" source="CVE"/>
	<description>
	Unspecified vulnerability in Wireshark before 1.0.7-0.1-1 has unknown impact and attack vectors.
	</description>
 </metadata>
<!-- 9af723e66556cd28d89b219f9e202d7e -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032366" comment="wireshark less than 1.0.5-1.26.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091267" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1267</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1267" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1267" source="CVE"/>
	<description>
	Unspecified vulnerability in the LDAP dissector in Wireshark 0.99.2 through 1.0.6, when running on Windows, allows remote attackers to cause a denial of service (crash) via unknown attack vectors.
	</description>
 </metadata>
<!-- 9af723e66556cd28d89b219f9e202d7e -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032366" comment="wireshark less than 1.0.5-1.26.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091268" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1268</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1268" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1268" source="CVE"/>
	<description>
	The Check Point High-Availability Protocol (CPHAP) dissector in Wireshark 0.9.6 through 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted FWHA_MY_STATE packet.
	</description>
 </metadata>
<!-- 9af723e66556cd28d89b219f9e202d7e -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032366" comment="wireshark less than 1.0.5-1.26.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091269" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1269</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1269" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1269" source="CVE"/>
	<description>
	Unspecified vulnerability in Wireshark 0.99.6 through 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted Tektronix .rf5 file.
	</description>
 </metadata>
<!-- 9af723e66556cd28d89b219f9e202d7e -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032366" comment="wireshark less than 1.0.5-1.26.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091270" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1270</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1270" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1270" source="CVE"/>
	<description>
	libclamav/untar.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (infinite loop) via a crafted TAR file that causes (1) clamd and (2) clamscan to hang.
	</description>
 </metadata>
<!-- e036f8c1ee8c76653c4e246982056c02 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032190" comment="clamav less than 0.95-0.2.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091274" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1274</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1274" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1274" source="CVE"/>
	<description>
	Integer overflow in the qt_error parse_trak_atom function in demuxers/demux_qt.c in xine-lib 1.1.16.2 and earlier allows remote attackers to execute arbitrary code via a Quicktime movie file with a large count value in an STTS atom, which triggers a heap-based buffer overflow.
	</description>
 </metadata>
<!-- ad70154324c99f39d4df3011cd62bccc -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052788" comment="libxine1 less than 1.1.15-23.2.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091297" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1297</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1297" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1297" source="CVE"/>
	<description>
	iscsi_discovery in open-iscsi in SUSE openSUSE 10.3 through 11.1 and SUSE Linux Enterprise (SLE) 10 SP2 and 11 allows local users to overwrite arbitrary files via a symlink attack on an unspecified temporary file that has a predictable name.
	</description>
 </metadata>
<!-- fbcc4c51379d17385396bb257e2bd261 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054839" comment="open-iscsi less than 2.0.870-26.6.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091302" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1302</title>
	<affected family="unix">
		<platform>SLE 11 DESKTOP Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1302" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1302" source="CVE"/>
	<description>
	The browser engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to (1) nsAsyncInstantiateEvent::Run, (2) nsStyleContext::Destroy, (3) nsComputedDOMStyle::GetWidth, (4) the xslt_attributeset_ImportSameName.html test case for the XSLT stylesheet compiler, (5) nsXULDocument::SynchronizeBroadcastListener, (6) IsBindingAncestor, (7) PL_DHashTableOperate and nsEditor::EndUpdateViewBatch, and (8) gfxSkipCharsIterator::SetOffsets, and other vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8d58759fa070160f1f7d27df1de3a166 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032267" comment="MozillaFirefox-translations less than 3.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032268" comment="MozillaFirefox less than 3.0.9-0.1.1"/>
		</criteria>
	</criteria>
	<!-- bd731d7f7868bdb421d1037cfa3c2413 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053248" comment="MozillaThunderbird-translations less than 2.0.0.22-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053249" comment="MozillaThunderbird less than 2.0.0.22-0.1.1"/>
		</criteria>
	</criteria>
	<!-- fab01148f9c2f94e57e7070118a7818e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032269" comment="mozilla-xulrunner190-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052298" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032270" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052299" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032271" comment="mozilla-xulrunner190-translations less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032273" comment="mozilla-xulrunner190 less than 1.9.0.9-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091303" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1303</title>
	<affected family="unix">
		<platform>SLE 11 DESKTOP Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1303" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1303" source="CVE"/>
	<description>
	The browser engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to nsSVGElement::BindToTree.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8d58759fa070160f1f7d27df1de3a166 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032267" comment="MozillaFirefox-translations less than 3.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032268" comment="MozillaFirefox less than 3.0.9-0.1.1"/>
		</criteria>
	</criteria>
	<!-- bd731d7f7868bdb421d1037cfa3c2413 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053248" comment="MozillaThunderbird-translations less than 2.0.0.22-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053249" comment="MozillaThunderbird less than 2.0.0.22-0.1.1"/>
		</criteria>
	</criteria>
	<!-- fab01148f9c2f94e57e7070118a7818e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032269" comment="mozilla-xulrunner190-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052298" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032270" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052299" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032271" comment="mozilla-xulrunner190-translations less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032273" comment="mozilla-xulrunner190 less than 1.9.0.9-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091304" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1304</title>
	<affected family="unix">
		<platform>SLE 11 DESKTOP Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1304" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1304" source="CVE"/>
	<description>
	The JavaScript engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors involving (1) js_FindPropertyHelper, related to the definitions of Math and Date; and (2) js_CheckRedeclaration.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8d58759fa070160f1f7d27df1de3a166 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032267" comment="MozillaFirefox-translations less than 3.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032268" comment="MozillaFirefox less than 3.0.9-0.1.1"/>
		</criteria>
	</criteria>
	<!-- bd731d7f7868bdb421d1037cfa3c2413 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053248" comment="MozillaThunderbird-translations less than 2.0.0.22-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053249" comment="MozillaThunderbird less than 2.0.0.22-0.1.1"/>
		</criteria>
	</criteria>
	<!-- fab01148f9c2f94e57e7070118a7818e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032269" comment="mozilla-xulrunner190-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052298" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032270" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052299" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032271" comment="mozilla-xulrunner190-translations less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032273" comment="mozilla-xulrunner190 less than 1.9.0.9-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091305" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1305</title>
	<affected family="unix">
		<platform>SLE 11 DESKTOP Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1305" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1305" source="CVE"/>
	<description>
	The JavaScript engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors involving JSOP_DEFVAR and properties that lack the JSPROP_PERMANENT attribute.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8d58759fa070160f1f7d27df1de3a166 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032267" comment="MozillaFirefox-translations less than 3.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032268" comment="MozillaFirefox less than 3.0.9-0.1.1"/>
		</criteria>
	</criteria>
	<!-- bd731d7f7868bdb421d1037cfa3c2413 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053248" comment="MozillaThunderbird-translations less than 2.0.0.22-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053249" comment="MozillaThunderbird less than 2.0.0.22-0.1.1"/>
		</criteria>
	</criteria>
	<!-- fab01148f9c2f94e57e7070118a7818e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032269" comment="mozilla-xulrunner190-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052298" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032270" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052299" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032271" comment="mozilla-xulrunner190-translations less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032273" comment="mozilla-xulrunner190 less than 1.9.0.9-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091306" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1306</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1306" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1306" source="CVE"/>
	<description>
	The jar: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not follow the Content-Disposition header of the inner URI, which allows remote attackers to conduct cross-site scripting (XSS) attacks and possibly other attacks via an uploaded .jar file with a "Content-Disposition: attachment" designation.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8d58759fa070160f1f7d27df1de3a166 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032267" comment="MozillaFirefox-translations less than 3.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032268" comment="MozillaFirefox less than 3.0.9-0.1.1"/>
		</criteria>
	</criteria>
	<!-- fab01148f9c2f94e57e7070118a7818e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032269" comment="mozilla-xulrunner190-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052298" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032270" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052299" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032271" comment="mozilla-xulrunner190-translations less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032273" comment="mozilla-xulrunner190 less than 1.9.0.9-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091307" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1307</title>
	<affected family="unix">
		<platform>SLE 11 DESKTOP Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1307" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1307" source="CVE"/>
	<description>
	The view-source: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not properly implement the Same Origin Policy, which allows remote attackers to (1) bypass crossdomain.xml restrictions and connect to arbitrary web sites via a Flash file; (2) read, create, or modify Local Shared Objects via a Flash file; or (3) bypass unspecified restrictions and render content via vectors involving a jar: URI.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8d58759fa070160f1f7d27df1de3a166 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032267" comment="MozillaFirefox-translations less than 3.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032268" comment="MozillaFirefox less than 3.0.9-0.1.1"/>
		</criteria>
	</criteria>
	<!-- bd731d7f7868bdb421d1037cfa3c2413 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053248" comment="MozillaThunderbird-translations less than 2.0.0.22-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053249" comment="MozillaThunderbird less than 2.0.0.22-0.1.1"/>
		</criteria>
	</criteria>
	<!-- fab01148f9c2f94e57e7070118a7818e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032269" comment="mozilla-xulrunner190-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052298" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032270" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052299" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032271" comment="mozilla-xulrunner190-translations less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032273" comment="mozilla-xulrunner190 less than 1.9.0.9-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091308" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1308</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1308" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1308" source="CVE"/>
	<description>
	Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey allows remote attackers to inject arbitrary web script or HTML via vectors involving XBL JavaScript bindings and remote stylesheets, as exploited in the wild by a March 2009 eBay listing.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8d58759fa070160f1f7d27df1de3a166 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032267" comment="MozillaFirefox-translations less than 3.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032268" comment="MozillaFirefox less than 3.0.9-0.1.1"/>
		</criteria>
	</criteria>
	<!-- fab01148f9c2f94e57e7070118a7818e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032269" comment="mozilla-xulrunner190-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052298" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032270" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052299" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032271" comment="mozilla-xulrunner190-translations less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032273" comment="mozilla-xulrunner190 less than 1.9.0.9-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091309" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1309</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1309" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1309" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey do not properly implement the Same Origin Policy for (1) XMLHttpRequest, involving a mismatch for a document's principal, and (2) XPCNativeWrapper.toString, involving an incorrect __proto__ scope, which allows remote attackers to conduct cross-site scripting (XSS) attacks and possibly other attacks via a crafted document.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8d58759fa070160f1f7d27df1de3a166 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032267" comment="MozillaFirefox-translations less than 3.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032268" comment="MozillaFirefox less than 3.0.9-0.1.1"/>
		</criteria>
	</criteria>
	<!-- fab01148f9c2f94e57e7070118a7818e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032269" comment="mozilla-xulrunner190-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052298" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032270" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052299" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032271" comment="mozilla-xulrunner190-translations less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032273" comment="mozilla-xulrunner190 less than 1.9.0.9-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091310" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1310</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1310" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1310" source="CVE"/>
	<description>
	Cross-site scripting (XSS) vulnerability in the MozSearch plugin implementation in Mozilla Firefox before 3.0.9 allows user-assisted remote attackers to inject arbitrary web script or HTML via a javascript: URI in the SearchForm element.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8d58759fa070160f1f7d27df1de3a166 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032267" comment="MozillaFirefox-translations less than 3.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032268" comment="MozillaFirefox less than 3.0.9-0.1.1"/>
		</criteria>
	</criteria>
	<!-- fab01148f9c2f94e57e7070118a7818e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032269" comment="mozilla-xulrunner190-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052298" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032270" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052299" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032271" comment="mozilla-xulrunner190-translations less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032273" comment="mozilla-xulrunner190 less than 1.9.0.9-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091311" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1311</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1311" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1311" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.9 and SeaMonkey before 1.1.17 allow user-assisted remote attackers to obtain sensitive information via a web page with an embedded frame, which causes POST data from an outer page to be sent to the inner frame's URL during a SAVEMODE_FILEONLY save of the inner frame.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8d58759fa070160f1f7d27df1de3a166 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032267" comment="MozillaFirefox-translations less than 3.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032268" comment="MozillaFirefox less than 3.0.9-0.1.1"/>
		</criteria>
	</criteria>
	<!-- fab01148f9c2f94e57e7070118a7818e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032269" comment="mozilla-xulrunner190-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052298" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032270" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052299" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032271" comment="mozilla-xulrunner190-translations less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032273" comment="mozilla-xulrunner190 less than 1.9.0.9-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091312" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1312</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1312" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1312" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.9 and SeaMonkey 1.1.17 do not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header. NOTE: it was later reported that Firefox 3.6 a1 pre and Mozilla 1.7.x and earlier are also affected.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8d58759fa070160f1f7d27df1de3a166 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032267" comment="MozillaFirefox-translations less than 3.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032268" comment="MozillaFirefox less than 3.0.9-0.1.1"/>
		</criteria>
	</criteria>
	<!-- fab01148f9c2f94e57e7070118a7818e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032269" comment="mozilla-xulrunner190-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052298" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032270" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052299" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032271" comment="mozilla-xulrunner190-translations less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032273" comment="mozilla-xulrunner190 less than 1.9.0.9-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091313" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1313</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1313" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1313" source="CVE"/>
	<description>
	The nsTextFrame::ClearTextRun function in layout/generic/nsTextFrameThebes.cpp in Mozilla Firefox 3.0.9 allows remote attackers to cause a denial of service (memory corruption) and probably execute arbitrary code via unspecified vectors.  NOTE: this vulnerability reportedly exists because of an incorrect fix for CVE-2009-1302.
	</description>
 </metadata>
<!-- c36aac5ba4baab1921d49192891f9295 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032367" comment="MozillaFirefox-translations less than 3.0.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032368" comment="MozillaFirefox less than 3.0.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032369" comment="mozilla-xulrunner190-32bit less than 1.9.0.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052828" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032370" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052829" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032371" comment="mozilla-xulrunner190-translations less than 1.9.0.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032373" comment="mozilla-xulrunner190 less than 1.9.0.10-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091337" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1337</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1337" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1337" source="CVE"/>
	<description>
	The exit_notify function in kernel/exit.c in the Linux kernel before 2.6.30-rc1 does not restrict exit signals when the CAP_KILL capability is held, which allows local users to send an arbitrary signal to a process by running a program that modifies the exit_signal field and then uses an exec system call to launch a setuid application.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 80db93c687bbdeb62c79f877c742f4bb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032356" comment="kernel-pae-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032341" comment="kernel-pae-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032357" comment="kernel-pae less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032360" comment="kernel-xen-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032342" comment="kernel-xen-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032361" comment="kernel-xen less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 9e40eecb7327c57e210599e2f65e0e81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032360" comment="kernel-xen-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032342" comment="kernel-xen-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032361" comment="kernel-xen less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091360" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1360</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1360" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1360" source="CVE"/>
	<description>
	The __inet6_check_established function in net/ipv6/inet6_hashtables.c in the Linux kernel before 2.6.29, when Network Namespace Support (aka NET_NS) is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via vectors involving IPv6 packets.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 80db93c687bbdeb62c79f877c742f4bb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032356" comment="kernel-pae-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032341" comment="kernel-pae-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032357" comment="kernel-pae less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032360" comment="kernel-xen-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032342" comment="kernel-xen-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032361" comment="kernel-xen less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 9e40eecb7327c57e210599e2f65e0e81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032360" comment="kernel-xen-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032342" comment="kernel-xen-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032361" comment="kernel-xen less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091364" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1364</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1364" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1364" source="CVE"/>
	<description>
	Use-after-free vulnerability in the embedded GD library in libwmf 0.2.8.4 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted WMF file.
	</description>
 </metadata>
<!-- d93ec92b7d5eec7a9c6f74410c95e732 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052853" comment="libwmf less than 0.2.8.4-206.27.4"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091373" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1373</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1373" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1373" source="CVE"/>
	<description>
	Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) before 2.5.6 allows remote authenticated users to execute arbitrary code via vectors involving an outbound XMPP file transfer.  NOTE: some of these details are obtained from third party information.
	</description>
 </metadata>
<!-- 387045b930341190664017ca29b12c16 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053476" comment="finch less than 2.5.1-9.11.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053478" comment="libpurple-lang less than 2.5.1-9.11.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053479" comment="libpurple less than 2.5.1-9.11.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053481" comment="pidgin less than 2.5.1-9.11.3"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091375" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1375</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1375" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1375" source="CVE"/>
	<description>
	The PurpleCircBuffer implementation in Pidgin (formerly Gaim) before 2.5.6 does not properly maintain a certain buffer, which allows remote attackers to cause a denial of service (memory corruption and application crash) via vectors involving the (1) XMPP or (2) Sametime protocol.
	</description>
 </metadata>
<!-- 387045b930341190664017ca29b12c16 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053476" comment="finch less than 2.5.1-9.11.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053478" comment="libpurple-lang less than 2.5.1-9.11.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053479" comment="libpurple less than 2.5.1-9.11.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053481" comment="pidgin less than 2.5.1-9.11.3"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091376" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1376</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1376" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1376" source="CVE"/>
	<description>
	Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin (formerly Gaim) before 2.5.6 on 32-bit platforms allow remote attackers to execute arbitrary code via a malformed SLP message with a crafted offset value, leading to buffer overflows.  NOTE: this issue exists because of an incomplete fix for CVE-2008-2927.
	</description>
 </metadata>
<!-- 387045b930341190664017ca29b12c16 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053476" comment="finch less than 2.5.1-9.11.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053478" comment="libpurple-lang less than 2.5.1-9.11.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053479" comment="libpurple less than 2.5.1-9.11.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053481" comment="pidgin less than 2.5.1-9.11.3"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091377" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1377</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1377" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1377" source="CVE"/>
	<description>
	The dtls1_buffer_record function in ssl/d1_pkt.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allows remote attackers to cause a denial of service (memory consumption) via a large series of "future epoch" DTLS records that are buffered in a queue, aka "DTLS record buffer limitation bug."
	</description>
 </metadata>
<!-- d4ddbfaf8e97ad6cc1b69035fcaf1610 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032374" comment="libopenssl0_9_8-32bit less than 0.9.8h-30.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032376" comment="libopenssl0_9_8 less than 0.9.8h-30.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032378" comment="openssl less than 0.9.8h-30.13.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091378" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1378</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1378" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1378" source="CVE"/>
	<description>
	Multiple memory leaks in the dtls1_process_out_of_seq_message function in ssl/d1_both.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allow remote attackers to cause a denial of service (memory consumption) via DTLS records that (1) are duplicates or (2) have sequence numbers much greater than current sequence numbers, aka "DTLS fragment handling memory leak."
	</description>
 </metadata>
<!-- d4ddbfaf8e97ad6cc1b69035fcaf1610 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032374" comment="libopenssl0_9_8-32bit less than 0.9.8h-30.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032376" comment="libopenssl0_9_8 less than 0.9.8h-30.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032378" comment="openssl less than 0.9.8h-30.13.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091379" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1379</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1379" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1379" source="CVE"/>
	<description>
	Use-after-free vulnerability in the dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL 1.0.0 Beta 2 allows remote attackers to cause a denial of service (openssl s_client crash) and possibly have unspecified other impact via a DTLS packet, as demonstrated by a packet from a server that uses a crafted server certificate.
	</description>
 </metadata>
<!-- d4ddbfaf8e97ad6cc1b69035fcaf1610 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032374" comment="libopenssl0_9_8-32bit less than 0.9.8h-30.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032376" comment="libopenssl0_9_8 less than 0.9.8h-30.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032378" comment="openssl less than 0.9.8h-30.13.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091385" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1385</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1385" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1385" source="CVE"/>
	<description>
	Integer underflow in the e1000_clean_rx_irq function in drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel before 2.6.30-rc8, the e1000e driver in the Linux kernel, and Intel Wired Ethernet (aka e1000) before 7.5.5 allows remote attackers to cause a denial of service (panic) via a crafted frame size.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 23bbed017e105329dd9057458aa97ecc -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053523" comment="kernel-default-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053546" comment="kernel-default-extra less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053524" comment="kernel-default less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053525" comment="kernel-source less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053526" comment="kernel-syms less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053527" comment="kernel-xen-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053547" comment="kernel-xen-extra less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053528" comment="kernel-xen less than 2.6.27.25-0.1.1"/>
		</criteria>
	</criteria>
	<!-- efe472a6c3ff8e53697cca9b64ed6db5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053523" comment="kernel-default-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053546" comment="kernel-default-extra less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053524" comment="kernel-default less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053536" comment="kernel-pae-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053564" comment="kernel-pae-extra less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053537" comment="kernel-pae less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053525" comment="kernel-source less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053526" comment="kernel-syms less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053527" comment="kernel-xen-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053547" comment="kernel-xen-extra less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053528" comment="kernel-xen less than 2.6.27.25-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091386" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1386</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1386" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1386" source="CVE"/>
	<description>
	ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS ChangeCipherSpec packet that occurs before ClientHello.
	</description>
 </metadata>
<!-- 3d101627652fdb3b5c37983fb7f4ab19 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032379" comment="libopenssl0_9_8-32bit less than 0.9.8h-30.14.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032381" comment="libopenssl0_9_8 less than 0.9.8h-30.14.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032383" comment="openssl less than 0.9.8h-30.14.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091387" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1387</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1387" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1387" source="CVE"/>
	<description>
	The dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL before 1.0.0 Beta 2 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence DTLS handshake message, related to a "fragment bug."
	</description>
 </metadata>
<!-- 3d101627652fdb3b5c37983fb7f4ab19 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032379" comment="libopenssl0_9_8-32bit less than 0.9.8h-30.14.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032381" comment="libopenssl0_9_8 less than 0.9.8h-30.14.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032383" comment="openssl less than 0.9.8h-30.14.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091389" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1389</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1389" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1389" source="CVE"/>
	<description>
	Buffer overflow in the RTL8169 NIC driver (drivers/net/r8169.c) in the Linux kernel before 2.6.30 allows remote attackers to cause a denial of service (kernel memory corruption and crash) via a long packet.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0522f4d2681968d0e344aad24e0e341b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054108" comment="kernel-default-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054182" comment="kernel-default-extra less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054109" comment="kernel-default less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054110" comment="kernel-pae-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054183" comment="kernel-pae-extra less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054111" comment="kernel-pae less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054112" comment="kernel-source less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054113" comment="kernel-syms less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054116" comment="kernel-xen-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054184" comment="kernel-xen-extra less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054117" comment="kernel-xen less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 125c8b5a7b30fdb1de7b2255eb1649a7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054108" comment="kernel-default-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054182" comment="kernel-default-extra less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054109" comment="kernel-default less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054112" comment="kernel-source less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054113" comment="kernel-syms less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054116" comment="kernel-xen-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054184" comment="kernel-xen-extra less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054117" comment="kernel-xen less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 23bbed017e105329dd9057458aa97ecc -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053523" comment="kernel-default-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053546" comment="kernel-default-extra less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053524" comment="kernel-default less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053525" comment="kernel-source less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053526" comment="kernel-syms less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053527" comment="kernel-xen-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053547" comment="kernel-xen-extra less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053528" comment="kernel-xen less than 2.6.27.25-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 66504af0afe753b5175112b44bc8827d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061675" comment="kernel-default-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061679" comment="kernel-pae-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061680" comment="kernel-pae-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061681" comment="kernel-pae less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061693" comment="kernel-xen-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- c8a29eec659b0b2b3e85c610b67beacd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061675" comment="kernel-default-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061693" comment="kernel-xen-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- efe472a6c3ff8e53697cca9b64ed6db5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053523" comment="kernel-default-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053546" comment="kernel-default-extra less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053524" comment="kernel-default less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053536" comment="kernel-pae-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053564" comment="kernel-pae-extra less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053537" comment="kernel-pae less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053525" comment="kernel-source less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053526" comment="kernel-syms less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053527" comment="kernel-xen-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053547" comment="kernel-xen-extra less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053528" comment="kernel-xen less than 2.6.27.25-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091391" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1391</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1391" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1391" source="CVE"/>
	<description>
	Off-by-one error in the inflate function in Zlib.xs in Compress::Raw::Zlib Perl module before 2.017, as used in AMaViS, SpamAssassin, and possibly other products, allows context-dependent attackers to cause a denial of service (hang or crash) via a crafted zlib compressed stream that triggers a heap-based buffer overflow, as exploited in the wild by Trojan.Downloader-71014 in June 2009.
	</description>
 </metadata>
<!-- 5e29d335b627fec85a5ced02fb051e10 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032384" comment="perl-32bit less than 5.10.0-64.43.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032385" comment="perl-base less than 5.10.0-64.43.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032386" comment="perl-doc less than 5.10.0-64.43.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032388" comment="perl less than 5.10.0-64.43.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091392" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1392</title>
	<affected family="unix">
		<platform>SLE 11 DESKTOP Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1392" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1392" source="CVE"/>
	<description>
	The browser engine in Mozilla Firefox 3 before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsEventStateManager::GetContentState and nsNativeTheme::CheckBooleanAttr; (2) UnhookTextRunFromFrames and ClearAllTextRunReferences; (3) nsTextFrame::ClearTextRun; (4) IsPercentageAware; (5) PL_DHashTableFinish; (6) nsListBoxBodyFrame::GetNextItemBox; (7) AtomTableClearEntry, related to the atom table, DOM mutation events, and Unicode surrogates; (8) nsHTMLEditor::HideResizers; and (9) nsWindow::SetCursor, related to changing the cursor; and other vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- bd731d7f7868bdb421d1037cfa3c2413 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053248" comment="MozillaThunderbird-translations less than 2.0.0.22-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053249" comment="MozillaThunderbird less than 2.0.0.22-0.1.1"/>
		</criteria>
	</criteria>
	<!-- de3e4a68d06355acbebbe6d9a72836b8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032389" comment="MozillaFirefox-translations less than 3.0.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032390" comment="MozillaFirefox less than 3.0.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032391" comment="mozilla-xulrunner190-32bit less than 1.9.0.11-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052932" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.11-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032392" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.11-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052933" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.11-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032393" comment="mozilla-xulrunner190-translations less than 1.9.0.11-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032395" comment="mozilla-xulrunner190 less than 1.9.0.11-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091439" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1439</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1439" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1439" source="CVE"/>
	<description>
	Buffer overflow in fs/cifs/connect.c in CIFS in the Linux kernel 2.6.29 and earlier allows remote attackers to cause a denial of service (crash) via a long nativeFileSystem field in a Tree Connect response to an SMB mount request.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 80db93c687bbdeb62c79f877c742f4bb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032356" comment="kernel-pae-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032341" comment="kernel-pae-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032357" comment="kernel-pae less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032360" comment="kernel-xen-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032342" comment="kernel-xen-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032361" comment="kernel-xen less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 9e40eecb7327c57e210599e2f65e0e81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032360" comment="kernel-xen-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032342" comment="kernel-xen-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032361" comment="kernel-xen less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091492" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1492</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1492" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1492" source="CVE"/>
	<description>
	The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and earlier allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that contains an annotation, and has an OpenAction entry with JavaScript code that calls this method with crafted integer arguments.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 171b567f3ee12695a6604f1e15bda4d3 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052937" comment="acroread less than 8.1.5-0.1.1"/>
	</criteria>
	<!-- beab115e754f4e95a00a5f5ede2fa484 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052939" comment="acroread_ja less than 8.1.5-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091493" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1493</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1493" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1493" source="CVE"/>
	<description>
	The customDictionaryOpen spell method in the JavaScript API in Adobe Reader 9.1, 8.1.4, 7.1.1, and earlier on Linux and UNIX allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that triggers a call to this method with a long string in the second argument.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 171b567f3ee12695a6604f1e15bda4d3 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052937" comment="acroread less than 8.1.5-0.1.1"/>
	</criteria>
	<!-- beab115e754f4e95a00a5f5ede2fa484 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052939" comment="acroread_ja less than 8.1.5-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091563" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1563</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1563" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1563" source="CVE"/>
	<description>
	** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2009-0689.  Reason: This candidate is a duplicate of CVE-2009-0689.  Certain codebase relationships were not originally clear.  Notes: All CVE users should reference CVE-2009-0689 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04c6e38838a85fc92531b3e56904b052 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055940" comment="mozilla-xulrunner190-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055953" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055941" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055955" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055942" comment="mozilla-xulrunner190-translations less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055944" comment="mozilla-xulrunner190 less than 1.9.0.15-0.1.2"/>
		</criteria>
	</criteria>
	<!-- 49179a9289fbe778bc2320690c17d088 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055945" comment="MozillaFirefox-translations less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055946" comment="MozillaFirefox less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055947" comment="mozilla-xulrunner191-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055966" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055948" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055968" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055949" comment="mozilla-xulrunner191-translations less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055951" comment="mozilla-xulrunner191 less than 1.9.1.4-2.1.3"/>
		</criteria>
	</criteria>
	<!-- ea83feacee19ffa926f0205c68b1bb6b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056065" comment="mozilla-nspr-32bit less than 4.8.2-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056067" comment="mozilla-nspr less than 4.8.2-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091570" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1570</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1570" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1570" source="CVE"/>
	<description>
	Integer overflow in the ReadImage function in plug-ins/file-bmp/bmp-read.c in GIMP 2.6.7 might allow remote attackers to execute arbitrary code via a BMP file with crafted width and height values that trigger a heap-based buffer overflow.
	</description>
 </metadata>
<!-- 8ba40ccada7a302ad31567388357c039 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059682" comment="gimp-lang less than 2.6.2-3.28.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059683" comment="gimp-plugins-python less than 2.6.2-3.28.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059684" comment="gimp less than 2.6.2-3.28.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091571" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1571</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1571" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1571" source="CVE"/>
	<description>
	Use-after-free vulnerability in the HTML parser in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to execute arbitrary code via unspecified method calls that attempt to access freed objects in low-memory situations.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5c9ba6a33f35e3ab788cbbefde6cf8a6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058351" comment="MozillaFirefox-translations less than 3.5.8-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058352" comment="MozillaFirefox less than 3.5.8-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058353" comment="mozilla-xulrunner191-32bit less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058436" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058354" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058438" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058355" comment="mozilla-xulrunner191-translations less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058357" comment="mozilla-xulrunner191 less than 1.9.1.8-1.1.1"/>
		</criteria>
	</criteria>
	<!-- deb36b8154e27ded345f064786253ca1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058358" comment="mozilla-xulrunner190-32bit less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058432" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058359" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058433" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058360" comment="mozilla-xulrunner190-translations less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058362" comment="mozilla-xulrunner190 less than 1.9.0.18-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091574" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1574</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1574" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1574" source="CVE"/>
	<description>
	racoon/isakmp_frag.c in ipsec-tools before 0.7.2 allows remote attackers to cause a denial of service (crash) via crafted fragmented packets without a payload, which triggers a NULL pointer dereference.
	</description>
 </metadata>
<!-- c6ea66016a3ad7e943d9b2acd348297d -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052958" comment="novell-ipsec-tools less than 0.7.1-2.29.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091630" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1630</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1630" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1630" source="CVE"/>
	<description>
	The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, when atomic_open is available, does not check execute (aka EXEC or MAY_EXEC) permission bits, which allows local users to bypass permissions and execute files, as demonstrated by files on an NFSv4 fileserver.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 23bbed017e105329dd9057458aa97ecc -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053523" comment="kernel-default-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053546" comment="kernel-default-extra less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053524" comment="kernel-default less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053525" comment="kernel-source less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053526" comment="kernel-syms less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053527" comment="kernel-xen-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053547" comment="kernel-xen-extra less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053528" comment="kernel-xen less than 2.6.27.25-0.1.1"/>
		</criteria>
	</criteria>
	<!-- efe472a6c3ff8e53697cca9b64ed6db5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053523" comment="kernel-default-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053546" comment="kernel-default-extra less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053524" comment="kernel-default less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053536" comment="kernel-pae-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053564" comment="kernel-pae-extra less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053537" comment="kernel-pae less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053525" comment="kernel-source less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053526" comment="kernel-syms less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053527" comment="kernel-xen-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053547" comment="kernel-xen-extra less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053528" comment="kernel-xen less than 2.6.27.25-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091631" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1631</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1631" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1631" source="CVE"/>
	<description>
	The Mailer component in Evolution 2.26.1 and earlier uses world-readable permissions for the .evolution directory, and certain directories and files under .evolution/ related to local mail, which allows local users to obtain sensitive information by reading these files.
	</description>
 </metadata>
<!-- c7c8e33671ac7994fac1b1913560d9bd -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009058657" comment="evolution-data-server-32bit less than 2.24.1.1-11.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058658" comment="evolution-data-server-lang less than 2.24.1.1-11.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058660" comment="evolution-data-server less than 2.24.1.1-11.12.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091632" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1632</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1632" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1632" source="CVE"/>
	<description>
	Multiple memory leaks in Ipsec-tools before 0.7.2 allow remote attackers to cause a denial of service (memory consumption) via vectors involving (1) signature verification during user authentication with X.509 certificates, related to the eay_check_x509sign function in src/racoon/crypto_openssl.c; and (2) the NAT-Traversal (aka NAT-T) keepalive implementation, related to src/racoon/nattraversal.c.
	</description>
 </metadata>
<!-- c6ea66016a3ad7e943d9b2acd348297d -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052958" comment="novell-ipsec-tools less than 0.7.1-2.29.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091633" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1633</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1633" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1633" source="CVE"/>
	<description>
	Multiple buffer overflows in the cifs subsystem in the Linux kernel before 2.6.29.4 allow remote CIFS servers to cause a denial of service (memory corruption) and possibly have unspecified other impact via (1) a malformed Unicode string, related to Unicode string area alignment in fs/cifs/sess.c; or (2) long Unicode characters, related to fs/cifs/cifssmb.c and the cifs_readdir function in fs/cifs/readdir.c.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 80db93c687bbdeb62c79f877c742f4bb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032356" comment="kernel-pae-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032341" comment="kernel-pae-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032357" comment="kernel-pae less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032360" comment="kernel-xen-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032342" comment="kernel-xen-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032361" comment="kernel-xen less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 9e40eecb7327c57e210599e2f65e0e81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032360" comment="kernel-xen-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032342" comment="kernel-xen-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032361" comment="kernel-xen less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091720" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1720</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1720" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1720" source="CVE"/>
	<description>
	Multiple integer overflows in OpenEXR 1.2.2 and 1.6.1 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors that trigger heap-based buffer overflows, related to (1) the Imf::PreviewImage::PreviewImage function and (2) compressor constructors.  NOTE: some of these details are obtained from third party information.
	</description>
 </metadata>
<!-- a9d4fc04f93289a20122dfbd5edb2ce0 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054497" comment="OpenEXR less than 1.6.1-83.17.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091721" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1721</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1721" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1721" source="CVE"/>
	<description>
	The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a free of an uninitialized pointer.
	</description>
 </metadata>
<!-- a9d4fc04f93289a20122dfbd5edb2ce0 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054497" comment="OpenEXR less than 1.6.1-83.17.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091725" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1725</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1725" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1725" source="CVE"/>
	<description>
	WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms; KHTML in kdelibs in KDE; QtWebKit (aka Qt toolkit); and possibly other products do not properly handle numeric character references, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.
	</description>
 </metadata>
<!-- 5444a721a519041421447122e142f15c -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009064866" comment="kdelibs3-default-style less than 3.5.10-23.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009064868" comment="kdelibs3 less than 3.5.10-23.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009064869" comment="kdelibs4-core less than 4.1.3-8.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009064870" comment="kdelibs4 less than 4.1.3-8.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009064873" comment="libkde4 less than 4.1.3-8.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009064876" comment="libkdecore4 less than 4.1.3-8.21.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091788" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1788</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1788" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1788" source="CVE"/>
	<description>
	Heap-based buffer overflow in voc_read_header in libsndfile 1.0.15 through 1.0.19, as used in Winamp 5.552 and possibly other media programs, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a VOC file with an invalid header value.
	</description>
 </metadata>
<!-- c3156403fc4e395e999fff161ceb9bea -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053458" comment="libsndfile-32bit less than 1.0.17-172.14.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053460" comment="libsndfile less than 1.0.17-172.14.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091791" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1791</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1791" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1791" source="CVE"/>
	<description>
	Heap-based buffer overflow in aiff_read_header in libsndfile 1.0.15 through 1.0.19, as used in Winamp 5.552 and possibly other media programs, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an AIFF file with an invalid header value.
	</description>
 </metadata>
<!-- c3156403fc4e395e999fff161ceb9bea -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053458" comment="libsndfile-32bit less than 1.0.17-172.14.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053460" comment="libsndfile less than 1.0.17-172.14.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091829" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1829</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1829" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1829" source="CVE"/>
	<description>
	Unspecified vulnerability in the PCNFSD dissector in Wireshark 0.8.20 through 1.0.7 allows remote attackers to cause a denial of service (crash) via crafted PCNFSD packets.
	</description>
 </metadata>
<!-- 9af723e66556cd28d89b219f9e202d7e -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032366" comment="wireshark less than 1.0.5-1.26.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091832" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1832</title>
	<affected family="unix">
		<platform>SLE 11 DESKTOP Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1832" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1832" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors involving "double frame construction."
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- bd731d7f7868bdb421d1037cfa3c2413 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053248" comment="MozillaThunderbird-translations less than 2.0.0.22-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053249" comment="MozillaThunderbird less than 2.0.0.22-0.1.1"/>
		</criteria>
	</criteria>
	<!-- de3e4a68d06355acbebbe6d9a72836b8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032389" comment="MozillaFirefox-translations less than 3.0.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032390" comment="MozillaFirefox less than 3.0.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032391" comment="mozilla-xulrunner190-32bit less than 1.9.0.11-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052932" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.11-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032392" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.11-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052933" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.11-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032393" comment="mozilla-xulrunner190-translations less than 1.9.0.11-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032395" comment="mozilla-xulrunner190 less than 1.9.0.11-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091833" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1833</title>
	<affected family="unix">
		<platform>SLE 11 DESKTOP Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1833" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1833" source="CVE"/>
	<description>
	The JavaScript engine in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) js_LeaveSharpObject, (2) ParseXMLSource, and (3) a certain assertion in jsinterp.c; and other vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- bd731d7f7868bdb421d1037cfa3c2413 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053248" comment="MozillaThunderbird-translations less than 2.0.0.22-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053249" comment="MozillaThunderbird less than 2.0.0.22-0.1.1"/>
		</criteria>
	</criteria>
	<!-- de3e4a68d06355acbebbe6d9a72836b8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032389" comment="MozillaFirefox-translations less than 3.0.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032390" comment="MozillaFirefox less than 3.0.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032391" comment="mozilla-xulrunner190-32bit less than 1.9.0.11-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052932" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.11-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032392" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.11-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052933" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.11-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032393" comment="mozilla-xulrunner190-translations less than 1.9.0.11-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032395" comment="mozilla-xulrunner190 less than 1.9.0.11-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091834" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1834</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1834" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1834" source="CVE"/>
	<description>
	Visual truncation vulnerability in netwerk/dns/src/nsIDNService.cpp in Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 allows remote attackers to spoof the location bar via an IDN with invalid Unicode characters that are displayed as whitespace, as demonstrated by the \u115A through \u115E characters.
	</description>
 </metadata>
<!-- de3e4a68d06355acbebbe6d9a72836b8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032389" comment="MozillaFirefox-translations less than 3.0.11-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032390" comment="MozillaFirefox less than 3.0.11-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032391" comment="mozilla-xulrunner190-32bit less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052932" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032392" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052933" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032393" comment="mozilla-xulrunner190-translations less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032395" comment="mozilla-xulrunner190 less than 1.9.0.11-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091835" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1835</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1835" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1835" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 associate local documents with external domain names located after the file:// substring in a URL, which allows user-assisted remote attackers to read arbitrary cookies via a crafted HTML document, as demonstrated by a URL with file://example.com/C:/ at the beginning.
	</description>
 </metadata>
<!-- de3e4a68d06355acbebbe6d9a72836b8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032389" comment="MozillaFirefox-translations less than 3.0.11-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032390" comment="MozillaFirefox less than 3.0.11-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032391" comment="mozilla-xulrunner190-32bit less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052932" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032392" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052933" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032393" comment="mozilla-xulrunner190-translations less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032395" comment="mozilla-xulrunner190 less than 1.9.0.11-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091836" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1836</title>
	<affected family="unix">
		<platform>SLE 11 DESKTOP Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1836" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1836" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 use the HTTP Host header to determine the context of a document provided in a non-200 CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- bd731d7f7868bdb421d1037cfa3c2413 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053248" comment="MozillaThunderbird-translations less than 2.0.0.22-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053249" comment="MozillaThunderbird less than 2.0.0.22-0.1.1"/>
		</criteria>
	</criteria>
	<!-- de3e4a68d06355acbebbe6d9a72836b8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032389" comment="MozillaFirefox-translations less than 3.0.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032390" comment="MozillaFirefox less than 3.0.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032391" comment="mozilla-xulrunner190-32bit less than 1.9.0.11-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052932" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.11-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032392" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.11-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052933" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.11-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032393" comment="mozilla-xulrunner190-translations less than 1.9.0.11-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032395" comment="mozilla-xulrunner190 less than 1.9.0.11-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091837" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1837</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1837" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1837" source="CVE"/>
	<description>
	Race condition in the NPObjWrapper_NewResolve function in modules/plugin/base/src/nsJSNPRuntime.cpp in xul.dll in Mozilla Firefox 3 before 3.0.11 might allow remote attackers to execute arbitrary code via a page transition during Java applet loading, related to a use-after-free vulnerability for memory associated with a destroyed Java object.
	</description>
 </metadata>
<!-- de3e4a68d06355acbebbe6d9a72836b8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032389" comment="MozillaFirefox-translations less than 3.0.11-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032390" comment="MozillaFirefox less than 3.0.11-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032391" comment="mozilla-xulrunner190-32bit less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052932" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032392" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052933" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032393" comment="mozilla-xulrunner190-translations less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032395" comment="mozilla-xulrunner190 less than 1.9.0.11-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091838" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1838</title>
	<affected family="unix">
		<platform>SLE 11 DESKTOP Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1838" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1838" source="CVE"/>
	<description>
	The garbage-collection implementation in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 sets an element's owner document to null in unspecified circumstances, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted event handler, related to an incorrect context for this event handler.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- bd731d7f7868bdb421d1037cfa3c2413 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053248" comment="MozillaThunderbird-translations less than 2.0.0.22-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053249" comment="MozillaThunderbird less than 2.0.0.22-0.1.1"/>
		</criteria>
	</criteria>
	<!-- de3e4a68d06355acbebbe6d9a72836b8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032389" comment="MozillaFirefox-translations less than 3.0.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032390" comment="MozillaFirefox less than 3.0.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032391" comment="mozilla-xulrunner190-32bit less than 1.9.0.11-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052932" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.11-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032392" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.11-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052933" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.11-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032393" comment="mozilla-xulrunner190-translations less than 1.9.0.11-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032395" comment="mozilla-xulrunner190 less than 1.9.0.11-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091839" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1839</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1839" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1839" source="CVE"/>
	<description>
	Mozilla Firefox 3 before 3.0.11 associates an incorrect principal with a file: URL loaded through the location bar, which allows user-assisted remote attackers to bypass intended access restrictions and read files via a crafted HTML document, aka a "file-URL-to-file-URL scripting" attack.
	</description>
 </metadata>
<!-- de3e4a68d06355acbebbe6d9a72836b8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032389" comment="MozillaFirefox-translations less than 3.0.11-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032390" comment="MozillaFirefox less than 3.0.11-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032391" comment="mozilla-xulrunner190-32bit less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052932" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032392" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052933" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032393" comment="mozilla-xulrunner190-translations less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032395" comment="mozilla-xulrunner190 less than 1.9.0.11-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091840" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1840</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1840" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1840" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.11, Thunderbird, and SeaMonkey do not check content policy before loading a script file into a XUL document, which allows remote attackers to bypass intended access restrictions via a crafted HTML document, as demonstrated by a "web bug" in an e-mail message, or web script or an advertisement in a web page.
	</description>
 </metadata>
<!-- de3e4a68d06355acbebbe6d9a72836b8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032389" comment="MozillaFirefox-translations less than 3.0.11-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032390" comment="MozillaFirefox less than 3.0.11-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032391" comment="mozilla-xulrunner190-32bit less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052932" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032392" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009052933" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032393" comment="mozilla-xulrunner190-translations less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032395" comment="mozilla-xulrunner190 less than 1.9.0.11-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091841" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1841</title>
	<affected family="unix">
		<platform>SLE 11 DESKTOP Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1841" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1841" source="CVE"/>
	<description>
	js/src/xpconnect/src/xpcwrappedjsclass.cpp in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to execute arbitrary web script with the privileges of a chrome object, as demonstrated by the browser sidebar and the FeedWriter.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- bd731d7f7868bdb421d1037cfa3c2413 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053248" comment="MozillaThunderbird-translations less than 2.0.0.22-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053249" comment="MozillaThunderbird less than 2.0.0.22-0.1.1"/>
		</criteria>
	</criteria>
	<!-- de3e4a68d06355acbebbe6d9a72836b8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032389" comment="MozillaFirefox-translations less than 3.0.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032390" comment="MozillaFirefox less than 3.0.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032391" comment="mozilla-xulrunner190-32bit less than 1.9.0.11-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052932" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.11-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032392" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.11-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052933" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.11-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032393" comment="mozilla-xulrunner190-translations less than 1.9.0.11-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032395" comment="mozilla-xulrunner190 less than 1.9.0.11-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091855" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1855</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1855" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1855" source="CVE"/>
	<description>
	Stack-based buffer overflow in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow attackers to execute arbitrary code via a PDF file containing a malformed U3D model file with a crafted extension block.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- afe186fd3bad60212fb8d8d8b51e1454 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009051914" comment="acroread less than 8.1.6-0.1.1"/>
	</criteria>
	<!-- d585d11ae44add7af85ddd5eccb6818d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054066" comment="acroread_ja less than 8.1.6-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091856" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1856</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1856" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1856" source="CVE"/>
	<description>
	Integer overflow in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 allows attackers to cause a denial of service or possibly execute arbitrary code via a PDF file containing unspecified parameters to the FlateDecode filter, which triggers a heap-based buffer overflow.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- afe186fd3bad60212fb8d8d8b51e1454 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009051914" comment="acroread less than 8.1.6-0.1.1"/>
	</criteria>
	<!-- d585d11ae44add7af85ddd5eccb6818d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054066" comment="acroread_ja less than 8.1.6-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091857" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1857</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1857" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1857" source="CVE"/>
	<description>
	Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 allow attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a PDF document with a crafted TrueType font.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- afe186fd3bad60212fb8d8d8b51e1454 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009051914" comment="acroread less than 8.1.6-0.1.1"/>
	</criteria>
	<!-- d585d11ae44add7af85ddd5eccb6818d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054066" comment="acroread_ja less than 8.1.6-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091858" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1858</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1858" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1858" source="CVE"/>
	<description>
	The JBIG2 filter in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow remote attackers to execute arbitrary code via unspecified vectors that trigger memory corruption.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- afe186fd3bad60212fb8d8d8b51e1454 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009051914" comment="acroread less than 8.1.6-0.1.1"/>
	</criteria>
	<!-- d585d11ae44add7af85ddd5eccb6818d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054066" comment="acroread_ja less than 8.1.6-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091859" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1859</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1859" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1859" source="CVE"/>
	<description>
	Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow attackers to execute arbitrary code via unspecified vectors that trigger memory corruption.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- afe186fd3bad60212fb8d8d8b51e1454 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009051914" comment="acroread less than 8.1.6-0.1.1"/>
	</criteria>
	<!-- d585d11ae44add7af85ddd5eccb6818d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054066" comment="acroread_ja less than 8.1.6-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091861" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1861</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1861" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1861" source="CVE"/>
	<description>
	Multiple heap-based buffer overflows in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF file with a JPX (aka JPEG2000) stream that triggers heap memory corruption.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- afe186fd3bad60212fb8d8d8b51e1454 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009051914" comment="acroread less than 8.1.6-0.1.1"/>
	</criteria>
	<!-- d585d11ae44add7af85ddd5eccb6818d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054066" comment="acroread_ja less than 8.1.6-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091862" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1862</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1862" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1862" source="CVE"/>
	<description>
	Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via (1) a crafted Flash application in a .pdf file or (2) a crafted .swf file, related to authplay.dll, as exploited in the wild in July 2009.
	</description>
 </metadata>
<!-- 0ed97f904ab5337b5e08c83e789c22d2 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053711" comment="flash-player less than 10.0.32.18-0.1.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091863" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1863</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1863" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1863" source="CVE"/>
	<description>
	Unspecified vulnerability in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors, related to a "privilege escalation vulnerability."
	</description>
 </metadata>
<!-- 0ed97f904ab5337b5e08c83e789c22d2 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053711" comment="flash-player less than 10.0.32.18-0.1.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091864" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1864</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1864" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1864" source="CVE"/>
	<description>
	Heap-based buffer overflow in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors.
	</description>
 </metadata>
<!-- 0ed97f904ab5337b5e08c83e789c22d2 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053711" comment="flash-player less than 10.0.32.18-0.1.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091865" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1865</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1865" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1865" source="CVE"/>
	<description>
	Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, related to a "null pointer vulnerability."
	</description>
 </metadata>
<!-- 0ed97f904ab5337b5e08c83e789c22d2 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053711" comment="flash-player less than 10.0.32.18-0.1.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091866" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1866</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1866" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1866" source="CVE"/>
	<description>
	Stack-based buffer overflow in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors.
	</description>
 </metadata>
<!-- 0ed97f904ab5337b5e08c83e789c22d2 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053711" comment="flash-player less than 10.0.32.18-0.1.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091867" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1867</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1867" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1867" source="CVE"/>
	<description>
	Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to trick a user into (1) selecting a link or (2) completing a dialog, related to a "clickjacking vulnerability."
	</description>
 </metadata>
<!-- 0ed97f904ab5337b5e08c83e789c22d2 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053711" comment="flash-player less than 10.0.32.18-0.1.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091868" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1868</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1868" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1868" source="CVE"/>
	<description>
	Heap-based buffer overflow in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors involving URL parsing.
	</description>
 </metadata>
<!-- 0ed97f904ab5337b5e08c83e789c22d2 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053711" comment="flash-player less than 10.0.32.18-0.1.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091869" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1869</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1869" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1869" source="CVE"/>
	<description>
	Integer overflow in the ActionScript Virtual Machine 2 (AVM2) abcFile parser in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an AVM2 file with a large intrf_count value that triggers a dereference of an out-of-bounds pointer.
	</description>
 </metadata>
<!-- 0ed97f904ab5337b5e08c83e789c22d2 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053711" comment="flash-player less than 10.0.32.18-0.1.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091870" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1870</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1870" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1870" source="CVE"/>
	<description>
	Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to obtain sensitive information via vectors involving saving an SWF file to a hard drive, related to a "local sandbox vulnerability."
	</description>
 </metadata>
<!-- 0ed97f904ab5337b5e08c83e789c22d2 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053711" comment="flash-player less than 10.0.32.18-0.1.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091882" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1882</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1882" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1882" source="CVE"/>
	<description>
	Integer overflow in the XMakeImage function in magick/xwindow.c in ImageMagick 6.5.2-8, and GraphicsMagick, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF file, which triggers a buffer overflow.  NOTE: some of these details are obtained from third party information.
	</description>
 </metadata>
<!-- f6592befc7ebf5f90a71638a03946d67 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053004" comment="ImageMagick less than 6.4.3.6-7.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053006" comment="libMagick++1 less than 6.4.3.6-7.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032399" comment="libMagickCore1-32bit less than 6.4.3.6-7.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032400" comment="libMagickCore1 less than 6.4.3.6-7.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053008" comment="libMagickWand1 less than 6.4.3.6-7.19.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091886" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1886</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1886" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1886" source="CVE"/>
	<description>
	Multiple format string vulnerabilities in client/client.c in smbclient in Samba 3.2.0 through 3.2.12 might allow context-dependent attackers to execute arbitrary code via format string specifiers in a filename.
	</description>
 </metadata>
<!-- 3ac5dcd69a8c15958c4ed600c1a9ee9e -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053220" comment="cifs-mount less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053222" comment="libsmbclient0-32bit less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053224" comment="libsmbclient0 less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053225" comment="libtalloc1-32bit less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053227" comment="libtalloc1 less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053228" comment="libtdb1-32bit less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053230" comment="libtdb1 less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053231" comment="libwbclient0-32bit less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053233" comment="libwbclient0 less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053234" comment="samba-32bit less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053235" comment="samba-client-32bit less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053237" comment="samba-client less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053238" comment="samba-krb-printing less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053259" comment="samba-vscan less than 0.3.6b-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053239" comment="samba-winbind-32bit less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053241" comment="samba-winbind less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053243" comment="samba less than 3.2.7-11.7.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091888" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1888</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1888" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1888" source="CVE"/>
	<description>
	The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x before 3.0.35, 3.1.x and 3.2.x before 3.2.13, and 3.3.x before 3.3.6, when dos filemode is enabled, allows remote attackers to modify access control lists for files via vectors related to read access to uninitialized memory.
	</description>
 </metadata>
<!-- 3ac5dcd69a8c15958c4ed600c1a9ee9e -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053220" comment="cifs-mount less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053222" comment="libsmbclient0-32bit less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053224" comment="libsmbclient0 less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053225" comment="libtalloc1-32bit less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053227" comment="libtalloc1 less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053228" comment="libtdb1-32bit less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053230" comment="libtdb1 less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053231" comment="libwbclient0-32bit less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053233" comment="libwbclient0 less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053234" comment="samba-32bit less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053235" comment="samba-client-32bit less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053237" comment="samba-client less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053238" comment="samba-krb-printing less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053259" comment="samba-vscan less than 0.3.6b-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053239" comment="samba-winbind-32bit less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053241" comment="samba-winbind less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053243" comment="samba less than 3.2.7-11.7.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091889" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1889</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1889" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1889" source="CVE"/>
	<description>
	The OSCAR protocol implementation in Pidgin before 2.5.8 misinterprets the ICQWebMessage message type as the ICQSMS message type, which allows remote attackers to cause a denial of service (application crash) via a crafted ICQ web message that triggers allocation of a large amount of memory.
	</description>
 </metadata>
<!-- 387045b930341190664017ca29b12c16 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053476" comment="finch less than 2.5.1-9.11.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053478" comment="libpurple-lang less than 2.5.1-9.11.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053479" comment="libpurple less than 2.5.1-9.11.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053481" comment="pidgin less than 2.5.1-9.11.3"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091895" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1895</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1895" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1895" source="CVE"/>
	<description>
	The personality subsystem in the Linux kernel before 2.6.31-rc3 has a PER_CLEAR_ON_SETID setting that does not clear the ADDR_COMPAT_LAYOUT and MMAP_PAGE_ZERO flags when executing a setuid or setgid program, which makes it easier for local users to leverage the details of memory usage to (1) conduct NULL pointer dereference attacks, (2) bypass the mmap_min_addr protection mechanism, or (3) defeat address space layout randomization (ASLR).
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0522f4d2681968d0e344aad24e0e341b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054108" comment="kernel-default-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054182" comment="kernel-default-extra less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054109" comment="kernel-default less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054110" comment="kernel-pae-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054183" comment="kernel-pae-extra less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054111" comment="kernel-pae less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054112" comment="kernel-source less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054113" comment="kernel-syms less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054116" comment="kernel-xen-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054184" comment="kernel-xen-extra less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054117" comment="kernel-xen less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 125c8b5a7b30fdb1de7b2255eb1649a7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054108" comment="kernel-default-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054182" comment="kernel-default-extra less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054109" comment="kernel-default less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054112" comment="kernel-source less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054113" comment="kernel-syms less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054116" comment="kernel-xen-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054184" comment="kernel-xen-extra less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054117" comment="kernel-xen less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091904" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1904</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1904" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1904" source="CVE"/>
	<description>
	The BigDecimal library in Ruby 1.8.6 before p369 and 1.8.7 before p173 allows context-dependent attackers to cause a denial of service (application crash) via a string argument that represents a large number, as demonstrated by an attempted conversion to the Float data type.
	</description>
 </metadata>
<!-- c8369586b31bf86da2231acd00ad8f78 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053194" comment="ruby less than 1.8.7.p72-5.22.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091932" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1932</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1932" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1932" source="CVE"/>
	<description>
	Multiple integer overflows in the (1) user_info_callback, (2) user_endrow_callback, and (3) gst_pngdec_task functions (ext/libpng/gstpngdec.c) in GStreamer Good Plug-ins (aka gst-plugins-good or gstreamer-plugins-good) 0.10.15 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted PNG file, which triggers a buffer overflow.
	</description>
 </metadata>
<!-- e3f7d863f6867202ad78ce023a8c99e9 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053080" comment="gstreamer-0_10-plugins-good-lang less than 0.10.10-4.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053081" comment="gstreamer-0_10-plugins-good less than 0.10.10-4.9.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091961" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1961</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1961" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1961" source="CVE"/>
	<description>
	The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, 2.6.29 before 2.6.29.4, and possibly other versions down to 2.6.19 allows local users to cause a denial of service (prevention of file creation and removal) via a series of splice system calls that trigger a deadlock between the generic_file_splice_write, splice_from_pipe, and ocfs2_file_splice_write functions.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 23bbed017e105329dd9057458aa97ecc -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053523" comment="kernel-default-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053546" comment="kernel-default-extra less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053524" comment="kernel-default less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053525" comment="kernel-source less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053526" comment="kernel-syms less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053527" comment="kernel-xen-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053547" comment="kernel-xen-extra less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053528" comment="kernel-xen less than 2.6.27.25-0.1.1"/>
		</criteria>
	</criteria>
	<!-- efe472a6c3ff8e53697cca9b64ed6db5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053523" comment="kernel-default-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053546" comment="kernel-default-extra less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053524" comment="kernel-default less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053536" comment="kernel-pae-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053564" comment="kernel-pae-extra less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053537" comment="kernel-pae less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053525" comment="kernel-source less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053526" comment="kernel-syms less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053527" comment="kernel-xen-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053547" comment="kernel-xen-extra less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053528" comment="kernel-xen less than 2.6.27.25-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092028" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2028</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2028" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2028" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 have unknown impact and attack vectors, related to "Adobe internally discovered issues."
	</description>
 </metadata>
<!-- afe186fd3bad60212fb8d8d8b51e1454 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009051914" comment="acroread less than 8.1.6-0.1.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092042" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2042</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2042" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2042" source="CVE"/>
	<description>
	libpng before 1.2.37 does not properly parse 1-bit interlaced images with width values that are not divisible by 8, which causes libpng to include uninitialized bits in certain rows of a PNG file and might allow remote attackers to read portions of sensitive memory via "out-of-bounds pixels" in the file.
	</description>
 </metadata>
<!-- 347346dddae72c6d0521d44e36060298 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053369" comment="libpng-devel less than 1.2.31-5.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053355" comment="libpng12-0-32bit less than 1.2.31-5.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053357" comment="libpng12-0 less than 1.2.31-5.12.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092139" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2139</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2139" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2139" source="CVE"/>
	<description>
	Heap-based buffer overflow in svtools/source/filter.vcl/wmf/enhwmf.cxx in Go-oo 2.x and 3.x before 3.0.1, previously named ooo-build and related to OpenOffice.org (OOo), allows remote attackers to execute arbitrary code via a crafted EMF file, a similar issue to CVE-2008-2238.
	</description>
 </metadata>
<!-- a9bd052827d214256bfa24cd42e76d80 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009054735" comment="OpenOffice_org-LanguageTool-de less than 0.9.9-2.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054736" comment="OpenOffice_org-LanguageTool-en less than 0.9.9-2.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054737" comment="OpenOffice_org-LanguageTool-es less than 0.9.9-2.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054738" comment="OpenOffice_org-LanguageTool-fr less than 0.9.9-2.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054739" comment="OpenOffice_org-LanguageTool-it less than 0.9.9-2.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054740" comment="OpenOffice_org-LanguageTool-nl less than 0.9.9-2.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054741" comment="OpenOffice_org-LanguageTool-pl less than 0.9.9-2.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054742" comment="OpenOffice_org-LanguageTool-sv less than 0.9.9-2.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054743" comment="OpenOffice_org-LanguageTool less than 0.9.9-2.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054744" comment="OpenOffice_org-base-drivers-postgresql less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054745" comment="OpenOffice_org-base-extensions less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054654" comment="OpenOffice_org-base less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054746" comment="OpenOffice_org-calc-extensions less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054657" comment="OpenOffice_org-calc less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054659" comment="OpenOffice_org-components less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054747" comment="OpenOffice_org-draw-extensions less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054660" comment="OpenOffice_org-draw less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054662" comment="OpenOffice_org-filters-optional less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054663" comment="OpenOffice_org-filters less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054664" comment="OpenOffice_org-gnome less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054665" comment="OpenOffice_org-help-ar less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054666" comment="OpenOffice_org-help-cs less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054667" comment="OpenOffice_org-help-da less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054668" comment="OpenOffice_org-help-de less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054669" comment="OpenOffice_org-help-en-GB less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054670" comment="OpenOffice_org-help-en-US-devel less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054671" comment="OpenOffice_org-help-en-US less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054672" comment="OpenOffice_org-help-es less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054673" comment="OpenOffice_org-help-fr less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054748" comment="OpenOffice_org-help-gu-IN less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054749" comment="OpenOffice_org-help-hi-IN less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054674" comment="OpenOffice_org-help-hu less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054675" comment="OpenOffice_org-help-it less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054676" comment="OpenOffice_org-help-ja less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054750" comment="OpenOffice_org-help-ko less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054677" comment="OpenOffice_org-help-nl less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054678" comment="OpenOffice_org-help-pl less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054679" comment="OpenOffice_org-help-pt-BR less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054680" comment="OpenOffice_org-help-pt less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054681" comment="OpenOffice_org-help-ru less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054682" comment="OpenOffice_org-help-sv less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054683" comment="OpenOffice_org-help-zh-CN less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054684" comment="OpenOffice_org-help-zh-TW less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054685" comment="OpenOffice_org-icon-themes less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054751" comment="OpenOffice_org-impress-extensions less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054687" comment="OpenOffice_org-impress less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054688" comment="OpenOffice_org-kde less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054689" comment="OpenOffice_org-l10n-af less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054690" comment="OpenOffice_org-l10n-ar less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054691" comment="OpenOffice_org-l10n-ca less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054692" comment="OpenOffice_org-l10n-cs less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054693" comment="OpenOffice_org-l10n-da less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054694" comment="OpenOffice_org-l10n-de less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054695" comment="OpenOffice_org-l10n-el less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054696" comment="OpenOffice_org-l10n-en-GB less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054697" comment="OpenOffice_org-l10n-es less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054699" comment="OpenOffice_org-l10n-extras less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054700" comment="OpenOffice_org-l10n-fi less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054701" comment="OpenOffice_org-l10n-fr less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054752" comment="OpenOffice_org-l10n-gu-IN less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054753" comment="OpenOffice_org-l10n-hi-IN less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054702" comment="OpenOffice_org-l10n-hu less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054703" comment="OpenOffice_org-l10n-it less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054704" comment="OpenOffice_org-l10n-ja less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054754" comment="OpenOffice_org-l10n-ko less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054705" comment="OpenOffice_org-l10n-nb less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054706" comment="OpenOffice_org-l10n-nl less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054707" comment="OpenOffice_org-l10n-nn less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054708" comment="OpenOffice_org-l10n-pl less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054709" comment="OpenOffice_org-l10n-pt-BR less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054710" comment="OpenOffice_org-l10n-pt less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054711" comment="OpenOffice_org-l10n-ru less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054712" comment="OpenOffice_org-l10n-sk less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054713" comment="OpenOffice_org-l10n-sv less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054714" comment="OpenOffice_org-l10n-xh less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054715" comment="OpenOffice_org-l10n-zh-CN less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054716" comment="OpenOffice_org-l10n-zh-TW less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054717" comment="OpenOffice_org-l10n-zu less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054719" comment="OpenOffice_org-libs-core less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054721" comment="OpenOffice_org-libs-extern less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054723" comment="OpenOffice_org-libs-gui less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054724" comment="OpenOffice_org-mailmerge less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054725" comment="OpenOffice_org-math less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054726" comment="OpenOffice_org-mono less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054727" comment="OpenOffice_org-officebean less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054728" comment="OpenOffice_org-pyuno less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054731" comment="OpenOffice_org-ure less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054755" comment="OpenOffice_org-writer-extensions less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054733" comment="OpenOffice_org-writer less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054734" comment="OpenOffice_org less than 3.1.1.1-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092140" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2140</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2140" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2140" source="CVE"/>
	<description>
	Multiple heap-based buffer overflows in cppcanvas/source/mtfrenderer/emfplus.cxx in Go-oo 2.x and 3.x before 3.0.1, previously named ooo-build and related to OpenOffice.org (OOo), allow remote attackers to execute arbitrary code via a crafted EMF+ file, a similar issue to CVE-2008-2238.
	</description>
 </metadata>
<!-- a9bd052827d214256bfa24cd42e76d80 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009054735" comment="OpenOffice_org-LanguageTool-de less than 0.9.9-2.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054736" comment="OpenOffice_org-LanguageTool-en less than 0.9.9-2.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054737" comment="OpenOffice_org-LanguageTool-es less than 0.9.9-2.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054738" comment="OpenOffice_org-LanguageTool-fr less than 0.9.9-2.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054739" comment="OpenOffice_org-LanguageTool-it less than 0.9.9-2.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054740" comment="OpenOffice_org-LanguageTool-nl less than 0.9.9-2.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054741" comment="OpenOffice_org-LanguageTool-pl less than 0.9.9-2.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054742" comment="OpenOffice_org-LanguageTool-sv less than 0.9.9-2.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054743" comment="OpenOffice_org-LanguageTool less than 0.9.9-2.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054744" comment="OpenOffice_org-base-drivers-postgresql less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054745" comment="OpenOffice_org-base-extensions less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054654" comment="OpenOffice_org-base less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054746" comment="OpenOffice_org-calc-extensions less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054657" comment="OpenOffice_org-calc less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054659" comment="OpenOffice_org-components less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054747" comment="OpenOffice_org-draw-extensions less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054660" comment="OpenOffice_org-draw less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054662" comment="OpenOffice_org-filters-optional less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054663" comment="OpenOffice_org-filters less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054664" comment="OpenOffice_org-gnome less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054665" comment="OpenOffice_org-help-ar less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054666" comment="OpenOffice_org-help-cs less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054667" comment="OpenOffice_org-help-da less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054668" comment="OpenOffice_org-help-de less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054669" comment="OpenOffice_org-help-en-GB less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054670" comment="OpenOffice_org-help-en-US-devel less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054671" comment="OpenOffice_org-help-en-US less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054672" comment="OpenOffice_org-help-es less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054673" comment="OpenOffice_org-help-fr less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054748" comment="OpenOffice_org-help-gu-IN less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054749" comment="OpenOffice_org-help-hi-IN less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054674" comment="OpenOffice_org-help-hu less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054675" comment="OpenOffice_org-help-it less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054676" comment="OpenOffice_org-help-ja less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054750" comment="OpenOffice_org-help-ko less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054677" comment="OpenOffice_org-help-nl less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054678" comment="OpenOffice_org-help-pl less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054679" comment="OpenOffice_org-help-pt-BR less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054680" comment="OpenOffice_org-help-pt less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054681" comment="OpenOffice_org-help-ru less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054682" comment="OpenOffice_org-help-sv less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054683" comment="OpenOffice_org-help-zh-CN less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054684" comment="OpenOffice_org-help-zh-TW less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054685" comment="OpenOffice_org-icon-themes less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054751" comment="OpenOffice_org-impress-extensions less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054687" comment="OpenOffice_org-impress less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054688" comment="OpenOffice_org-kde less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054689" comment="OpenOffice_org-l10n-af less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054690" comment="OpenOffice_org-l10n-ar less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054691" comment="OpenOffice_org-l10n-ca less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054692" comment="OpenOffice_org-l10n-cs less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054693" comment="OpenOffice_org-l10n-da less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054694" comment="OpenOffice_org-l10n-de less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054695" comment="OpenOffice_org-l10n-el less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054696" comment="OpenOffice_org-l10n-en-GB less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054697" comment="OpenOffice_org-l10n-es less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054699" comment="OpenOffice_org-l10n-extras less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054700" comment="OpenOffice_org-l10n-fi less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054701" comment="OpenOffice_org-l10n-fr less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054752" comment="OpenOffice_org-l10n-gu-IN less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054753" comment="OpenOffice_org-l10n-hi-IN less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054702" comment="OpenOffice_org-l10n-hu less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054703" comment="OpenOffice_org-l10n-it less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054704" comment="OpenOffice_org-l10n-ja less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054754" comment="OpenOffice_org-l10n-ko less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054705" comment="OpenOffice_org-l10n-nb less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054706" comment="OpenOffice_org-l10n-nl less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054707" comment="OpenOffice_org-l10n-nn less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054708" comment="OpenOffice_org-l10n-pl less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054709" comment="OpenOffice_org-l10n-pt-BR less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054710" comment="OpenOffice_org-l10n-pt less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054711" comment="OpenOffice_org-l10n-ru less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054712" comment="OpenOffice_org-l10n-sk less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054713" comment="OpenOffice_org-l10n-sv less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054714" comment="OpenOffice_org-l10n-xh less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054715" comment="OpenOffice_org-l10n-zh-CN less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054716" comment="OpenOffice_org-l10n-zh-TW less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054717" comment="OpenOffice_org-l10n-zu less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054719" comment="OpenOffice_org-libs-core less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054721" comment="OpenOffice_org-libs-extern less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054723" comment="OpenOffice_org-libs-gui less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054724" comment="OpenOffice_org-mailmerge less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054725" comment="OpenOffice_org-math less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054726" comment="OpenOffice_org-mono less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054727" comment="OpenOffice_org-officebean less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054728" comment="OpenOffice_org-pyuno less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054731" comment="OpenOffice_org-ure less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054755" comment="OpenOffice_org-writer-extensions less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054733" comment="OpenOffice_org-writer less than 3.1.1.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054734" comment="OpenOffice_org less than 3.1.1.1-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092285" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2285</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2285" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2285" source="CVE"/>
	<description>
	Buffer underflow in the LZWDecodeCompat function in libtiff 3.8.2 allows context-dependent attackers to cause a denial of service (crash) via a crafted TIFF image, a different vulnerability than CVE-2008-2327.
	</description>
 </metadata>
<!-- 2260ae46f623edd1c3e7ba019b3a771d -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053719" comment="libtiff3-32bit less than 3.8.2-141.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053721" comment="libtiff3 less than 3.8.2-141.7.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092287" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2287</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2287" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2287" source="CVE"/>
	<description>
	The kvm_arch_vcpu_ioctl_set_sregs function in the KVM in Linux kernel 2.6 before 2.6.30, when running on x86 systems, does not validate the page table root in a KVM_SET_SREGS call, which allows local users to cause a denial of service (crash or hang) via a crafted cr3 value, which triggers a NULL pointer dereference in the gfn_to_rmap function.
	</description>
 </metadata>
<!-- 3b73baf8f221b972ab3ab4de3e9c3406 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009054848" comment="kvm-kmp-default less than 78.2.6.30.1_2.6.27.25_0.1-0.2.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054849" comment="kvm-kmp-pae less than 78.2.6.30.1_2.6.27.25_0.1-0.2.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054850" comment="kvm less than 78.0.10.5-0.2.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092347" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2347</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2347" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2347" source="CVE"/>
	<description>
	Multiple integer overflows in inter-color spaces conversion tools in libtiff 3.8 through 3.8.2, 3.9, and 4.0 allow context-dependent attackers to execute arbitrary code via a TIFF image with large (1) width and (2) height values, which triggers a heap-based buffer overflow in the (a) cvt_whole_image function in tiff2rgba and (b) tiffcvt function in rgb2ycbcr.
	</description>
 </metadata>
<!-- ac9a395c3876a17a1dea5f9f475054d1 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009054049" comment="libtiff3-32bit less than 3.8.2-141.8.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054051" comment="libtiff3 less than 3.8.2-141.8.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092395" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2395</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2395" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2395" source="CVE"/>
	<description>
	SQL injection vulnerability in the K2 (com_k2) component 1.0.1 Beta and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the category parameter in an itemlist action to index.php.
	</description>
 </metadata>
<!-- 0ed97f904ab5337b5e08c83e789c22d2 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053711" comment="flash-player less than 10.0.32.18-0.1.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092404" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2404</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2404" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2404" source="CVE"/>
	<description>
	Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thunderbird, SeaMonkey, Evolution, Pidgin, and AOL Instant Messenger (AIM), allows remote SSL servers to cause a denial of service (application crash) or possibly execute arbitrary code via a long domain name in the subject's Common Name (CN) field of an X.509 certificate, related to the cert_TestHostName function.
	</description>
 </metadata>
<!-- 5d306b6d7dd56f9b174098ca596f270a -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053937" comment="libfreebl3-32bit less than 3.12.3.1-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053939" comment="libfreebl3 less than 3.12.3.1-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053940" comment="mozilla-nss-32bit less than 3.12.3.1-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053941" comment="mozilla-nss-tools less than 3.12.3.1-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053943" comment="mozilla-nss less than 3.12.3.1-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092406" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2406</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2406" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2406" source="CVE"/>
	<description>
	Stack-based buffer overflow in the parse_tag_11_packet function in fs/ecryptfs/keystore.c in the eCryptfs subsystem in the Linux kernel before 2.6.30.4 allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving a crafted eCryptfs file, related to not ensuring that the key signature length in a Tag 11 packet is compatible with the key signature buffer size.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0522f4d2681968d0e344aad24e0e341b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054108" comment="kernel-default-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054182" comment="kernel-default-extra less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054109" comment="kernel-default less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054110" comment="kernel-pae-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054183" comment="kernel-pae-extra less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054111" comment="kernel-pae less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054112" comment="kernel-source less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054113" comment="kernel-syms less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054116" comment="kernel-xen-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054184" comment="kernel-xen-extra less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054117" comment="kernel-xen less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 125c8b5a7b30fdb1de7b2255eb1649a7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054108" comment="kernel-default-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054182" comment="kernel-default-extra less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054109" comment="kernel-default less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054112" comment="kernel-source less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054113" comment="kernel-syms less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054116" comment="kernel-xen-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054184" comment="kernel-xen-extra less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054117" comment="kernel-xen less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092407" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2407</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2407" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2407" source="CVE"/>
	<description>
	Heap-based buffer overflow in the parse_tag_3_packet function in fs/ecryptfs/keystore.c in the eCryptfs subsystem in the Linux kernel before 2.6.30.4 allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving a crafted eCryptfs file, related to a large encrypted key size in a Tag 3 packet.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0522f4d2681968d0e344aad24e0e341b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054108" comment="kernel-default-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054182" comment="kernel-default-extra less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054109" comment="kernel-default less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054110" comment="kernel-pae-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054183" comment="kernel-pae-extra less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054111" comment="kernel-pae less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054112" comment="kernel-source less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054113" comment="kernel-syms less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054116" comment="kernel-xen-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054184" comment="kernel-xen-extra less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054117" comment="kernel-xen less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 125c8b5a7b30fdb1de7b2255eb1649a7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054108" comment="kernel-default-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054182" comment="kernel-default-extra less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054109" comment="kernel-default less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054112" comment="kernel-source less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054113" comment="kernel-syms less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054116" comment="kernel-xen-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054184" comment="kernel-xen-extra less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054117" comment="kernel-xen less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092408" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2408</title>
	<affected family="unix">
		<platform>SLE 11 DESKTOP Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2408" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2408" source="CVE"/>
	<description>
	Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority. NOTE: this was originally reported for Firefox before 3.5.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 3c4a420c84f14ecc1db307f54b2cb540 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054875" comment="MozillaThunderbird-translations less than 2.0.0.23-0.2.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054876" comment="MozillaThunderbird less than 2.0.0.23-0.2.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054877" comment="hunspell less than 1.2.7-1.16"/>
		</criteria>
	</criteria>
	<!-- 5d306b6d7dd56f9b174098ca596f270a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053937" comment="libfreebl3-32bit less than 3.12.3.1-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053939" comment="libfreebl3 less than 3.12.3.1-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053940" comment="mozilla-nss-32bit less than 3.12.3.1-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053941" comment="mozilla-nss-tools less than 3.12.3.1-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053943" comment="mozilla-nss less than 3.12.3.1-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 8b6ad83a2d239c9f63b11481566420f0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054902" comment="libldap-2_4-2-32bit less than 2.4.12-7.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054904" comment="libldap-2_4-2 less than 2.4.12-7.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054906" comment="openldap2-client less than 2.4.12-7.18.1"/>
		</criteria>
	</criteria>
	<!-- cc9c5a6c5fd4bd88c6a42dc93653674b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054908" comment="mutt less than 1.5.17-42.32.1"/>
	</criteria>
	<!-- db036d6c88b93b6c89d6d75d9b617dce -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055774" comment="libneon27 less than 0.28.3-2.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055775" comment="neon less than 0.28.3-2.12.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092416" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2416</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2416" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2416" source="CVE"/>
	<description>
	Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.
	</description>
 </metadata>
<!-- 829b31ab282bbd0be50115fc32887eb8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053779" comment="libxml2-32bit less than 2.7.1-10.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053782" comment="libxml2 less than 2.7.1-10.9.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092417" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2417</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2417" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2417" source="CVE"/>
	<description>
	lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
	</description>
 </metadata>
<!-- bd3c8afff979262cbf1ca535c4eb2e68 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053896" comment="curl less than 7.19.0-11.22.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053897" comment="keyutils-libs-32bit less than 1.2-107.22"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053899" comment="keyutils-libs less than 1.2-107.22"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053900" comment="libcurl4-32bit less than 7.19.0-11.22.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053902" comment="libcurl4 less than 7.19.0-11.22.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053903" comment="libidn-32bit less than 1.10-3.18"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053905" comment="libidn less than 1.10-3.18"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092446" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2446</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2446" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2446" source="CVE"/>
	<description>
	Multiple format string vulnerabilities in the dispatch_command function in libmysqld/sql_parse.cc in mysqld in MySQL 4.0.0 through 5.0.83 allow remote authenticated users to cause a denial of service (daemon crash) and possibly have unspecified other impact via format string specifiers in a database name in a (1) COM_CREATE_DB or (2) COM_DROP_DB request.  NOTE: some of these details are obtained from third party information.
	</description>
 </metadata>
<!-- 6b4ffc010711f4a40d2054f5fc473cc7 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009054286" comment="libmysqlclient15-32bit less than 5.0.67-13.16.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054288" comment="libmysqlclient15 less than 5.0.67-13.16.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054294" comment="libmysqlclient_r15-32bit less than 5.0.67-13.16.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054289" comment="libmysqlclient_r15 less than 5.0.67-13.16.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054291" comment="mysql-client less than 5.0.67-13.16.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054292" comment="mysql less than 5.0.67-13.16.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092462" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2462</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2462" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2462" source="CVE"/>
	<description>
	The browser engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) the frame chain and synchronous events, (2) a SetMayHaveFrame assertion and nsCSSFrameConstructor::CreateFloatingLetterFrame, (3) nsCSSFrameConstructor::ConstructFrame, (4) the child list and initial reflow, (5) GetLastSpecialSibling, (6) nsFrameManager::GetPrimaryFrameFor and MathML, (7) nsFrame::GetBoxAscent, (8) nsCSSFrameConstructor::AdjustParentFrame, (9) nsDOMOfflineResourceList, and (10) nsContentUtils::ComparePosition.
	</description>
 </metadata>
<!-- d3be5c712e2e2706b7b11ecd08d9e22f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053589" comment="MozillaFirefox-translations less than 3.0.12-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053590" comment="MozillaFirefox less than 3.0.12-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053591" comment="mozilla-xulrunner190-32bit less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053597" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053592" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053599" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053593" comment="mozilla-xulrunner190-translations less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053595" comment="mozilla-xulrunner190 less than 1.9.0.12-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092463" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2463</title>
	<affected family="unix">
		<platform>SLE 11 DESKTOP Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2463" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2463" source="CVE"/>
	<description>
	Multiple integer overflows in the (1) PL_Base64Decode and (2) PL_Base64Encode functions in nsprpub/lib/libc/src/base64.c in Mozilla Firefox before 3.0.12, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors that trigger buffer overflows.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- d3be5c712e2e2706b7b11ecd08d9e22f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053589" comment="MozillaFirefox-translations less than 3.0.12-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053590" comment="MozillaFirefox less than 3.0.12-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053591" comment="mozilla-xulrunner190-32bit less than 1.9.0.12-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053597" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.12-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053592" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.12-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053599" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.12-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053593" comment="mozilla-xulrunner190-translations less than 1.9.0.12-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053595" comment="mozilla-xulrunner190 less than 1.9.0.12-1.1.1"/>
		</criteria>
	</criteria>
	<!-- f2377272fe27726ada5a22ead971d6aa -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059215" comment="MozillaThunderbird-translations less than 2.0.0.24-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059216" comment="MozillaThunderbird less than 2.0.0.24-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092464" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2464</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2464" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2464" source="CVE"/>
	<description>
	The nsXULTemplateQueryProcessorRDF::CheckIsSeparator function in Mozilla Firefox before 3.0.12, SeaMonkey 2.0a1pre, and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to loading multiple RDF files in a XUL tree element.
	</description>
 </metadata>
<!-- d3be5c712e2e2706b7b11ecd08d9e22f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053589" comment="MozillaFirefox-translations less than 3.0.12-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053590" comment="MozillaFirefox less than 3.0.12-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053591" comment="mozilla-xulrunner190-32bit less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053597" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053592" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053599" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053593" comment="mozilla-xulrunner190-translations less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053595" comment="mozilla-xulrunner190 less than 1.9.0.12-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092465" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2465</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2465" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2465" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.12 and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via vectors involving double frame construction, related to (1) nsHTMLContentSink.cpp, (2) nsXMLContentSink.cpp, and (3) nsPresShell.cpp, and the nsSubDocumentFrame::Reflow function.
	</description>
 </metadata>
<!-- d3be5c712e2e2706b7b11ecd08d9e22f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053589" comment="MozillaFirefox-translations less than 3.0.12-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053590" comment="MozillaFirefox less than 3.0.12-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053591" comment="mozilla-xulrunner190-32bit less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053597" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053592" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053599" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053593" comment="mozilla-xulrunner190-translations less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053595" comment="mozilla-xulrunner190 less than 1.9.0.12-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092466" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2466</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2466" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2466" source="CVE"/>
	<description>
	The JavaScript engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsDOMClassInfo.cpp, (2) JS_HashTableRawLookup, and (3) MirrorWrappedNativeParent and js_LockGCThingRT.
	</description>
 </metadata>
<!-- d3be5c712e2e2706b7b11ecd08d9e22f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053589" comment="MozillaFirefox-translations less than 3.0.12-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053590" comment="MozillaFirefox less than 3.0.12-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053591" comment="mozilla-xulrunner190-32bit less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053597" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053592" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053599" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053593" comment="mozilla-xulrunner190-translations less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053595" comment="mozilla-xulrunner190 less than 1.9.0.12-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092467" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2467</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2467" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2467" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.12 and 3.5 before 3.5.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving a Flash object, a slow script dialog, and the unloading of the Flash plugin, which triggers attempted use of a deleted object.
	</description>
 </metadata>
<!-- d3be5c712e2e2706b7b11ecd08d9e22f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053589" comment="MozillaFirefox-translations less than 3.0.12-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053590" comment="MozillaFirefox less than 3.0.12-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053591" comment="mozilla-xulrunner190-32bit less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053597" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053592" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053599" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053593" comment="mozilla-xulrunner190-translations less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053595" comment="mozilla-xulrunner190 less than 1.9.0.12-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092469" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2469</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2469" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2469" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.12 does not properly handle an SVG element that has a property with a watch function and an __defineSetter__ function, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted document, related to a certain pointer misinterpretation.
	</description>
 </metadata>
<!-- d3be5c712e2e2706b7b11ecd08d9e22f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053589" comment="MozillaFirefox-translations less than 3.0.12-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053590" comment="MozillaFirefox less than 3.0.12-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053591" comment="mozilla-xulrunner190-32bit less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053597" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053592" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053599" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053593" comment="mozilla-xulrunner190-translations less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053595" comment="mozilla-xulrunner190 less than 1.9.0.12-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092471" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2471</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2471" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2471" source="CVE"/>
	<description>
	The setTimeout function in Mozilla Firefox before 3.0.12 does not properly preserve object wrapping, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted call, related to XPCNativeWrapper.
	</description>
 </metadata>
<!-- d3be5c712e2e2706b7b11ecd08d9e22f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053589" comment="MozillaFirefox-translations less than 3.0.12-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053590" comment="MozillaFirefox less than 3.0.12-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053591" comment="mozilla-xulrunner190-32bit less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053597" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053592" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053599" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053593" comment="mozilla-xulrunner190-translations less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053595" comment="mozilla-xulrunner190 less than 1.9.0.12-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092472" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2472</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2472" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2472" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted document, related to a "cross origin wrapper bypass."
	</description>
 </metadata>
<!-- d3be5c712e2e2706b7b11ecd08d9e22f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053589" comment="MozillaFirefox-translations less than 3.0.12-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053590" comment="MozillaFirefox less than 3.0.12-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053591" comment="mozilla-xulrunner190-32bit less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053597" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053592" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053599" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053593" comment="mozilla-xulrunner190-translations less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053595" comment="mozilla-xulrunner190 less than 1.9.0.12-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092473" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2473</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2473" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2473" source="CVE"/>
	<description>
	neon before 0.28.6, when expat is used, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
	</description>
 </metadata>
<!-- db036d6c88b93b6c89d6d75d9b617dce -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009055774" comment="libneon27 less than 0.28.3-2.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055775" comment="neon less than 0.28.3-2.12.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092475" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2475</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2475" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2475" source="CVE"/>
	<description>
	Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, might allow context-dependent attackers to obtain sensitive information via vectors involving static variables that are declared without the final keyword, related to (1) LayoutQueue, (2) Cursor.predefined, (3) AccessibleResourceBundle.getContents, (4) ImageReaderSpi.STANDARD_INPUT_TYPE, (5) ImageWriterSpi.STANDARD_OUTPUT_TYPE, (6) the imageio plugins, (7) DnsContext.debug, (8) RmfFileReader/StandardMidiFileWriter.types, (9) AbstractSaslImpl.logger, (10) Synth.Region.uiToRegionMap/lowerCaseNameMap, (11) the Introspector class and a cache of BeanInfo, and (12) JAX-WS, a different vulnerability than CVE-2009-2673.
	</description>
 </metadata>
<!-- accd5a6b831574e65ab9c351daa38e5b -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053757" comment="java-1_6_0-sun-alsa less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053763" comment="java-1_6_0-sun-demo less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053759" comment="java-1_6_0-sun-jdbc less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053760" comment="java-1_6_0-sun-plugin less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053761" comment="java-1_6_0-sun-src less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053762" comment="java-1_6_0-sun less than 1.6.0.u15-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092476" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2476</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2476" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2476" source="CVE"/>
	<description>
	The Java Management Extensions (JMX) implementation in Sun Java SE 6 before Update 15, and OpenJDK, does not properly enforce OpenType checks, which allows context-dependent attackers to bypass intended access restrictions by leveraging finalizer resurrection to obtain a reference to a privileged object.
	</description>
 </metadata>
<!-- accd5a6b831574e65ab9c351daa38e5b -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053757" comment="java-1_6_0-sun-alsa less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053763" comment="java-1_6_0-sun-demo less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053759" comment="java-1_6_0-sun-jdbc less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053760" comment="java-1_6_0-sun-plugin less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053761" comment="java-1_6_0-sun-src less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053762" comment="java-1_6_0-sun less than 1.6.0.u15-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092493" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2493</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2493" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2493" source="CVE"/>
	<description>
	The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1; and Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2; does not properly restrict use of OleLoadFromStream in instantiating objects from data streams, which allows remote attackers to execute arbitrary code via a crafted HTML document with an ATL (1) component or (2) control, related to ATL headers and bypassing security policies, aka "ATL COM Initialization Vulnerability."
	</description>
 </metadata>
<!-- 0ed97f904ab5337b5e08c83e789c22d2 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053711" comment="flash-player less than 10.0.32.18-0.1.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092560" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2560</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2560" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2560" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in Wireshark 1.2.0 allow remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace and is processed by the (1) Bluetooth L2CAP, (2) RADIUS, or (3) MIOP dissector. NOTE: it was later reported that the RADIUS issue also affects 0.10.13 through 1.0.9.
	</description>
 </metadata>
<!-- 21376954221689990a2fee3602c8189f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056792" comment="wireshark less than 1.0.5-1.31.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092562" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2562</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2562" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2562" source="CVE"/>
	<description>
	Unspecified vulnerability in the AFS dissector in Wireshark 0.9.2 through 1.2.0 allows remote attackers to cause a denial of service (crash) via unknown vectors.
	</description>
 </metadata>
<!-- dbebbebc6602a5f4dc39225f2c067daa -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054498" comment="wireshark less than 1.0.5-1.27.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092563" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2563</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2563" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2563" source="CVE"/>
	<description>
	Unspecified vulnerability in the Infiniband dissector in Wireshark 1.0.6 through 1.2.0, when running on unspecified platforms, allows remote attackers to cause a denial of service (crash) via unknown vectors.
	</description>
 </metadata>
<!-- 963ff40259d4863a011be226650534cb -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058844" comment="wireshark less than 1.0.5-1.34.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092564" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2564</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2564" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2564" source="CVE"/>
	<description>
	NOS Microsystems getPlus Download Manager, as used in Adobe Reader 1.6.2.36 and possibly other versions, Corel getPlus Download Manager before 1.5.0.48, and possibly other products, installs NOS\bin\getPlus_HelperSvc.exe with insecure permissions (Everyone:Full Control), which allows local users to gain SYSTEM privileges by replacing getPlus_HelperSvc.exe with a Trojan horse program, as demonstrated by use of getPlus Download Manager within Adobe Reader. NOTE: within Adobe Reader, the scope of this issue is limited because the program is deleted and the associated service is not automatically launched after a successful installation and reboot.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- ce38af327adaced851154dd69b821772 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055730" comment="acroread_ja less than 8.1.7-0.1.1"/>
	</criteria>
	<!-- da542e714548e7606e770f4fa3ce65f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055727" comment="acroread less than 8.1.7-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092624" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2624</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2624" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2624" source="CVE"/>
	<description>
	The huft_build function in inflate.c in gzip before 1.3.13 creates a hufts (aka huffman) table that is too small, which allows remote attackers to cause a denial of service (application crash or infinite loop) or possibly execute arbitrary code via a crafted archive.  NOTE: this issue is caused by a CVE-2006-4334 regression.
	</description>
 </metadata>
<!-- 8388a149c9d32703af6f0ac8782851c4 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057426" comment="gzip less than 1.3.12-69.19.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092625" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2625</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2625" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2625" source="CVE"/>
	<description>
	XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1f9677a08fca714e8676c96c9e388edb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054298" comment="xerces-j2 less than 2.8.1-238.27.1"/>
	</criteria>
	<!-- cc3e3bda8217aa28262b6982edd9bee5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060325" comment="libpython2_6-1_0-32bit less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060327" comment="libpython2_6-1_0 less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060329" comment="python-base-32bit less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060331" comment="python-base less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060332" comment="python-curses less than 2.6.0-8.9.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060429" comment="python-devel less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060338" comment="python-xml less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060339" comment="python less than 2.6.0-8.9.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092654" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2654</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2654" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2654" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.13, and 3.5.x before 3.5.2, allows remote attackers to spoof the address bar, and possibly conduct phishing attacks, via a crafted web page that calls window.open with an invalid character in the URL, makes document.write calls to the resulting object, and then calls the stop method during the loading of the error page.
	</description>
 </metadata>
<!-- 0f13983ab3e07c9cb46294b6377d70a9 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053944" comment="MozillaFirefox-translations less than 3.0.13-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053945" comment="MozillaFirefox less than 3.0.13-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053946" comment="gconf2-32bit less than 2.24.0-7.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053948" comment="gconf2 less than 2.24.0-7.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053949" comment="libidl-32bit less than 0.8.11-2.14"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053951" comment="libidl less than 0.8.11-2.14"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053952" comment="mozilla-xulrunner190-32bit less than 1.9.0.13-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053972" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.13-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053953" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.13-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053974" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.13-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053954" comment="mozilla-xulrunner190-translations less than 1.9.0.13-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053956" comment="mozilla-xulrunner190 less than 1.9.0.13-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053957" comment="orbit2-32bit less than 2.14.16-2.16"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053959" comment="orbit2 less than 2.14.16-2.16"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092662" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2662</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2662" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2662" source="CVE"/>
	<description>
	The browser engine in Mozilla Firefox 3.5.x before 3.5.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the TraceRecorder::snapshot function in js/src/jstracer.cpp, and unspecified other vectors.
	</description>
 </metadata>
<!-- 0f13983ab3e07c9cb46294b6377d70a9 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053944" comment="MozillaFirefox-translations less than 3.0.13-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053945" comment="MozillaFirefox less than 3.0.13-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053946" comment="gconf2-32bit less than 2.24.0-7.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053948" comment="gconf2 less than 2.24.0-7.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053949" comment="libidl-32bit less than 0.8.11-2.14"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053951" comment="libidl less than 0.8.11-2.14"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053952" comment="mozilla-xulrunner190-32bit less than 1.9.0.13-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053972" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.13-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053953" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.13-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053974" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.13-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053954" comment="mozilla-xulrunner190-translations less than 1.9.0.13-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053956" comment="mozilla-xulrunner190 less than 1.9.0.13-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053957" comment="orbit2-32bit less than 2.14.16-2.16"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053959" comment="orbit2 less than 2.14.16-2.16"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092663" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2663</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2009-2663" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2663" source="CVE"/>
	<description>
	libvorbis before r16182, as used in Mozilla Firefox 3.5.x before 3.5.2 and other products, allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .ogg file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0f13983ab3e07c9cb46294b6377d70a9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053944" comment="MozillaFirefox-translations less than 3.0.13-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053945" comment="MozillaFirefox less than 3.0.13-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053946" comment="gconf2-32bit less than 2.24.0-7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053948" comment="gconf2 less than 2.24.0-7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053949" comment="libidl-32bit less than 0.8.11-2.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053951" comment="libidl less than 0.8.11-2.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053952" comment="mozilla-xulrunner190-32bit less than 1.9.0.13-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053972" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.13-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053953" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.13-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053974" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.13-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053954" comment="mozilla-xulrunner190-translations less than 1.9.0.13-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053956" comment="mozilla-xulrunner190 less than 1.9.0.13-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053957" comment="orbit2-32bit less than 2.14.16-2.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053959" comment="orbit2 less than 2.14.16-2.16"/>
		</criteria>
	</criteria>
	<!-- 29a723aec45f6f33d099de1d7add5181 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061090" comment="libvorbis-32bit less than 1.2.0-79.13.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061093" comment="libvorbis less than 1.2.0-79.13.1"/>
		</criteria>
	</criteria>
	<!-- 6f61731fb3658c18c77c67445b09caf1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061090" comment="libvorbis-32bit less than 1.2.0-79.13.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061093" comment="libvorbis less than 1.2.0-79.13.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092664" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2664</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2664" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2664" source="CVE"/>
	<description>
	The js_watch_set function in js/src/jsdbgapi.cpp in the JavaScript engine in Mozilla Firefox before 3.0.12 allows remote attackers to cause a denial of service (assertion failure and application exit) or possibly execute arbitrary code via a crafted .js file, related to a "memory safety bug." NOTE: this was originally reported as affecting versions before 3.0.13.
	</description>
 </metadata>
<!-- 0f13983ab3e07c9cb46294b6377d70a9 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053944" comment="MozillaFirefox-translations less than 3.0.13-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053945" comment="MozillaFirefox less than 3.0.13-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053946" comment="gconf2-32bit less than 2.24.0-7.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053948" comment="gconf2 less than 2.24.0-7.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053949" comment="libidl-32bit less than 0.8.11-2.14"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053951" comment="libidl less than 0.8.11-2.14"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053952" comment="mozilla-xulrunner190-32bit less than 1.9.0.13-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053972" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.13-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053953" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.13-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053974" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.13-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053954" comment="mozilla-xulrunner190-translations less than 1.9.0.13-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053956" comment="mozilla-xulrunner190 less than 1.9.0.13-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053957" comment="orbit2-32bit less than 2.14.16-2.16"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053959" comment="orbit2 less than 2.14.16-2.16"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092666" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2666</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2666" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2666" source="CVE"/>
	<description>
	socket.c in fetchmail before 6.3.11 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
	</description>
 </metadata>
<!-- 26aa1c657e53800ab93f6510f4c057b5 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053783" comment="fetchmail less than 6.3.8.90-13.16.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092670" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2670</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2670" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2670" source="CVE"/>
	<description>
	The audio system in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to java.lang.System properties by (1) untrusted applets and (2) Java Web Start applications, which allows context-dependent attackers to obtain sensitive information by reading these properties.
	</description>
 </metadata>
<!-- accd5a6b831574e65ab9c351daa38e5b -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053757" comment="java-1_6_0-sun-alsa less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053763" comment="java-1_6_0-sun-demo less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053759" comment="java-1_6_0-sun-jdbc less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053760" comment="java-1_6_0-sun-plugin less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053761" comment="java-1_6_0-sun-src less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053762" comment="java-1_6_0-sun less than 1.6.0.u15-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092671" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2671</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2671" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2671" source="CVE"/>
	<description>
	The SOCKS proxy implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows remote attackers to discover the username of the account that invoked an untrusted (1) applet or (2) Java Web Start application via unspecified vectors.
	</description>
 </metadata>
<!-- accd5a6b831574e65ab9c351daa38e5b -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053757" comment="java-1_6_0-sun-alsa less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053763" comment="java-1_6_0-sun-demo less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053759" comment="java-1_6_0-sun-jdbc less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053760" comment="java-1_6_0-sun-plugin less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053761" comment="java-1_6_0-sun-src less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053762" comment="java-1_6_0-sun less than 1.6.0.u15-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092672" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2672</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2672" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2672" source="CVE"/>
	<description>
	The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to browser cookies by untrusted (1) applets and (2) Java Web Start applications, which allows remote attackers to hijack web sessions via unspecified vectors.
	</description>
 </metadata>
<!-- accd5a6b831574e65ab9c351daa38e5b -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053757" comment="java-1_6_0-sun-alsa less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053763" comment="java-1_6_0-sun-demo less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053759" comment="java-1_6_0-sun-jdbc less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053760" comment="java-1_6_0-sun-plugin less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053761" comment="java-1_6_0-sun-src less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053762" comment="java-1_6_0-sun less than 1.6.0.u15-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092673" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2673</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2673" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2673" source="CVE"/>
	<description>
	The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unspecified vectors, related to a declaration that lacks the final keyword.
	</description>
 </metadata>
<!-- accd5a6b831574e65ab9c351daa38e5b -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053757" comment="java-1_6_0-sun-alsa less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053763" comment="java-1_6_0-sun-demo less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053759" comment="java-1_6_0-sun-jdbc less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053760" comment="java-1_6_0-sun-plugin less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053761" comment="java-1_6_0-sun-src less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053762" comment="java-1_6_0-sun less than 1.6.0.u15-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092674" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2674</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2674" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2674" source="CVE"/>
	<description>
	Integer overflow in javaws.exe in Sun Java Web Start in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 allows context-dependent attackers to execute arbitrary code via a crafted JPEG image that is not properly handled during display to a splash screen, which triggers a heap-based buffer overflow.
	</description>
 </metadata>
<!-- accd5a6b831574e65ab9c351daa38e5b -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053757" comment="java-1_6_0-sun-alsa less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053763" comment="java-1_6_0-sun-demo less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053759" comment="java-1_6_0-sun-jdbc less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053760" comment="java-1_6_0-sun-plugin less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053761" comment="java-1_6_0-sun-src less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053762" comment="java-1_6_0-sun less than 1.6.0.u15-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092675" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2675</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2675" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2675" source="CVE"/>
	<description>
	Integer overflow in the unpack200 utility in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows context-dependent attackers to gain privileges via unspecified length fields in the header of a Pack200-compressed JAR file, which leads to a heap-based buffer overflow during decompression.
	</description>
 </metadata>
<!-- accd5a6b831574e65ab9c351daa38e5b -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053757" comment="java-1_6_0-sun-alsa less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053763" comment="java-1_6_0-sun-demo less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053759" comment="java-1_6_0-sun-jdbc less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053760" comment="java-1_6_0-sun-plugin less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053761" comment="java-1_6_0-sun-src less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053762" comment="java-1_6_0-sun less than 1.6.0.u15-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092676" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2676</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2676" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2676" source="CVE"/>
	<description>
	Unspecified vulnerability in JNLPAppletlauncher in Sun Java SE, and SE for Business, in JDK and JRE 6 Update 14 and earlier and JDK and JRE 5.0 Update 19 and earlier; and Java SE for Business in SDK and JRE 1.4.2_21 and earlier; allows remote attackers to create or modify arbitrary files via vectors involving an untrusted Java applet that accesses an old version of JNLPAppletLauncher.
	</description>
 </metadata>
<!-- accd5a6b831574e65ab9c351daa38e5b -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053757" comment="java-1_6_0-sun-alsa less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053763" comment="java-1_6_0-sun-demo less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053759" comment="java-1_6_0-sun-jdbc less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053760" comment="java-1_6_0-sun-plugin less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053761" comment="java-1_6_0-sun-src less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053762" comment="java-1_6_0-sun less than 1.6.0.u15-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092688" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2688</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2688" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2688" source="CVE"/>
	<description>
	Multiple integer overflows in glyphs-eimage.c in XEmacs 21.4.22, when running on Windows, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) the tiff_instantiate function processing a crafted TIFF file, (2) the png_instantiate function processing a crafted PNG file, and (3) the jpeg_instantiate function processing a crafted JPEG file, all which trigger a heap-based buffer overflow.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
	</description>
 </metadata>
<!-- 2f3c5cd409e146b9e7c1494fd51dd21a -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009054269" comment="xemacs-info less than 21.5.28.20080401-59.23.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054270" comment="xemacs less than 21.5.28.20080401-59.23.2"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092689" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2689</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2689" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2689" source="CVE"/>
	<description>
	JDK13Services.getProviders in Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, grants full privileges to instances of unspecified object types, which allows context-dependent attackers to bypass intended access restrictions via an untrusted (1) applet or (2) application.
	</description>
 </metadata>
<!-- accd5a6b831574e65ab9c351daa38e5b -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053757" comment="java-1_6_0-sun-alsa less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053763" comment="java-1_6_0-sun-demo less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053759" comment="java-1_6_0-sun-jdbc less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053760" comment="java-1_6_0-sun-plugin less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053761" comment="java-1_6_0-sun-src less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053762" comment="java-1_6_0-sun less than 1.6.0.u15-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092690" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2690</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2690" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2690" source="CVE"/>
	<description>
	The encoder in Sun Java SE 6 before Update 15, and OpenJDK, grants read access to private variables with unspecified names, which allows context-dependent attackers to obtain sensitive information via an untrusted (1) applet or (2) application.
	</description>
 </metadata>
<!-- accd5a6b831574e65ab9c351daa38e5b -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053757" comment="java-1_6_0-sun-alsa less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053763" comment="java-1_6_0-sun-demo less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053759" comment="java-1_6_0-sun-jdbc less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053760" comment="java-1_6_0-sun-plugin less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053761" comment="java-1_6_0-sun-src less than 1.6.0.u15-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053762" comment="java-1_6_0-sun less than 1.6.0.u15-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092692" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2692</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2692" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2692" source="CVE"/>
	<description>
	The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using mmap to map page zero, placing arbitrary code on this page, and then invoking an unavailable operation, as demonstrated by the sendpage operation (sock_sendpage function) on a PF_PPPOX socket.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0522f4d2681968d0e344aad24e0e341b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054108" comment="kernel-default-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054182" comment="kernel-default-extra less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054109" comment="kernel-default less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054110" comment="kernel-pae-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054183" comment="kernel-pae-extra less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054111" comment="kernel-pae less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054112" comment="kernel-source less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054113" comment="kernel-syms less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054116" comment="kernel-xen-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054184" comment="kernel-xen-extra less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054117" comment="kernel-xen less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 125c8b5a7b30fdb1de7b2255eb1649a7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054108" comment="kernel-default-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054182" comment="kernel-default-extra less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054109" comment="kernel-default less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054112" comment="kernel-source less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054113" comment="kernel-syms less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054116" comment="kernel-xen-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054184" comment="kernel-xen-extra less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054117" comment="kernel-xen less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092694" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2694</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2694" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2694" source="CVE"/>
	<description>
	The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim) before 2.5.9 and Adium 1.3.5 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) by sending multiple crafted SLP (aka MSNSLP) messages to trigger an overwrite of an arbitrary memory location.  NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1376.
	</description>
 </metadata>
<!-- 2cd3f87b75950a877414c147a8efe9f6 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009054483" comment="finch less than 2.5.1-9.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054485" comment="libpurple-lang less than 2.5.1-9.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054486" comment="libpurple less than 2.5.1-9.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054488" comment="pidgin less than 2.5.1-9.13.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092700" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2700</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2700" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2700" source="CVE"/>
	<description>
	src/network/ssl/qsslcertificate.cpp in Nokia Trolltech Qt 4.x does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
	</description>
 </metadata>
<!-- c980cdd57955d1f78a74976fd2c23c32 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056137" comment="libqt4-32bit less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056138" comment="libqt4-qt3support-32bit less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056140" comment="libqt4-qt3support less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056141" comment="libqt4-sql-32bit less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056215" comment="libqt4-sql-sqlite-32bit less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056142" comment="libqt4-sql-sqlite less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056144" comment="libqt4-sql less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056145" comment="libqt4-x11-32bit less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056147" comment="libqt4-x11 less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056149" comment="libqt4 less than 4.4.3-12.11.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092730" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2730</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2730" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2730" source="CVE"/>
	<description>
	libgnutls in GnuTLS before 2.8.2 does not properly handle a '\0' character in a domain name in the subject's (1) Common Name (CN) or (2) Subject Alternative Name (SAN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
	</description>
 </metadata>
<!-- af7de3dbf0c217bd35268d7b9dccbe34 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009054538" comment="gnutls less than 2.4.1-24.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054539" comment="libgnutls26-32bit less than 2.4.1-24.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054541" comment="libgnutls26 less than 2.4.1-24.19.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092813" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2813</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2813" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2813" source="CVE"/>
	<description>
	Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in the SMB subsystem in Apple Mac OS X 10.5.8 when Windows File Sharing is enabled, Fedora 11, and other operating systems, does not properly handle errors in resolving pathnames, which allows remote authenticated users to bypass intended sharing restrictions, and read, create, or modify files, in certain circumstances involving user accounts that lack home directories.
	</description>
 </metadata>
<!-- dbedb3fb1fc74639fa0c893e6c0ad7f6 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009055477" comment="cifs-mount less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055479" comment="libsmbclient0-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055481" comment="libsmbclient0 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055482" comment="libtalloc1-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055484" comment="libtalloc1 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055485" comment="libtdb1-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055487" comment="libtdb1 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055488" comment="libwbclient0-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055490" comment="libwbclient0 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055491" comment="samba-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055492" comment="samba-client-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055494" comment="samba-client less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055495" comment="samba-krb-printing less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055613" comment="samba-vscan less than 0.3.6b-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055496" comment="samba-winbind-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055498" comment="samba-winbind less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055500" comment="samba less than 3.2.7-11.8.2"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092820" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2820</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2820" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2820" source="CVE"/>
	<description>
	The web interface in CUPS before 1.4.2, as used on Apple Mac OS X before 10.6.2 and other platforms, does not properly handle (1) HTTP headers and (2) HTML templates, which allows remote attackers to conduct cross-site scripting (XSS) attacks and HTTP response splitting attacks via vectors related to (a) the product's web interface, (b) the configuration of the print system, and (c) the titles of printed jobs, as demonstrated by an XSS attack that uses the kerberos parameter to the admin program, and leverages attribute injection and HTTP Parameter Pollution (HPP) issues.
	</description>
 </metadata>
<!-- d4e3a70fb8819a66d8ccea9697c425ea -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056119" comment="cups-client less than 1.3.9-8.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056120" comment="cups-libs-32bit less than 1.3.9-8.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056122" comment="cups-libs less than 1.3.9-8.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056123" comment="cups less than 1.3.9-8.20.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092848" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2848</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2848" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2848" source="CVE"/>
	<description>
	The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current-&gt;clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via a clone system call with CLONE_CHILD_SETTID or CLONE_CHILD_CLEARTID enabled, which is not properly handled during thread creation and exit.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 180ffe58c62210bba55d0af594f5207f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055844" comment="kernel-default-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055845" comment="kernel-default-extra less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055846" comment="kernel-default less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055852" comment="kernel-pae-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055853" comment="kernel-pae-extra less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055854" comment="kernel-pae less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055859" comment="kernel-source less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055860" comment="kernel-syms less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055865" comment="kernel-xen-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055866" comment="kernel-xen-extra less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055867" comment="kernel-xen less than 2.6.27.37-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 6d2f53ab7e3e69501a86208057c2ef96 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055844" comment="kernel-default-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055845" comment="kernel-default-extra less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055846" comment="kernel-default less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055859" comment="kernel-source less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055860" comment="kernel-syms less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055865" comment="kernel-xen-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055866" comment="kernel-xen-extra less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055867" comment="kernel-xen less than 2.6.27.37-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092903" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2903</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2903" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2903" source="CVE"/>
	<description>
	Memory leak in the appletalk subsystem in the Linux kernel 2.4.x through 2.4.37.6 and 2.6.x through 2.6.31, when the appletalk and ipddp modules are loaded but the ipddp"N" device is not found, allows remote attackers to cause a denial of service (memory consumption) via IP-DDP datagrams.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 114b9cf953db7d4a1a91082495d33414 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056549" comment="kernel-default-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056511" comment="kernel-xen-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056550" comment="kernel-xen-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056512" comment="kernel-xen less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- a3c4f0428e25dca1993e5018e76d6758 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056549" comment="kernel-default-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056519" comment="kernel-pae-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056552" comment="kernel-pae-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056520" comment="kernel-pae less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056511" comment="kernel-xen-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056550" comment="kernel-xen-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056512" comment="kernel-xen less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092906" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2906</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2906" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2906" source="CVE"/>
	<description>
	smbd in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8, and 3.4 before 3.4.2 allows remote authenticated users to cause a denial of service (infinite loop) via an unanticipated oplock break notification reply packet.
	</description>
 </metadata>
<!-- dbedb3fb1fc74639fa0c893e6c0ad7f6 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009055477" comment="cifs-mount less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055479" comment="libsmbclient0-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055481" comment="libsmbclient0 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055482" comment="libtalloc1-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055484" comment="libtalloc1 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055485" comment="libtdb1-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055487" comment="libtdb1 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055488" comment="libwbclient0-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055490" comment="libwbclient0 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055491" comment="samba-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055492" comment="samba-client-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055494" comment="samba-client less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055495" comment="samba-krb-printing less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055613" comment="samba-vscan less than 0.3.6b-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055496" comment="samba-winbind-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055498" comment="samba-winbind less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055500" comment="samba less than 3.2.7-11.8.2"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092909" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2909</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2909" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2909" source="CVE"/>
	<description>
	Integer signedness error in the ax25_setsockopt function in net/ax25/af_ax25.c in the ax25 subsystem in the Linux kernel before 2.6.31.2 allows local users to cause a denial of service (OOPS) via a crafted optlen value in an SO_BINDTODEVICE operation.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 180ffe58c62210bba55d0af594f5207f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055844" comment="kernel-default-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055845" comment="kernel-default-extra less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055846" comment="kernel-default less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055852" comment="kernel-pae-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055853" comment="kernel-pae-extra less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055854" comment="kernel-pae less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055859" comment="kernel-source less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055860" comment="kernel-syms less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055865" comment="kernel-xen-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055866" comment="kernel-xen-extra less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055867" comment="kernel-xen less than 2.6.27.37-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 6d2f53ab7e3e69501a86208057c2ef96 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055844" comment="kernel-default-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055845" comment="kernel-default-extra less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055846" comment="kernel-default less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055859" comment="kernel-source less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055860" comment="kernel-syms less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055865" comment="kernel-xen-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055866" comment="kernel-xen-extra less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055867" comment="kernel-xen less than 2.6.27.37-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092910" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2910</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2910" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2910" source="CVE"/>
	<description>
	arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.31.4 on the x86_64 platform does not clear certain kernel registers before a return to user mode, which allows local users to read register values from an earlier process by switching an ia32 process to 64-bit mode.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 114b9cf953db7d4a1a91082495d33414 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056549" comment="kernel-default-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056511" comment="kernel-xen-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056550" comment="kernel-xen-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056512" comment="kernel-xen less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- 180ffe58c62210bba55d0af594f5207f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055844" comment="kernel-default-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055845" comment="kernel-default-extra less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055846" comment="kernel-default less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055852" comment="kernel-pae-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055853" comment="kernel-pae-extra less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055854" comment="kernel-pae less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055859" comment="kernel-source less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055860" comment="kernel-syms less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055865" comment="kernel-xen-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055866" comment="kernel-xen-extra less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055867" comment="kernel-xen less than 2.6.27.37-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 6d2f53ab7e3e69501a86208057c2ef96 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055844" comment="kernel-default-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055845" comment="kernel-default-extra less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055846" comment="kernel-default less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055859" comment="kernel-source less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055860" comment="kernel-syms less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055865" comment="kernel-xen-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055866" comment="kernel-xen-extra less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055867" comment="kernel-xen less than 2.6.27.37-0.1.1"/>
		</criteria>
	</criteria>
	<!-- a3c4f0428e25dca1993e5018e76d6758 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056549" comment="kernel-default-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056519" comment="kernel-pae-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056552" comment="kernel-pae-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056520" comment="kernel-pae less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056511" comment="kernel-xen-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056550" comment="kernel-xen-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056512" comment="kernel-xen less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092948" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2948</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2948" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2948" source="CVE"/>
	<description>
	mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly enforce permissions, which allows local users to read part of the credentials file and obtain the password by specifying the path to the credentials file and using the --verbose or -v option.
	</description>
 </metadata>
<!-- dbedb3fb1fc74639fa0c893e6c0ad7f6 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009055477" comment="cifs-mount less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055479" comment="libsmbclient0-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055481" comment="libsmbclient0 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055482" comment="libtalloc1-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055484" comment="libtalloc1 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055485" comment="libtdb1-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055487" comment="libtdb1 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055488" comment="libwbclient0-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055490" comment="libwbclient0 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055491" comment="samba-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055492" comment="samba-client-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055494" comment="samba-client less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055495" comment="samba-krb-printing less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055613" comment="samba-vscan less than 0.3.6b-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055496" comment="samba-winbind-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055498" comment="samba-winbind less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055500" comment="samba less than 3.2.7-11.8.2"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092949" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2949</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2949" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2949" source="CVE"/>
	<description>
	Integer overflow in the XPMReader::ReadXPM function in filter.vcl/ixpm/svt_xpmread.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to execute arbitrary code via a crafted XPM file that triggers a heap-based buffer overflow.
	</description>
 </metadata>
<!-- b3f5b1e481a1ae74918748c80997e6c7 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009058823" comment="OpenOffice_org-LanguageTool-de less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058824" comment="OpenOffice_org-LanguageTool-en less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058825" comment="OpenOffice_org-LanguageTool-es less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058826" comment="OpenOffice_org-LanguageTool-fr less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058827" comment="OpenOffice_org-LanguageTool-it less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058828" comment="OpenOffice_org-LanguageTool-nl less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058829" comment="OpenOffice_org-LanguageTool-pl less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058830" comment="OpenOffice_org-LanguageTool-sv less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058831" comment="OpenOffice_org-LanguageTool less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058832" comment="OpenOffice_org-base-drivers-postgresql less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058833" comment="OpenOffice_org-base-extensions less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058741" comment="OpenOffice_org-base less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058834" comment="OpenOffice_org-calc-extensions less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058744" comment="OpenOffice_org-calc less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058746" comment="OpenOffice_org-components less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058835" comment="OpenOffice_org-draw-extensions less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058747" comment="OpenOffice_org-draw less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058749" comment="OpenOffice_org-filters-optional less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058750" comment="OpenOffice_org-filters less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058751" comment="OpenOffice_org-gnome less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058752" comment="OpenOffice_org-help-ar less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058753" comment="OpenOffice_org-help-cs less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058754" comment="OpenOffice_org-help-da less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058755" comment="OpenOffice_org-help-de less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058756" comment="OpenOffice_org-help-en-GB less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058757" comment="OpenOffice_org-help-en-US-devel less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058758" comment="OpenOffice_org-help-en-US less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058759" comment="OpenOffice_org-help-es less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058760" comment="OpenOffice_org-help-fr less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058836" comment="OpenOffice_org-help-gu-IN less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058837" comment="OpenOffice_org-help-hi-IN less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058761" comment="OpenOffice_org-help-hu less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058762" comment="OpenOffice_org-help-it less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058763" comment="OpenOffice_org-help-ja less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058838" comment="OpenOffice_org-help-ko less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058764" comment="OpenOffice_org-help-nl less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058765" comment="OpenOffice_org-help-pl less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058766" comment="OpenOffice_org-help-pt-BR less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058767" comment="OpenOffice_org-help-pt less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058768" comment="OpenOffice_org-help-ru less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058769" comment="OpenOffice_org-help-sv less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058770" comment="OpenOffice_org-help-zh-CN less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058771" comment="OpenOffice_org-help-zh-TW less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058772" comment="OpenOffice_org-icon-themes less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058839" comment="OpenOffice_org-impress-extensions less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058774" comment="OpenOffice_org-impress less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058775" comment="OpenOffice_org-kde less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058776" comment="OpenOffice_org-l10n-af less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058777" comment="OpenOffice_org-l10n-ar less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058778" comment="OpenOffice_org-l10n-ca less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058779" comment="OpenOffice_org-l10n-cs less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058780" comment="OpenOffice_org-l10n-da less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058781" comment="OpenOffice_org-l10n-de less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058782" comment="OpenOffice_org-l10n-el less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058783" comment="OpenOffice_org-l10n-en-GB less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058784" comment="OpenOffice_org-l10n-es less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058786" comment="OpenOffice_org-l10n-extras less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058787" comment="OpenOffice_org-l10n-fi less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058788" comment="OpenOffice_org-l10n-fr less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058840" comment="OpenOffice_org-l10n-gu-IN less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058841" comment="OpenOffice_org-l10n-hi-IN less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058789" comment="OpenOffice_org-l10n-hu less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058790" comment="OpenOffice_org-l10n-it less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058791" comment="OpenOffice_org-l10n-ja less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058842" comment="OpenOffice_org-l10n-ko less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058792" comment="OpenOffice_org-l10n-nb less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058793" comment="OpenOffice_org-l10n-nl less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058794" comment="OpenOffice_org-l10n-nn less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058795" comment="OpenOffice_org-l10n-pl less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058796" comment="OpenOffice_org-l10n-pt-BR less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058797" comment="OpenOffice_org-l10n-pt less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058798" comment="OpenOffice_org-l10n-ru less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058799" comment="OpenOffice_org-l10n-sk less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058800" comment="OpenOffice_org-l10n-sv less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058801" comment="OpenOffice_org-l10n-xh less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058802" comment="OpenOffice_org-l10n-zh-CN less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058803" comment="OpenOffice_org-l10n-zh-TW less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058804" comment="OpenOffice_org-l10n-zu less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058806" comment="OpenOffice_org-libs-core less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058808" comment="OpenOffice_org-libs-extern less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058810" comment="OpenOffice_org-libs-gui less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058811" comment="OpenOffice_org-mailmerge less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058812" comment="OpenOffice_org-math less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058813" comment="OpenOffice_org-mono less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058814" comment="OpenOffice_org-officebean less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058815" comment="OpenOffice_org-openclipart less than 3-1.25.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058816" comment="OpenOffice_org-pyuno less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058819" comment="OpenOffice_org-ure less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058843" comment="OpenOffice_org-writer-extensions less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058821" comment="OpenOffice_org-writer less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058822" comment="OpenOffice_org less than 3.2.0.7-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092950" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2950</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2950" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2950" source="CVE"/>
	<description>
	Heap-based buffer overflow in the GIFLZWDecompressor::GIFLZWDecompressor function in filter.vcl/lgif/decode.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file, related to LZW decompression.
	</description>
 </metadata>
<!-- b3f5b1e481a1ae74918748c80997e6c7 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009058823" comment="OpenOffice_org-LanguageTool-de less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058824" comment="OpenOffice_org-LanguageTool-en less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058825" comment="OpenOffice_org-LanguageTool-es less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058826" comment="OpenOffice_org-LanguageTool-fr less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058827" comment="OpenOffice_org-LanguageTool-it less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058828" comment="OpenOffice_org-LanguageTool-nl less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058829" comment="OpenOffice_org-LanguageTool-pl less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058830" comment="OpenOffice_org-LanguageTool-sv less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058831" comment="OpenOffice_org-LanguageTool less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058832" comment="OpenOffice_org-base-drivers-postgresql less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058833" comment="OpenOffice_org-base-extensions less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058741" comment="OpenOffice_org-base less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058834" comment="OpenOffice_org-calc-extensions less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058744" comment="OpenOffice_org-calc less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058746" comment="OpenOffice_org-components less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058835" comment="OpenOffice_org-draw-extensions less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058747" comment="OpenOffice_org-draw less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058749" comment="OpenOffice_org-filters-optional less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058750" comment="OpenOffice_org-filters less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058751" comment="OpenOffice_org-gnome less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058752" comment="OpenOffice_org-help-ar less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058753" comment="OpenOffice_org-help-cs less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058754" comment="OpenOffice_org-help-da less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058755" comment="OpenOffice_org-help-de less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058756" comment="OpenOffice_org-help-en-GB less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058757" comment="OpenOffice_org-help-en-US-devel less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058758" comment="OpenOffice_org-help-en-US less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058759" comment="OpenOffice_org-help-es less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058760" comment="OpenOffice_org-help-fr less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058836" comment="OpenOffice_org-help-gu-IN less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058837" comment="OpenOffice_org-help-hi-IN less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058761" comment="OpenOffice_org-help-hu less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058762" comment="OpenOffice_org-help-it less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058763" comment="OpenOffice_org-help-ja less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058838" comment="OpenOffice_org-help-ko less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058764" comment="OpenOffice_org-help-nl less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058765" comment="OpenOffice_org-help-pl less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058766" comment="OpenOffice_org-help-pt-BR less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058767" comment="OpenOffice_org-help-pt less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058768" comment="OpenOffice_org-help-ru less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058769" comment="OpenOffice_org-help-sv less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058770" comment="OpenOffice_org-help-zh-CN less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058771" comment="OpenOffice_org-help-zh-TW less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058772" comment="OpenOffice_org-icon-themes less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058839" comment="OpenOffice_org-impress-extensions less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058774" comment="OpenOffice_org-impress less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058775" comment="OpenOffice_org-kde less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058776" comment="OpenOffice_org-l10n-af less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058777" comment="OpenOffice_org-l10n-ar less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058778" comment="OpenOffice_org-l10n-ca less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058779" comment="OpenOffice_org-l10n-cs less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058780" comment="OpenOffice_org-l10n-da less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058781" comment="OpenOffice_org-l10n-de less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058782" comment="OpenOffice_org-l10n-el less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058783" comment="OpenOffice_org-l10n-en-GB less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058784" comment="OpenOffice_org-l10n-es less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058786" comment="OpenOffice_org-l10n-extras less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058787" comment="OpenOffice_org-l10n-fi less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058788" comment="OpenOffice_org-l10n-fr less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058840" comment="OpenOffice_org-l10n-gu-IN less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058841" comment="OpenOffice_org-l10n-hi-IN less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058789" comment="OpenOffice_org-l10n-hu less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058790" comment="OpenOffice_org-l10n-it less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058791" comment="OpenOffice_org-l10n-ja less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058842" comment="OpenOffice_org-l10n-ko less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058792" comment="OpenOffice_org-l10n-nb less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058793" comment="OpenOffice_org-l10n-nl less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058794" comment="OpenOffice_org-l10n-nn less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058795" comment="OpenOffice_org-l10n-pl less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058796" comment="OpenOffice_org-l10n-pt-BR less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058797" comment="OpenOffice_org-l10n-pt less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058798" comment="OpenOffice_org-l10n-ru less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058799" comment="OpenOffice_org-l10n-sk less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058800" comment="OpenOffice_org-l10n-sv less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058801" comment="OpenOffice_org-l10n-xh less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058802" comment="OpenOffice_org-l10n-zh-CN less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058803" comment="OpenOffice_org-l10n-zh-TW less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058804" comment="OpenOffice_org-l10n-zu less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058806" comment="OpenOffice_org-libs-core less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058808" comment="OpenOffice_org-libs-extern less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058810" comment="OpenOffice_org-libs-gui less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058811" comment="OpenOffice_org-mailmerge less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058812" comment="OpenOffice_org-math less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058813" comment="OpenOffice_org-mono less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058814" comment="OpenOffice_org-officebean less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058815" comment="OpenOffice_org-openclipart less than 3-1.25.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058816" comment="OpenOffice_org-pyuno less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058819" comment="OpenOffice_org-ure less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058843" comment="OpenOffice_org-writer-extensions less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058821" comment="OpenOffice_org-writer less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058822" comment="OpenOffice_org less than 3.2.0.7-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092957" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2957</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2957" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2957" source="CVE"/>
	<description>
	Heap-based buffer overflow in the tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, might allow remote attackers to execute arbitrary code via a long filename in a TFTP packet, as demonstrated by a read (aka RRQ) request.
	</description>
 </metadata>
<!-- 8a9b5d38120dd10534d589b7deb85f02 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054813" comment="dnsmasq less than 2.45-12.23.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092958" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2958</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2958" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2958" source="CVE"/>
	<description>
	The tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a TFTP read (aka RRQ) request with a malformed blksize option.
	</description>
 </metadata>
<!-- 8a9b5d38120dd10534d589b7deb85f02 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054813" comment="dnsmasq less than 2.45-12.23.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092979" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2979</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2979" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2979" source="CVE"/>
	<description>
	Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 do not properly perform XMP-XML entity expansion, which allows remote attackers to cause a denial of service via a crafted document.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- ce38af327adaced851154dd69b821772 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055730" comment="acroread_ja less than 8.1.7-0.1.1"/>
	</criteria>
	<!-- da542e714548e7606e770f4fa3ce65f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055727" comment="acroread less than 8.1.7-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092980" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2980</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2980" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2980" source="CVE"/>
	<description>
	Integer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- ce38af327adaced851154dd69b821772 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055730" comment="acroread_ja less than 8.1.7-0.1.1"/>
	</criteria>
	<!-- da542e714548e7606e770f4fa3ce65f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055727" comment="acroread less than 8.1.7-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092981" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2981</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2981" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2981" source="CVE"/>
	<description>
	Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 do not properly validate input, which might allow attackers to bypass intended Trust Manager restrictions via unspecified vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- ce38af327adaced851154dd69b821772 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055730" comment="acroread_ja less than 8.1.7-0.1.1"/>
	</criteria>
	<!-- da542e714548e7606e770f4fa3ce65f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055727" comment="acroread less than 8.1.7-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092982" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2982</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2982" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2982" source="CVE"/>
	<description>
	An unspecified certificate in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might allow remote attackers to conduct a "social engineering attack" via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- ce38af327adaced851154dd69b821772 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055730" comment="acroread_ja less than 8.1.7-0.1.1"/>
	</criteria>
	<!-- da542e714548e7606e770f4fa3ce65f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055727" comment="acroread less than 8.1.7-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092983" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2983</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2983" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2983" source="CVE"/>
	<description>
	Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 allow attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- ce38af327adaced851154dd69b821772 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055730" comment="acroread_ja less than 8.1.7-0.1.1"/>
	</criteria>
	<!-- da542e714548e7606e770f4fa3ce65f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055727" comment="acroread less than 8.1.7-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092985" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2985</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2985" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2985" source="CVE"/>
	<description>
	Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allow attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-2996.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- ce38af327adaced851154dd69b821772 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055730" comment="acroread_ja less than 8.1.7-0.1.1"/>
	</criteria>
	<!-- da542e714548e7606e770f4fa3ce65f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055727" comment="acroread less than 8.1.7-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092986" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2986</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2986" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2986" source="CVE"/>
	<description>
	Multiple heap-based buffer overflows in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 might allow attackers to execute arbitrary code via unspecified vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- ce38af327adaced851154dd69b821772 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055730" comment="acroread_ja less than 8.1.7-0.1.1"/>
	</criteria>
	<!-- da542e714548e7606e770f4fa3ce65f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055727" comment="acroread less than 8.1.7-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092988" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2988</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2988" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2988" source="CVE"/>
	<description>
	Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 do not properly validate input, which allows attackers to cause a denial of service via unspecified vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- ce38af327adaced851154dd69b821772 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055730" comment="acroread_ja less than 8.1.7-0.1.1"/>
	</criteria>
	<!-- da542e714548e7606e770f4fa3ce65f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055727" comment="acroread less than 8.1.7-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092990" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2990</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2990" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2990" source="CVE"/>
	<description>
	Array index error in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might allow attackers to execute arbitrary code via unspecified vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- ce38af327adaced851154dd69b821772 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055730" comment="acroread_ja less than 8.1.7-0.1.1"/>
	</criteria>
	<!-- da542e714548e7606e770f4fa3ce65f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055727" comment="acroread less than 8.1.7-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092991" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2991</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2991" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2991" source="CVE"/>
	<description>
	Unspecified vulnerability in the Mozilla plug-in in Adobe Reader and Acrobat 8.x before 8.1.7, and possibly 7.x before 7.1.4 and 9.x before 9.2, might allow remote attackers to execute arbitrary code via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- ce38af327adaced851154dd69b821772 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055730" comment="acroread_ja less than 8.1.7-0.1.1"/>
	</criteria>
	<!-- da542e714548e7606e770f4fa3ce65f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055727" comment="acroread less than 8.1.7-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092992" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2992</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2992" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2992" source="CVE"/>
	<description>
	An unspecified ActiveX control in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 does not properly validate input, which allows attackers to cause a denial of service via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- ce38af327adaced851154dd69b821772 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055730" comment="acroread_ja less than 8.1.7-0.1.1"/>
	</criteria>
	<!-- da542e714548e7606e770f4fa3ce65f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055727" comment="acroread less than 8.1.7-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092993" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2993</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2993" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2993" source="CVE"/>
	<description>
	The JavaScript for Acrobat API in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 does not properly implement the (1) Privileged Context and (2) Safe Path restrictions for unspecified JavaScript methods, which allows remote attackers to create arbitrary files, and possibly execute arbitrary code, via the cPath parameter in a crafted PDF file.  NOTE: some of these details are obtained from third party information.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- ce38af327adaced851154dd69b821772 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055730" comment="acroread_ja less than 8.1.7-0.1.1"/>
	</criteria>
	<!-- da542e714548e7606e770f4fa3ce65f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055727" comment="acroread less than 8.1.7-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092994" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2994</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2994" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2994" source="CVE"/>
	<description>
	Buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 might allow attackers to execute arbitrary code via unspecified vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- ce38af327adaced851154dd69b821772 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055730" comment="acroread_ja less than 8.1.7-0.1.1"/>
	</criteria>
	<!-- da542e714548e7606e770f4fa3ce65f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055727" comment="acroread less than 8.1.7-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092996" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2996</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2996" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2996" source="CVE"/>
	<description>
	Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allow attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-2985.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- ce38af327adaced851154dd69b821772 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055730" comment="acroread_ja less than 8.1.7-0.1.1"/>
	</criteria>
	<!-- da542e714548e7606e770f4fa3ce65f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055727" comment="acroread less than 8.1.7-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092997" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2997</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2997" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2997" source="CVE"/>
	<description>
	Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 might allow attackers to execute arbitrary code via unspecified vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- ce38af327adaced851154dd69b821772 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055730" comment="acroread_ja less than 8.1.7-0.1.1"/>
	</criteria>
	<!-- da542e714548e7606e770f4fa3ce65f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055727" comment="acroread less than 8.1.7-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092998" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2998</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2998" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2998" source="CVE"/>
	<description>
	Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 do not properly validate input, which might allow attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-3458.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- ce38af327adaced851154dd69b821772 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055730" comment="acroread_ja less than 8.1.7-0.1.1"/>
	</criteria>
	<!-- da542e714548e7606e770f4fa3ce65f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055727" comment="acroread less than 8.1.7-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093002" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3002</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3002" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3002" source="CVE"/>
	<description>
	The Linux kernel before 2.6.31-rc7 does not initialize certain data structures within getname functions, which allows local users to read the contents of some kernel memory locations by calling getsockname on (1) an AF_APPLETALK socket, related to the atalk_getname function in net/appletalk/ddp.c; (2) an AF_IRDA socket, related to the irda_getname function in net/irda/af_irda.c; (3) an AF_ECONET socket, related to the econet_getname function in net/econet/af_econet.c; (4) an AF_NETROM socket, related to the nr_getname function in net/netrom/af_netrom.c; (5) an AF_ROSE socket, related to the rose_getname function in net/rose/af_rose.c; or (6) a raw CAN socket, related to the raw_getname function in net/can/raw.c.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 180ffe58c62210bba55d0af594f5207f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055844" comment="kernel-default-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055845" comment="kernel-default-extra less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055846" comment="kernel-default less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055852" comment="kernel-pae-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055853" comment="kernel-pae-extra less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055854" comment="kernel-pae less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055859" comment="kernel-source less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055860" comment="kernel-syms less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055865" comment="kernel-xen-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055866" comment="kernel-xen-extra less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055867" comment="kernel-xen less than 2.6.27.37-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 6d2f53ab7e3e69501a86208057c2ef96 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055844" comment="kernel-default-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055845" comment="kernel-default-extra less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055846" comment="kernel-default less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055859" comment="kernel-source less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055860" comment="kernel-syms less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055865" comment="kernel-xen-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055866" comment="kernel-xen-extra less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055867" comment="kernel-xen less than 2.6.27.37-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093024" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3024</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3024" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3024" source="CVE"/>
	<description>
	The verify_hostname_of_cert function in the certificate checking feature in IO-Socket-SSL (IO::Socket::SSL) 1.14 through 1.25 only matches the prefix of a hostname when no wildcard is used, which allows remote attackers to bypass the hostname check for a certificate.
	</description>
 </metadata>
<!-- bd0f3fd9459d5cdf06cf5c9214d908b2 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054781" comment="perl-IO-Socket-SSL less than 1.16-3.2.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093025" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3025</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3025" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3025" source="CVE"/>
	<description>
	Unspecified vulnerability in Pidgin 2.6.0 allows remote attackers to cause a denial of service (crash) via a link in a Yahoo IM.
	</description>
 </metadata>
<!-- 036b34b556d9338c53561c16d2f5a3ce -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056524" comment="cdparanoia-32bit less than IIIalpha9.8-691.22"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056526" comment="cdparanoia less than IIIalpha9.8-691.22"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056527" comment="desktop-file-utils less than 0.15-1.29"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056528" comment="fam-32bit less than 2.7.0-130.21"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056530" comment="fam less than 2.7.0-130.21"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056554" comment="finch less than 2.6.3-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056531" comment="gnome-vfs2-32bit less than 2.24.0-7.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056533" comment="gnome-vfs2 less than 2.24.0-7.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056555" comment="gstreamer-0_10-32bit less than 0.10.21-3.20"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056534" comment="gstreamer-0_10 less than 0.10.21-3.20"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056535" comment="libogg0-32bit less than 1.1.3-87.12"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056537" comment="libogg0 less than 1.1.3-87.12"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056538" comment="liboil-32bit less than 0.3.15-3.10"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056540" comment="liboil less than 0.3.15-3.10"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056558" comment="libpurple-lang less than 2.6.3-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056559" comment="libpurple less than 2.6.3-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056541" comment="libtheora0-32bit less than 1.0.beta2-4.28"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056543" comment="libtheora0 less than 1.0.beta2-4.28"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056562" comment="pidgin-otr less than 3.2.0-1.36.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056561" comment="pidgin less than 2.6.3-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093026" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3026</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3026" source="CVE"/>
	<description>
	protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions.
	</description>
 </metadata>
<!-- 036b34b556d9338c53561c16d2f5a3ce -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056524" comment="cdparanoia-32bit less than IIIalpha9.8-691.22"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056526" comment="cdparanoia less than IIIalpha9.8-691.22"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056527" comment="desktop-file-utils less than 0.15-1.29"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056528" comment="fam-32bit less than 2.7.0-130.21"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056530" comment="fam less than 2.7.0-130.21"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056554" comment="finch less than 2.6.3-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056531" comment="gnome-vfs2-32bit less than 2.24.0-7.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056533" comment="gnome-vfs2 less than 2.24.0-7.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056555" comment="gstreamer-0_10-32bit less than 0.10.21-3.20"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056534" comment="gstreamer-0_10 less than 0.10.21-3.20"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056535" comment="libogg0-32bit less than 1.1.3-87.12"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056537" comment="libogg0 less than 1.1.3-87.12"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056538" comment="liboil-32bit less than 0.3.15-3.10"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056540" comment="liboil less than 0.3.15-3.10"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056558" comment="libpurple-lang less than 2.6.3-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056559" comment="libpurple less than 2.6.3-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056541" comment="libtheora0-32bit less than 1.0.beta2-4.28"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056543" comment="libtheora0 less than 1.0.beta2-4.28"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056562" comment="pidgin-otr less than 3.2.0-1.36.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056561" comment="pidgin less than 2.6.3-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093051" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3051</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3051" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3051" source="CVE"/>
	<description>
	Multiple format string vulnerabilities in lib/silcclient/client_entry.c in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.10, and SILC Client before 1.1.8, allow remote attackers to execute arbitrary code via format string specifiers in a nickname field, related to the (1) silc_client_add_client, (2) silc_client_update_client, and (3) silc_client_nickname_format functions.
	</description>
 </metadata>
<!-- 8a79c9ab49ac9cd9f5e479fbeeb03404 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054843" comment="silc-toolkit less than 1.1.7-7.23.2"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093069" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3069</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3069" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3069" source="CVE"/>
	<description>
	Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 37796416bd210b06cf2ab2fa7d6b1bd9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055061" comment="mozilla-xulrunner190-32bit less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055095" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055063" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055098" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055065" comment="mozilla-xulrunner190-translations less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055068" comment="mozilla-xulrunner190 less than 1.9.0.14-1.1.1"/>
		</criteria>
	</criteria>
	<!-- dbecc804be7d87cf75529f49774665cb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055070" comment="MozillaFirefox-branding-SLED less than 3.5-1.1.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055071" comment="MozillaFirefox-translations less than 3.5.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055072" comment="MozillaFirefox less than 3.5.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055073" comment="libfreebl3-32bit less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055075" comment="libfreebl3 less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055076" comment="mozilla-nspr-32bit less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055078" comment="mozilla-nspr less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055079" comment="mozilla-nss-32bit less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055080" comment="mozilla-nss-tools less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055082" comment="mozilla-nss less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055083" comment="mozilla-xulrunner191-32bit less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055104" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055084" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055106" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055085" comment="mozilla-xulrunner191-translations less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055087" comment="mozilla-xulrunner191 less than 1.9.1.3-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093070" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3070</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3070" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3070" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 37796416bd210b06cf2ab2fa7d6b1bd9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055061" comment="mozilla-xulrunner190-32bit less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055095" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055063" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055098" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055065" comment="mozilla-xulrunner190-translations less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055068" comment="mozilla-xulrunner190 less than 1.9.0.14-1.1.1"/>
		</criteria>
	</criteria>
	<!-- dbecc804be7d87cf75529f49774665cb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055070" comment="MozillaFirefox-branding-SLED less than 3.5-1.1.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055071" comment="MozillaFirefox-translations less than 3.5.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055072" comment="MozillaFirefox less than 3.5.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055073" comment="libfreebl3-32bit less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055075" comment="libfreebl3 less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055076" comment="mozilla-nspr-32bit less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055078" comment="mozilla-nspr less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055079" comment="mozilla-nss-32bit less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055080" comment="mozilla-nss-tools less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055082" comment="mozilla-nss less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055083" comment="mozilla-xulrunner191-32bit less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055104" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055084" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055106" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055085" comment="mozilla-xulrunner191-translations less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055087" comment="mozilla-xulrunner191 less than 1.9.1.3-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093071" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3071</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3071" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3071" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.2, allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 37796416bd210b06cf2ab2fa7d6b1bd9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055061" comment="mozilla-xulrunner190-32bit less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055095" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055063" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055098" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055065" comment="mozilla-xulrunner190-translations less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055068" comment="mozilla-xulrunner190 less than 1.9.0.14-1.1.1"/>
		</criteria>
	</criteria>
	<!-- dbecc804be7d87cf75529f49774665cb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055070" comment="MozillaFirefox-branding-SLED less than 3.5-1.1.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055071" comment="MozillaFirefox-translations less than 3.5.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055072" comment="MozillaFirefox less than 3.5.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055073" comment="libfreebl3-32bit less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055075" comment="libfreebl3 less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055076" comment="mozilla-nspr-32bit less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055078" comment="mozilla-nspr less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055079" comment="mozilla-nss-32bit less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055080" comment="mozilla-nss-tools less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055082" comment="mozilla-nss less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055083" comment="mozilla-xulrunner191-32bit less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055104" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055084" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055106" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055085" comment="mozilla-xulrunner191-translations less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055087" comment="mozilla-xulrunner191 less than 1.9.1.3-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093072" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3072</title>
	<affected family="unix">
		<platform>SLE 11 DESKTOP Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3072" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3072" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14 and 3.5.x before 3.5.3, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the BinHex decoder in netwerk/streamconv/converters/nsBinHexDecoder.cpp, and unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 37796416bd210b06cf2ab2fa7d6b1bd9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055061" comment="mozilla-xulrunner190-32bit less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055095" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055063" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055098" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055065" comment="mozilla-xulrunner190-translations less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055068" comment="mozilla-xulrunner190 less than 1.9.0.14-1.1.1"/>
		</criteria>
	</criteria>
	<!-- dbecc804be7d87cf75529f49774665cb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055070" comment="MozillaFirefox-branding-SLED less than 3.5-1.1.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055071" comment="MozillaFirefox-translations less than 3.5.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055072" comment="MozillaFirefox less than 3.5.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055073" comment="libfreebl3-32bit less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055075" comment="libfreebl3 less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055076" comment="mozilla-nspr-32bit less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055078" comment="mozilla-nspr less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055079" comment="mozilla-nss-32bit less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055080" comment="mozilla-nss-tools less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055082" comment="mozilla-nss less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055083" comment="mozilla-xulrunner191-32bit less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055104" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055084" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055106" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055085" comment="mozilla-xulrunner191-translations less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055087" comment="mozilla-xulrunner191 less than 1.9.1.3-1.1.1"/>
		</criteria>
	</criteria>
	<!-- f2377272fe27726ada5a22ead971d6aa -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059215" comment="MozillaThunderbird-translations less than 2.0.0.24-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059216" comment="MozillaThunderbird less than 2.0.0.24-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093073" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3073</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3073" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3073" source="CVE"/>
	<description>
	Unspecified vulnerability in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 37796416bd210b06cf2ab2fa7d6b1bd9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055061" comment="mozilla-xulrunner190-32bit less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055095" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055063" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055098" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055065" comment="mozilla-xulrunner190-translations less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055068" comment="mozilla-xulrunner190 less than 1.9.0.14-1.1.1"/>
		</criteria>
	</criteria>
	<!-- dbecc804be7d87cf75529f49774665cb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055070" comment="MozillaFirefox-branding-SLED less than 3.5-1.1.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055071" comment="MozillaFirefox-translations less than 3.5.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055072" comment="MozillaFirefox less than 3.5.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055073" comment="libfreebl3-32bit less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055075" comment="libfreebl3 less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055076" comment="mozilla-nspr-32bit less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055078" comment="mozilla-nspr less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055079" comment="mozilla-nss-32bit less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055080" comment="mozilla-nss-tools less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055082" comment="mozilla-nss less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055083" comment="mozilla-xulrunner191-32bit less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055104" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055084" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055106" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055085" comment="mozilla-xulrunner191-translations less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055087" comment="mozilla-xulrunner191 less than 1.9.1.3-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093075" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3075</title>
	<affected family="unix">
		<platform>SLE 11 DESKTOP Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3075" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3075" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox before 3.0.14 and 3.5.x before 3.5.2, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to use of mutable strings in the js_StringReplaceHelper function in js/src/jsstr.cpp, and unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 37796416bd210b06cf2ab2fa7d6b1bd9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055061" comment="mozilla-xulrunner190-32bit less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055095" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055063" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055098" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055065" comment="mozilla-xulrunner190-translations less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055068" comment="mozilla-xulrunner190 less than 1.9.0.14-1.1.1"/>
		</criteria>
	</criteria>
	<!-- dbecc804be7d87cf75529f49774665cb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055070" comment="MozillaFirefox-branding-SLED less than 3.5-1.1.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055071" comment="MozillaFirefox-translations less than 3.5.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055072" comment="MozillaFirefox less than 3.5.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055073" comment="libfreebl3-32bit less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055075" comment="libfreebl3 less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055076" comment="mozilla-nspr-32bit less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055078" comment="mozilla-nspr less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055079" comment="mozilla-nss-32bit less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055080" comment="mozilla-nss-tools less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055082" comment="mozilla-nss less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055083" comment="mozilla-xulrunner191-32bit less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055104" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055084" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055106" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055085" comment="mozilla-xulrunner191-translations less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055087" comment="mozilla-xulrunner191 less than 1.9.1.3-1.1.1"/>
		</criteria>
	</criteria>
	<!-- f2377272fe27726ada5a22ead971d6aa -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059215" comment="MozillaThunderbird-translations less than 2.0.0.24-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059216" comment="MozillaThunderbird less than 2.0.0.24-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093076" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3076</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3076" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3076" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.14 does not properly implement certain dialogs associated with the (1) pkcs11.addmodule and (2) pkcs11.deletemodule operations, which makes it easier for remote attackers to trick a user into installing or removing an arbitrary PKCS11 module.
	</description>
 </metadata>
<!-- 37796416bd210b06cf2ab2fa7d6b1bd9 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009055061" comment="mozilla-xulrunner190-32bit less than 1.9.0.14-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055095" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.14-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055063" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.14-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055098" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.14-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055065" comment="mozilla-xulrunner190-translations less than 1.9.0.14-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055068" comment="mozilla-xulrunner190 less than 1.9.0.14-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093077" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3077</title>
	<affected family="unix">
		<platform>SLE 11 DESKTOP Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3077" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3077" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, does not properly manage pointers for the columns (aka TreeColumns) of a XUL tree element, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to a "dangling pointer vulnerability."
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 37796416bd210b06cf2ab2fa7d6b1bd9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055061" comment="mozilla-xulrunner190-32bit less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055095" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055063" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055098" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055065" comment="mozilla-xulrunner190-translations less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055068" comment="mozilla-xulrunner190 less than 1.9.0.14-1.1.1"/>
		</criteria>
	</criteria>
	<!-- dbecc804be7d87cf75529f49774665cb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055070" comment="MozillaFirefox-branding-SLED less than 3.5-1.1.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055071" comment="MozillaFirefox-translations less than 3.5.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055072" comment="MozillaFirefox less than 3.5.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055073" comment="libfreebl3-32bit less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055075" comment="libfreebl3 less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055076" comment="mozilla-nspr-32bit less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055078" comment="mozilla-nspr less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055079" comment="mozilla-nss-32bit less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055080" comment="mozilla-nss-tools less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055082" comment="mozilla-nss less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055083" comment="mozilla-xulrunner191-32bit less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055104" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055084" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055106" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055085" comment="mozilla-xulrunner191-translations less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055087" comment="mozilla-xulrunner191 less than 1.9.1.3-1.1.1"/>
		</criteria>
	</criteria>
	<!-- f2377272fe27726ada5a22ead971d6aa -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059215" comment="MozillaThunderbird-translations less than 2.0.0.24-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059216" comment="MozillaThunderbird less than 2.0.0.24-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093078" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3078</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3078" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3078" source="CVE"/>
	<description>
	Visual truncation vulnerability in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, allows remote attackers to trigger a vertical scroll and spoof URLs via unspecified Unicode characters with a tall line-height property.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 37796416bd210b06cf2ab2fa7d6b1bd9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055061" comment="mozilla-xulrunner190-32bit less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055095" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055063" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055098" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055065" comment="mozilla-xulrunner190-translations less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055068" comment="mozilla-xulrunner190 less than 1.9.0.14-1.1.1"/>
		</criteria>
	</criteria>
	<!-- dbecc804be7d87cf75529f49774665cb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055070" comment="MozillaFirefox-branding-SLED less than 3.5-1.1.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055071" comment="MozillaFirefox-translations less than 3.5.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055072" comment="MozillaFirefox less than 3.5.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055073" comment="libfreebl3-32bit less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055075" comment="libfreebl3 less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055076" comment="mozilla-nspr-32bit less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055078" comment="mozilla-nspr less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055079" comment="mozilla-nss-32bit less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055080" comment="mozilla-nss-tools less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055082" comment="mozilla-nss less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055083" comment="mozilla-xulrunner191-32bit less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055104" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055084" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055106" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055085" comment="mozilla-xulrunner191-translations less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055087" comment="mozilla-xulrunner191 less than 1.9.1.3-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093079" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3079</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3079" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3079" source="CVE"/>
	<description>
	Unspecified vulnerability in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, allows remote attackers to execute arbitrary JavaScript with chrome privileges via vectors involving an object, the FeedWriter, and the BrowserFeedWriter.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 37796416bd210b06cf2ab2fa7d6b1bd9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055061" comment="mozilla-xulrunner190-32bit less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055095" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055063" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055098" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055065" comment="mozilla-xulrunner190-translations less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055068" comment="mozilla-xulrunner190 less than 1.9.0.14-1.1.1"/>
		</criteria>
	</criteria>
	<!-- dbecc804be7d87cf75529f49774665cb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055070" comment="MozillaFirefox-branding-SLED less than 3.5-1.1.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055071" comment="MozillaFirefox-translations less than 3.5.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055072" comment="MozillaFirefox less than 3.5.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055073" comment="libfreebl3-32bit less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055075" comment="libfreebl3 less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055076" comment="mozilla-nspr-32bit less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055078" comment="mozilla-nspr less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055079" comment="mozilla-nss-32bit less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055080" comment="mozilla-nss-tools less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055082" comment="mozilla-nss less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055083" comment="mozilla-xulrunner191-32bit less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055104" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055084" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055106" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055085" comment="mozilla-xulrunner191-translations less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055087" comment="mozilla-xulrunner191 less than 1.9.1.3-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093080" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3080</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3080" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3080" source="CVE"/>
	<description>
	Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows local users to cause a denial of service or possibly gain privileges via a negative event index in an IOCTL request.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- e7c5f7ef7eeb152d788f9406d2374894 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057219" comment="kernel-pae-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057220" comment="kernel-pae-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057221" comment="kernel-pae less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057232" comment="kernel-xen-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057233" comment="kernel-xen-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057234" comment="kernel-xen less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e87c441668f87fa162f810ea0e06c3ba -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057232" comment="kernel-xen-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057233" comment="kernel-xen-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057234" comment="kernel-xen less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093083" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3083</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3083" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3083" source="CVE"/>
	<description>
	The msn_slp_sip_recv function in libpurple/protocols/msn/slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an SLP invite message that lacks certain required fields, as demonstrated by a malformed message from a KMess client.
	</description>
 </metadata>
<!-- 036b34b556d9338c53561c16d2f5a3ce -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056524" comment="cdparanoia-32bit less than IIIalpha9.8-691.22"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056526" comment="cdparanoia less than IIIalpha9.8-691.22"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056527" comment="desktop-file-utils less than 0.15-1.29"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056528" comment="fam-32bit less than 2.7.0-130.21"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056530" comment="fam less than 2.7.0-130.21"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056554" comment="finch less than 2.6.3-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056531" comment="gnome-vfs2-32bit less than 2.24.0-7.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056533" comment="gnome-vfs2 less than 2.24.0-7.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056555" comment="gstreamer-0_10-32bit less than 0.10.21-3.20"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056534" comment="gstreamer-0_10 less than 0.10.21-3.20"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056535" comment="libogg0-32bit less than 1.1.3-87.12"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056537" comment="libogg0 less than 1.1.3-87.12"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056538" comment="liboil-32bit less than 0.3.15-3.10"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056540" comment="liboil less than 0.3.15-3.10"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056558" comment="libpurple-lang less than 2.6.3-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056559" comment="libpurple less than 2.6.3-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056541" comment="libtheora0-32bit less than 1.0.beta2-4.28"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056543" comment="libtheora0 less than 1.0.beta2-4.28"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056562" comment="pidgin-otr less than 3.2.0-1.36.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056561" comment="pidgin less than 2.6.3-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093084" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3084</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3084" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3084" source="CVE"/>
	<description>
	The msn_slp_process_msg function in libpurple/protocols/msn/slpcall.c in the MSN protocol plugin in libpurple 2.6.0 and 2.6.1, as used in Pidgin before 2.6.2, allows remote attackers to cause a denial of service (application crash) via a handwritten (aka Ink) message, related to an uninitialized variable and the incorrect "UTF16-LE" charset name.
	</description>
 </metadata>
<!-- 036b34b556d9338c53561c16d2f5a3ce -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056524" comment="cdparanoia-32bit less than IIIalpha9.8-691.22"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056526" comment="cdparanoia less than IIIalpha9.8-691.22"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056527" comment="desktop-file-utils less than 0.15-1.29"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056528" comment="fam-32bit less than 2.7.0-130.21"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056530" comment="fam less than 2.7.0-130.21"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056554" comment="finch less than 2.6.3-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056531" comment="gnome-vfs2-32bit less than 2.24.0-7.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056533" comment="gnome-vfs2 less than 2.24.0-7.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056555" comment="gstreamer-0_10-32bit less than 0.10.21-3.20"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056534" comment="gstreamer-0_10 less than 0.10.21-3.20"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056535" comment="libogg0-32bit less than 1.1.3-87.12"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056537" comment="libogg0 less than 1.1.3-87.12"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056538" comment="liboil-32bit less than 0.3.15-3.10"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056540" comment="liboil less than 0.3.15-3.10"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056558" comment="libpurple-lang less than 2.6.3-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056559" comment="libpurple less than 2.6.3-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056541" comment="libtheora0-32bit less than 1.0.beta2-4.28"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056543" comment="libtheora0 less than 1.0.beta2-4.28"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056562" comment="pidgin-otr less than 3.2.0-1.36.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056561" comment="pidgin less than 2.6.3-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093085" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3085</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3085" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3085" source="CVE"/>
	<description>
	The XMPP protocol plugin in libpurple in Pidgin before 2.6.2 does not properly handle an error IQ stanza during an attempted fetch of a custom smiley, which allows remote attackers to cause a denial of service (application crash) via XHTML-IM content with cid: images.
	</description>
 </metadata>
<!-- 036b34b556d9338c53561c16d2f5a3ce -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056524" comment="cdparanoia-32bit less than IIIalpha9.8-691.22"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056526" comment="cdparanoia less than IIIalpha9.8-691.22"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056527" comment="desktop-file-utils less than 0.15-1.29"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056528" comment="fam-32bit less than 2.7.0-130.21"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056530" comment="fam less than 2.7.0-130.21"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056554" comment="finch less than 2.6.3-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056531" comment="gnome-vfs2-32bit less than 2.24.0-7.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056533" comment="gnome-vfs2 less than 2.24.0-7.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056555" comment="gstreamer-0_10-32bit less than 0.10.21-3.20"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056534" comment="gstreamer-0_10 less than 0.10.21-3.20"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056535" comment="libogg0-32bit less than 1.1.3-87.12"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056537" comment="libogg0 less than 1.1.3-87.12"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056538" comment="liboil-32bit less than 0.3.15-3.10"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056540" comment="liboil less than 0.3.15-3.10"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056558" comment="libpurple-lang less than 2.6.3-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056559" comment="libpurple less than 2.6.3-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056541" comment="libtheora0-32bit less than 1.0.beta2-4.28"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056543" comment="libtheora0 less than 1.0.beta2-4.28"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056562" comment="pidgin-otr less than 3.2.0-1.36.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056561" comment="pidgin less than 2.6.3-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093229" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3229</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3229" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3229" source="CVE"/>
	<description>
	The core server component in PostgreSQL 8.4 before 8.4.1, 8.3 before 8.3.8, and 8.2 before 8.2.14 allows remote authenticated users to cause a denial of service (backend shutdown) by "re-LOAD-ing" libraries from a certain plugins directory.
	</description>
 </metadata>
<!-- cd52231925ea5e4eb6c7b6a30a4b49ca -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009055022" comment="postgresql-libs-32bit less than 8.3.8-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055024" comment="postgresql-libs less than 8.3.8-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055026" comment="postgresql less than 8.3.8-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093230" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3230</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3230" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3230" source="CVE"/>
	<description>
	The core server component in PostgreSQL 8.4 before 8.4.1, 8.3 before 8.3.8, 8.2 before 8.2.14, 8.1 before 8.1.18, 8.0 before 8.0.22, and 7.4 before 7.4.26 does not use the appropriate privileges for the (1) RESET ROLE and (2) RESET SESSION AUTHORIZATION operations, which allows remote authenticated users to gain privileges.  NOTE: this is due to an incomplete fix for CVE-2007-6600.
	</description>
 </metadata>
<!-- cd52231925ea5e4eb6c7b6a30a4b49ca -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009055022" comment="postgresql-libs-32bit less than 8.3.8-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055024" comment="postgresql-libs less than 8.3.8-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055026" comment="postgresql less than 8.3.8-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093231" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3231</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3231" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3231" source="CVE"/>
	<description>
	The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.
	</description>
 </metadata>
<!-- cd52231925ea5e4eb6c7b6a30a4b49ca -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009055022" comment="postgresql-libs-32bit less than 8.3.8-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055024" comment="postgresql-libs less than 8.3.8-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055026" comment="postgresql less than 8.3.8-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093245" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3245</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3245" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3245" source="CVE"/>
	<description>
	OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact and context-dependent attack vectors.
	</description>
 </metadata>
<!-- fba66235e940d7d2f4064d7e1e803b60 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059248" comment="libopenssl0_9_8-32bit less than 0.9.8h-30.22.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059250" comment="libopenssl0_9_8 less than 0.9.8h-30.22.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059252" comment="openssl less than 0.9.8h-30.22.21.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093274" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3274</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3274" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3274" source="CVE"/>
	<description>
	Mozilla Firefox 3.6a1, 3.5.3, 3.5.2, and earlier 3.5.x versions, and 3.0.14 and earlier 2.x and 3.x versions, on Linux uses a predictable /tmp pathname for files selected from the Downloads window, which allows local users to replace an arbitrary downloaded file by placing a file in a /tmp location before the download occurs, related to the Download Manager component. NOTE: some of these details are obtained from third party information.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04c6e38838a85fc92531b3e56904b052 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055940" comment="mozilla-xulrunner190-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055953" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055941" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055955" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055942" comment="mozilla-xulrunner190-translations less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055944" comment="mozilla-xulrunner190 less than 1.9.0.15-0.1.2"/>
		</criteria>
	</criteria>
	<!-- 49179a9289fbe778bc2320690c17d088 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055945" comment="MozillaFirefox-translations less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055946" comment="MozillaFirefox less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055947" comment="mozilla-xulrunner191-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055966" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055948" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055968" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055949" comment="mozilla-xulrunner191-translations less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055951" comment="mozilla-xulrunner191 less than 1.9.1.4-2.1.3"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093286" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3286</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3286" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3286" source="CVE"/>
	<description>
	NFSv4 in the Linux kernel 2.6.18, and possibly other versions, does not properly clean up an inode when an O_EXCL create fails, which causes files to be created with insecure settings such as setuid bits, and possibly allows local users to gain privileges, related to the execution of the do_open_permission function even when a create fails.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 114b9cf953db7d4a1a91082495d33414 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056549" comment="kernel-default-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056511" comment="kernel-xen-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056550" comment="kernel-xen-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056512" comment="kernel-xen less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- a3c4f0428e25dca1993e5018e76d6758 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056549" comment="kernel-default-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056519" comment="kernel-pae-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056552" comment="kernel-pae-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056520" comment="kernel-pae less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056511" comment="kernel-xen-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056550" comment="kernel-xen-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056512" comment="kernel-xen less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093289" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3289</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3289" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3289" source="CVE"/>
	<description>
	The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), which allows user-assisted local users to modify files of other users, as demonstrated by using Nautilus to modify the permissions of the user home directory.
	</description>
 </metadata>
<!-- 9d502b72aea0be06bdfccffe06a4262e -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059885" comment="glib2-devel less than 2.18.2-7.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059847" comment="glib2-lang less than 2.18.2-7.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059848" comment="glib2 less than 2.18.2-7.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059849" comment="libgio-2_0-0-32bit less than 2.18.2-7.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059851" comment="libgio-2_0-0 less than 2.18.2-7.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059886" comment="libgio-fam less than 2.18.2-7.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059852" comment="libglib-2_0-0-32bit less than 2.18.2-7.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059854" comment="libglib-2_0-0 less than 2.18.2-7.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059855" comment="libgmodule-2_0-0-32bit less than 2.18.2-7.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059857" comment="libgmodule-2_0-0 less than 2.18.2-7.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059858" comment="libgobject-2_0-0-32bit less than 2.18.2-7.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059860" comment="libgobject-2_0-0 less than 2.18.2-7.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059861" comment="libgthread-2_0-0-32bit less than 2.18.2-7.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059863" comment="libgthread-2_0-0 less than 2.18.2-7.9.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093295" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3295</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3295" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3295" source="CVE"/>
	<description>
	The prep_reprocess_req function in kdc/do_tgs_req.c in the cross-realm referral implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a ticket request.
	</description>
 </metadata>
<!-- f95c0cbef4a252636c67dd8d77f705f6 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009057338" comment="krb5-32bit less than 1.6.3-133.26.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057341" comment="krb5-client less than 1.6.3-133.26.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057344" comment="krb5 less than 1.6.3-133.26.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093297" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3297</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3297" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3297" source="CVE"/>
	<description>
	** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2010-0787, CVE-2010-0788, CVE-2010-0789.  Reason: this candidate was intended for one issue in Samba, but it was used for multiple distinct issues, including one in FUSE and one in ncpfs.  Notes: All CVE users should consult CVE-2010-0787 (Samba), CVE-2010-0788 (ncpfs), and CVE-2010-0789 (FUSE) to determine which ID is appropriate.  All references and descriptions in this candidate have been removed to prevent accidental usage.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- b56bbe075a71b8de518011c0b0f5e42e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060019" comment="fuse less than 2.7.2-61.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060020" comment="libfuse2 less than 2.7.2-61.18.1"/>
		</criteria>
	</criteria>
	<!-- f1ed5706f5031275bd4d15784f3692ad -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057690" comment="fuse less than 2.7.2-61.15.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057691" comment="libfuse2 less than 2.7.2-61.15.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093301" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3301</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3301" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3301" source="CVE"/>
	<description>
	Integer underflow in filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted sprmTDefTable table property modifier in a Word document.
	</description>
 </metadata>
<!-- b3f5b1e481a1ae74918748c80997e6c7 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009058823" comment="OpenOffice_org-LanguageTool-de less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058824" comment="OpenOffice_org-LanguageTool-en less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058825" comment="OpenOffice_org-LanguageTool-es less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058826" comment="OpenOffice_org-LanguageTool-fr less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058827" comment="OpenOffice_org-LanguageTool-it less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058828" comment="OpenOffice_org-LanguageTool-nl less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058829" comment="OpenOffice_org-LanguageTool-pl less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058830" comment="OpenOffice_org-LanguageTool-sv less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058831" comment="OpenOffice_org-LanguageTool less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058832" comment="OpenOffice_org-base-drivers-postgresql less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058833" comment="OpenOffice_org-base-extensions less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058741" comment="OpenOffice_org-base less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058834" comment="OpenOffice_org-calc-extensions less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058744" comment="OpenOffice_org-calc less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058746" comment="OpenOffice_org-components less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058835" comment="OpenOffice_org-draw-extensions less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058747" comment="OpenOffice_org-draw less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058749" comment="OpenOffice_org-filters-optional less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058750" comment="OpenOffice_org-filters less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058751" comment="OpenOffice_org-gnome less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058752" comment="OpenOffice_org-help-ar less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058753" comment="OpenOffice_org-help-cs less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058754" comment="OpenOffice_org-help-da less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058755" comment="OpenOffice_org-help-de less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058756" comment="OpenOffice_org-help-en-GB less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058757" comment="OpenOffice_org-help-en-US-devel less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058758" comment="OpenOffice_org-help-en-US less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058759" comment="OpenOffice_org-help-es less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058760" comment="OpenOffice_org-help-fr less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058836" comment="OpenOffice_org-help-gu-IN less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058837" comment="OpenOffice_org-help-hi-IN less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058761" comment="OpenOffice_org-help-hu less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058762" comment="OpenOffice_org-help-it less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058763" comment="OpenOffice_org-help-ja less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058838" comment="OpenOffice_org-help-ko less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058764" comment="OpenOffice_org-help-nl less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058765" comment="OpenOffice_org-help-pl less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058766" comment="OpenOffice_org-help-pt-BR less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058767" comment="OpenOffice_org-help-pt less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058768" comment="OpenOffice_org-help-ru less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058769" comment="OpenOffice_org-help-sv less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058770" comment="OpenOffice_org-help-zh-CN less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058771" comment="OpenOffice_org-help-zh-TW less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058772" comment="OpenOffice_org-icon-themes less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058839" comment="OpenOffice_org-impress-extensions less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058774" comment="OpenOffice_org-impress less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058775" comment="OpenOffice_org-kde less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058776" comment="OpenOffice_org-l10n-af less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058777" comment="OpenOffice_org-l10n-ar less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058778" comment="OpenOffice_org-l10n-ca less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058779" comment="OpenOffice_org-l10n-cs less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058780" comment="OpenOffice_org-l10n-da less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058781" comment="OpenOffice_org-l10n-de less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058782" comment="OpenOffice_org-l10n-el less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058783" comment="OpenOffice_org-l10n-en-GB less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058784" comment="OpenOffice_org-l10n-es less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058786" comment="OpenOffice_org-l10n-extras less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058787" comment="OpenOffice_org-l10n-fi less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058788" comment="OpenOffice_org-l10n-fr less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058840" comment="OpenOffice_org-l10n-gu-IN less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058841" comment="OpenOffice_org-l10n-hi-IN less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058789" comment="OpenOffice_org-l10n-hu less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058790" comment="OpenOffice_org-l10n-it less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058791" comment="OpenOffice_org-l10n-ja less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058842" comment="OpenOffice_org-l10n-ko less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058792" comment="OpenOffice_org-l10n-nb less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058793" comment="OpenOffice_org-l10n-nl less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058794" comment="OpenOffice_org-l10n-nn less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058795" comment="OpenOffice_org-l10n-pl less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058796" comment="OpenOffice_org-l10n-pt-BR less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058797" comment="OpenOffice_org-l10n-pt less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058798" comment="OpenOffice_org-l10n-ru less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058799" comment="OpenOffice_org-l10n-sk less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058800" comment="OpenOffice_org-l10n-sv less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058801" comment="OpenOffice_org-l10n-xh less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058802" comment="OpenOffice_org-l10n-zh-CN less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058803" comment="OpenOffice_org-l10n-zh-TW less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058804" comment="OpenOffice_org-l10n-zu less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058806" comment="OpenOffice_org-libs-core less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058808" comment="OpenOffice_org-libs-extern less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058810" comment="OpenOffice_org-libs-gui less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058811" comment="OpenOffice_org-mailmerge less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058812" comment="OpenOffice_org-math less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058813" comment="OpenOffice_org-mono less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058814" comment="OpenOffice_org-officebean less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058815" comment="OpenOffice_org-openclipart less than 3-1.25.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058816" comment="OpenOffice_org-pyuno less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058819" comment="OpenOffice_org-ure less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058843" comment="OpenOffice_org-writer-extensions less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058821" comment="OpenOffice_org-writer less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058822" comment="OpenOffice_org less than 3.2.0.7-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093302" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3302</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3302" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3302" source="CVE"/>
	<description>
	filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted sprmTSetBrc table property modifier in a Word document, related to a "boundary error flaw."
	</description>
 </metadata>
<!-- b3f5b1e481a1ae74918748c80997e6c7 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009058823" comment="OpenOffice_org-LanguageTool-de less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058824" comment="OpenOffice_org-LanguageTool-en less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058825" comment="OpenOffice_org-LanguageTool-es less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058826" comment="OpenOffice_org-LanguageTool-fr less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058827" comment="OpenOffice_org-LanguageTool-it less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058828" comment="OpenOffice_org-LanguageTool-nl less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058829" comment="OpenOffice_org-LanguageTool-pl less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058830" comment="OpenOffice_org-LanguageTool-sv less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058831" comment="OpenOffice_org-LanguageTool less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058832" comment="OpenOffice_org-base-drivers-postgresql less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058833" comment="OpenOffice_org-base-extensions less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058741" comment="OpenOffice_org-base less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058834" comment="OpenOffice_org-calc-extensions less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058744" comment="OpenOffice_org-calc less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058746" comment="OpenOffice_org-components less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058835" comment="OpenOffice_org-draw-extensions less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058747" comment="OpenOffice_org-draw less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058749" comment="OpenOffice_org-filters-optional less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058750" comment="OpenOffice_org-filters less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058751" comment="OpenOffice_org-gnome less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058752" comment="OpenOffice_org-help-ar less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058753" comment="OpenOffice_org-help-cs less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058754" comment="OpenOffice_org-help-da less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058755" comment="OpenOffice_org-help-de less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058756" comment="OpenOffice_org-help-en-GB less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058757" comment="OpenOffice_org-help-en-US-devel less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058758" comment="OpenOffice_org-help-en-US less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058759" comment="OpenOffice_org-help-es less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058760" comment="OpenOffice_org-help-fr less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058836" comment="OpenOffice_org-help-gu-IN less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058837" comment="OpenOffice_org-help-hi-IN less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058761" comment="OpenOffice_org-help-hu less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058762" comment="OpenOffice_org-help-it less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058763" comment="OpenOffice_org-help-ja less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058838" comment="OpenOffice_org-help-ko less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058764" comment="OpenOffice_org-help-nl less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058765" comment="OpenOffice_org-help-pl less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058766" comment="OpenOffice_org-help-pt-BR less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058767" comment="OpenOffice_org-help-pt less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058768" comment="OpenOffice_org-help-ru less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058769" comment="OpenOffice_org-help-sv less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058770" comment="OpenOffice_org-help-zh-CN less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058771" comment="OpenOffice_org-help-zh-TW less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058772" comment="OpenOffice_org-icon-themes less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058839" comment="OpenOffice_org-impress-extensions less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058774" comment="OpenOffice_org-impress less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058775" comment="OpenOffice_org-kde less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058776" comment="OpenOffice_org-l10n-af less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058777" comment="OpenOffice_org-l10n-ar less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058778" comment="OpenOffice_org-l10n-ca less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058779" comment="OpenOffice_org-l10n-cs less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058780" comment="OpenOffice_org-l10n-da less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058781" comment="OpenOffice_org-l10n-de less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058782" comment="OpenOffice_org-l10n-el less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058783" comment="OpenOffice_org-l10n-en-GB less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058784" comment="OpenOffice_org-l10n-es less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058786" comment="OpenOffice_org-l10n-extras less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058787" comment="OpenOffice_org-l10n-fi less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058788" comment="OpenOffice_org-l10n-fr less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058840" comment="OpenOffice_org-l10n-gu-IN less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058841" comment="OpenOffice_org-l10n-hi-IN less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058789" comment="OpenOffice_org-l10n-hu less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058790" comment="OpenOffice_org-l10n-it less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058791" comment="OpenOffice_org-l10n-ja less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058842" comment="OpenOffice_org-l10n-ko less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058792" comment="OpenOffice_org-l10n-nb less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058793" comment="OpenOffice_org-l10n-nl less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058794" comment="OpenOffice_org-l10n-nn less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058795" comment="OpenOffice_org-l10n-pl less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058796" comment="OpenOffice_org-l10n-pt-BR less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058797" comment="OpenOffice_org-l10n-pt less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058798" comment="OpenOffice_org-l10n-ru less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058799" comment="OpenOffice_org-l10n-sk less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058800" comment="OpenOffice_org-l10n-sv less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058801" comment="OpenOffice_org-l10n-xh less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058802" comment="OpenOffice_org-l10n-zh-CN less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058803" comment="OpenOffice_org-l10n-zh-TW less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058804" comment="OpenOffice_org-l10n-zu less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058806" comment="OpenOffice_org-libs-core less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058808" comment="OpenOffice_org-libs-extern less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058810" comment="OpenOffice_org-libs-gui less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058811" comment="OpenOffice_org-mailmerge less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058812" comment="OpenOffice_org-math less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058813" comment="OpenOffice_org-mono less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058814" comment="OpenOffice_org-officebean less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058815" comment="OpenOffice_org-openclipart less than 3-1.25.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058816" comment="OpenOffice_org-pyuno less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058819" comment="OpenOffice_org-ure less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058843" comment="OpenOffice_org-writer-extensions less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058821" comment="OpenOffice_org-writer less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058822" comment="OpenOffice_org less than 3.2.0.7-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093370" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3370</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3370" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3370" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.15, and 3.5.x before 3.5.4, allows remote attackers to read form history by forging mouse and keyboard events that leverage the auto-fill feature to populate form fields, in an attacker-readable form, with history entries.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04c6e38838a85fc92531b3e56904b052 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055940" comment="mozilla-xulrunner190-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055953" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055941" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055955" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055942" comment="mozilla-xulrunner190-translations less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055944" comment="mozilla-xulrunner190 less than 1.9.0.15-0.1.2"/>
		</criteria>
	</criteria>
	<!-- 49179a9289fbe778bc2320690c17d088 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055945" comment="MozillaFirefox-translations less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055946" comment="MozillaFirefox less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055947" comment="mozilla-xulrunner191-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055966" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055948" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055968" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055949" comment="mozilla-xulrunner191-translations less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055951" comment="mozilla-xulrunner191 less than 1.9.1.4-2.1.3"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093371" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3371</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3371" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3371" source="CVE"/>
	<description>
	Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by creating JavaScript web-workers recursively.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04c6e38838a85fc92531b3e56904b052 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055940" comment="mozilla-xulrunner190-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055953" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055941" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055955" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055942" comment="mozilla-xulrunner190-translations less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055944" comment="mozilla-xulrunner190 less than 1.9.0.15-0.1.2"/>
		</criteria>
	</criteria>
	<!-- 49179a9289fbe778bc2320690c17d088 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055945" comment="MozillaFirefox-translations less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055946" comment="MozillaFirefox less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055947" comment="mozilla-xulrunner191-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055966" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055948" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055968" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055949" comment="mozilla-xulrunner191-translations less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055951" comment="mozilla-xulrunner191 less than 1.9.1.4-2.1.3"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093372" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3372</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3372" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3372" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via a crafted regular expression in a Proxy Auto-configuration (PAC) file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04c6e38838a85fc92531b3e56904b052 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055940" comment="mozilla-xulrunner190-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055953" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055941" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055955" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055942" comment="mozilla-xulrunner190-translations less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055944" comment="mozilla-xulrunner190 less than 1.9.0.15-0.1.2"/>
		</criteria>
	</criteria>
	<!-- 49179a9289fbe778bc2320690c17d088 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055945" comment="MozillaFirefox-translations less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055946" comment="MozillaFirefox less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055947" comment="mozilla-xulrunner191-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055966" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055948" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055968" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055949" comment="mozilla-xulrunner191-translations less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055951" comment="mozilla-xulrunner191 less than 1.9.1.4-2.1.3"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093373" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3373</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3373" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3373" source="CVE"/>
	<description>
	Heap-based buffer overflow in the GIF image parser in Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via unspecified vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04c6e38838a85fc92531b3e56904b052 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055940" comment="mozilla-xulrunner190-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055953" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055941" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055955" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055942" comment="mozilla-xulrunner190-translations less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055944" comment="mozilla-xulrunner190 less than 1.9.0.15-0.1.2"/>
		</criteria>
	</criteria>
	<!-- 49179a9289fbe778bc2320690c17d088 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055945" comment="MozillaFirefox-translations less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055946" comment="MozillaFirefox less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055947" comment="mozilla-xulrunner191-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055966" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055948" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055968" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055949" comment="mozilla-xulrunner191-translations less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055951" comment="mozilla-xulrunner191 less than 1.9.1.4-2.1.3"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093374" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3374</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3374" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3374" source="CVE"/>
	<description>
	The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04c6e38838a85fc92531b3e56904b052 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055940" comment="mozilla-xulrunner190-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055953" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055941" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055955" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055942" comment="mozilla-xulrunner190-translations less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055944" comment="mozilla-xulrunner190 less than 1.9.0.15-0.1.2"/>
		</criteria>
	</criteria>
	<!-- 49179a9289fbe778bc2320690c17d088 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055945" comment="MozillaFirefox-translations less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055946" comment="MozillaFirefox less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055947" comment="mozilla-xulrunner191-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055966" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055948" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055968" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055949" comment="mozilla-xulrunner191-translations less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055951" comment="mozilla-xulrunner191 less than 1.9.1.4-2.1.3"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093375" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3375</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3375" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3375" source="CVE"/>
	<description>
	content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allows user-assisted remote attackers to bypass the Same Origin Policy and read an arbitrary content selection via the document.getSelection function.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04c6e38838a85fc92531b3e56904b052 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055940" comment="mozilla-xulrunner190-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055953" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055941" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055955" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055942" comment="mozilla-xulrunner190-translations less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055944" comment="mozilla-xulrunner190 less than 1.9.0.15-0.1.2"/>
		</criteria>
	</criteria>
	<!-- 49179a9289fbe778bc2320690c17d088 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055945" comment="MozillaFirefox-translations less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055946" comment="MozillaFirefox less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055947" comment="mozilla-xulrunner191-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055966" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055948" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055968" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055949" comment="mozilla-xulrunner191-translations less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055951" comment="mozilla-xulrunner191 less than 1.9.1.4-2.1.3"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093376" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3376</title>
	<affected family="unix">
		<platform>SLE 11 DESKTOP Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3376" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3376" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, does not properly handle a right-to-left override (aka RLO or U+202E) Unicode character in a download filename, which allows remote attackers to spoof file extensions via a crafted filename, as demonstrated by displaying a non-executable extension for an executable file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04c6e38838a85fc92531b3e56904b052 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055940" comment="mozilla-xulrunner190-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055953" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055941" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055955" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055942" comment="mozilla-xulrunner190-translations less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055944" comment="mozilla-xulrunner190 less than 1.9.0.15-0.1.2"/>
		</criteria>
	</criteria>
	<!-- 49179a9289fbe778bc2320690c17d088 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055945" comment="MozillaFirefox-translations less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055946" comment="MozillaFirefox less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055947" comment="mozilla-xulrunner191-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055966" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055948" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055968" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055949" comment="mozilla-xulrunner191-translations less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055951" comment="mozilla-xulrunner191 less than 1.9.1.4-2.1.3"/>
		</criteria>
	</criteria>
	<!-- f2377272fe27726ada5a22ead971d6aa -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059215" comment="MozillaThunderbird-translations less than 2.0.0.24-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059216" comment="MozillaThunderbird less than 2.0.0.24-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093377" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3377</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3377" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3377" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in liboggz before cf5feeaab69b05e24, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
<!-- 49179a9289fbe778bc2320690c17d088 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009055945" comment="MozillaFirefox-translations less than 3.5.4-1.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055946" comment="MozillaFirefox less than 3.5.4-1.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055947" comment="mozilla-xulrunner191-32bit less than 1.9.1.4-2.1.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055966" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.4-2.1.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055948" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.4-2.1.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055968" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.4-2.1.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055949" comment="mozilla-xulrunner191-translations less than 1.9.1.4-2.1.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055951" comment="mozilla-xulrunner191 less than 1.9.1.4-2.1.3"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093378" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3378</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3378" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3378" source="CVE"/>
	<description>
	The oggplay_data_handle_theora_frame function in media/liboggplay/src/liboggplay/oggplay_data.c in liboggplay, as used in Mozilla Firefox 3.5.x before 3.5.4, attempts to reuse an earlier frame data structure upon encountering a decoding error for the first frame, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via a crafted .ogg video file.
	</description>
 </metadata>
<!-- 49179a9289fbe778bc2320690c17d088 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009055945" comment="MozillaFirefox-translations less than 3.5.4-1.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055946" comment="MozillaFirefox less than 3.5.4-1.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055947" comment="mozilla-xulrunner191-32bit less than 1.9.1.4-2.1.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055966" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.4-2.1.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055948" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.4-2.1.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055968" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.4-2.1.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055949" comment="mozilla-xulrunner191-translations less than 1.9.1.4-2.1.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055951" comment="mozilla-xulrunner191 less than 1.9.1.4-2.1.3"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093379" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3379</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3379" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3379" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in libvorbis, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.  NOTE: this might overlap CVE-2009-2663.
	</description>
 </metadata>
<!-- 49179a9289fbe778bc2320690c17d088 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009055945" comment="MozillaFirefox-translations less than 3.5.4-1.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055946" comment="MozillaFirefox less than 3.5.4-1.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055947" comment="mozilla-xulrunner191-32bit less than 1.9.1.4-2.1.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055966" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.4-2.1.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055948" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.4-2.1.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055968" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.4-2.1.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055949" comment="mozilla-xulrunner191-translations less than 1.9.1.4-2.1.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055951" comment="mozilla-xulrunner191 less than 1.9.1.4-2.1.3"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093380" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3380</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3380" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3380" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04c6e38838a85fc92531b3e56904b052 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055940" comment="mozilla-xulrunner190-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055953" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055941" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055955" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055942" comment="mozilla-xulrunner190-translations less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055944" comment="mozilla-xulrunner190 less than 1.9.0.15-0.1.2"/>
		</criteria>
	</criteria>
	<!-- 49179a9289fbe778bc2320690c17d088 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055945" comment="MozillaFirefox-translations less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055946" comment="MozillaFirefox less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055947" comment="mozilla-xulrunner191-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055966" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055948" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055968" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055949" comment="mozilla-xulrunner191-translations less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055951" comment="mozilla-xulrunner191 less than 1.9.1.4-2.1.3"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093381" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3381</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3381" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3381" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04c6e38838a85fc92531b3e56904b052 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055940" comment="mozilla-xulrunner190-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055953" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055941" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055955" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055942" comment="mozilla-xulrunner190-translations less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055944" comment="mozilla-xulrunner190 less than 1.9.0.15-0.1.2"/>
		</criteria>
	</criteria>
	<!-- 49179a9289fbe778bc2320690c17d088 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055945" comment="MozillaFirefox-translations less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055946" comment="MozillaFirefox less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055947" comment="mozilla-xulrunner191-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055966" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055948" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055968" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055949" comment="mozilla-xulrunner191-translations less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055951" comment="mozilla-xulrunner191 less than 1.9.1.4-2.1.3"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093382" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3382</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3382" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3382" source="CVE"/>
	<description>
	layout/base/nsCSSFrameConstructor.cpp in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 does not properly handle first-letter frames, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04c6e38838a85fc92531b3e56904b052 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055940" comment="mozilla-xulrunner190-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055953" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055941" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055955" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055942" comment="mozilla-xulrunner190-translations less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055944" comment="mozilla-xulrunner190 less than 1.9.0.15-0.1.2"/>
		</criteria>
	</criteria>
	<!-- 49179a9289fbe778bc2320690c17d088 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055945" comment="MozillaFirefox-translations less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055946" comment="MozillaFirefox less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055947" comment="mozilla-xulrunner191-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055966" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055948" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055968" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055949" comment="mozilla-xulrunner191-translations less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055951" comment="mozilla-xulrunner191 less than 1.9.1.4-2.1.3"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093383" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3383</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3383" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3383" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04c6e38838a85fc92531b3e56904b052 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055940" comment="mozilla-xulrunner190-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055953" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055941" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055955" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055942" comment="mozilla-xulrunner190-translations less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055944" comment="mozilla-xulrunner190 less than 1.9.0.15-0.1.2"/>
		</criteria>
	</criteria>
	<!-- 49179a9289fbe778bc2320690c17d088 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055945" comment="MozillaFirefox-translations less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055946" comment="MozillaFirefox less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055947" comment="mozilla-xulrunner191-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055966" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055948" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055968" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055949" comment="mozilla-xulrunner191-translations less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055951" comment="mozilla-xulrunner191 less than 1.9.1.4-2.1.3"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093388" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3388</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3388" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3388" source="CVE"/>
	<description>
	liboggplay in Mozilla Firefox 3.5.x before 3.5.6 and SeaMonkey before 2.0.1 might allow context-dependent attackers to cause a denial of service (application crash) or execute arbitrary code via unspecified vectors, related to "memory safety issues."
	</description>
 </metadata>
<!-- 5d919095d6df0dbca3e4ed34b00f367c -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056886" comment="MozillaFirefox-translations less than 3.5.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056887" comment="MozillaFirefox less than 3.5.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056888" comment="mozilla-xulrunner191-32bit less than 1.9.1.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056906" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056889" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056927" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056890" comment="mozilla-xulrunner191-translations less than 1.9.1.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056892" comment="mozilla-xulrunner191 less than 1.9.1.6-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093389" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3389</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3389" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3389" source="CVE"/>
	<description>
	Integer overflow in libtheora in Xiph.Org Theora before 1.1, as used in Mozilla Firefox 3.5 before 3.5.6 and SeaMonkey before 2.0.1, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a video with large dimensions.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5d919095d6df0dbca3e4ed34b00f367c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056886" comment="MozillaFirefox-translations less than 3.5.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056887" comment="MozillaFirefox less than 3.5.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056888" comment="mozilla-xulrunner191-32bit less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056906" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056889" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056927" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056890" comment="mozilla-xulrunner191-translations less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056892" comment="mozilla-xulrunner191 less than 1.9.1.6-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 8019505f916608385487352839f7512d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059264" comment="libtheora0-32bit less than 1.0.beta2-6.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059266" comment="libtheora0 less than 1.0.beta2-6.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093431" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3431</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3431" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3431" source="CVE"/>
	<description>
	Stack consumption vulnerability in Adobe Reader and Acrobat 9.1.3, 9.1.2, 9.1.1, and earlier 9.x versions; 8.1.6 and earlier 8.x versions; and possibly 7.1.4 and earlier 7.x versions allows remote attackers to cause a denial of service (application crash) via a PDF file with a large number of [ (open square bracket) characters in the argument to the alert method. NOTE: some of these details are obtained from third party information.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- ce38af327adaced851154dd69b821772 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055730" comment="acroread_ja less than 8.1.7-0.1.1"/>
	</criteria>
	<!-- da542e714548e7606e770f4fa3ce65f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055727" comment="acroread less than 8.1.7-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093458" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3458</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3458" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3458" source="CVE"/>
	<description>
	Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 do not properly validate input, which might allow attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-2998.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- ce38af327adaced851154dd69b821772 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055730" comment="acroread_ja less than 8.1.7-0.1.1"/>
	</criteria>
	<!-- da542e714548e7606e770f4fa3ce65f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055727" comment="acroread less than 8.1.7-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093459" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3459</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3459" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3459" source="CVE"/>
	<description>
	Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption, as exploited in the wild in October 2009. NOTE: some of these details are obtained from third party information.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- ce38af327adaced851154dd69b821772 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055730" comment="acroread_ja less than 8.1.7-0.1.1"/>
	</criteria>
	<!-- da542e714548e7606e770f4fa3ce65f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055727" comment="acroread less than 8.1.7-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093462" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3462</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3462" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3462" source="CVE"/>
	<description>
	Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 on Unix, when Debug mode is enabled, allow attackers to execute arbitrary code via unspecified vectors, related to a "format bug."
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- ce38af327adaced851154dd69b821772 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055730" comment="acroread_ja less than 8.1.7-0.1.1"/>
	</criteria>
	<!-- da542e714548e7606e770f4fa3ce65f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055727" comment="acroread less than 8.1.7-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093525" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3525</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3525" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3525" source="CVE"/>
	<description>
	The pyGrub boot loader in Xen 3.0.3, 3.3.0, and Xen-3.3.1 does not support the password option in grub.conf for para-virtualized guests, which allows attackers with access to the para-virtualized guest console to boot the guest or modify the guest's kernel boot parameters without providing the expected password.
	</description>
 </metadata>
<!-- 12418b25d25b9d86798e8ea9fc6f68a8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060676" comment="libvirt-python less than 0.4.6-14.60.16"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060677" comment="libvirt less than 0.4.6-14.60.16"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060678" comment="virt-manager less than 0.5.3-66.42.13"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060679" comment="virt-viewer less than 0.0.3-3.57.13"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060680" comment="vm-install less than 0.3.27-0.1.15"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060683" comment="xen-kmp-default less than 3.3.1_18546_24_2.6.27.45_0.3-0.3.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060684" comment="xen-kmp-pae less than 3.3.1_18546_24_2.6.27.45_0.3-0.3.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060685" comment="xen-libs less than 3.3.1_18546_24-0.3.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060686" comment="xen-tools-domU less than 3.3.1_18546_24-0.3.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060687" comment="xen-tools less than 3.3.1_18546_24-0.3.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060688" comment="xen less than 3.3.1_18546_24-0.3.7"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093547" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3547</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3547" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3547" source="CVE"/>
	<description>
	Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous pipe via a /proc/*/fd/ pathname.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 114b9cf953db7d4a1a91082495d33414 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056549" comment="kernel-default-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056511" comment="kernel-xen-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056550" comment="kernel-xen-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056512" comment="kernel-xen less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- a3c4f0428e25dca1993e5018e76d6758 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056549" comment="kernel-default-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056519" comment="kernel-pae-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056552" comment="kernel-pae-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056520" comment="kernel-pae less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056511" comment="kernel-xen-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056550" comment="kernel-xen-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056512" comment="kernel-xen less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093549" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3549</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3549" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3549" source="CVE"/>
	<description>
	packet-paltalk.c in the Paltalk dissector in Wireshark 1.2.0 through 1.2.2, on SPARC and certain other platforms, allows remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace.
	</description>
 </metadata>
<!-- 21376954221689990a2fee3602c8189f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056792" comment="wireshark less than 1.0.5-1.31.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093550" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3550</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3550" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3550" source="CVE"/>
	<description>
	The DCERPC/NT dissector in Wireshark 0.10.10 through 1.0.9 and 1.2.0 through 1.2.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a file that records a malformed packet trace.  NOTE: some of these details are obtained from third party information.
	</description>
 </metadata>
<!-- 21376954221689990a2fee3602c8189f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056792" comment="wireshark less than 1.0.5-1.31.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093551" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3551</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3551" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3551" source="CVE"/>
	<description>
	Off-by-one error in the dissect_negprot_response function in packet-smb.c in the SMB dissector in Wireshark 1.2.0 through 1.2.2 allows remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace.  NOTE: some of these details are obtained from third party information.
	</description>
 </metadata>
<!-- 21376954221689990a2fee3602c8189f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056792" comment="wireshark less than 1.0.5-1.31.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093553" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3553</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3553" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3553" source="CVE"/>
	<description>
	Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS 1.3.7 and 1.3.10 allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, related to improperly maintaining a reference count.  NOTE: some of these details are obtained from third party information.
	</description>
 </metadata>
<!-- a3fa76d8e915d3f22a35726188aa910b -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009058941" comment="cups-client less than 1.3.9-8.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058942" comment="cups-libs-32bit less than 1.3.9-8.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058944" comment="cups-libs less than 1.3.9-8.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058945" comment="cups less than 1.3.9-8.30.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093555" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3555</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2009-3555" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3555" source="CVE"/>
	<description>
	The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2ffd4e402785dad2cb33b70b2b6b9d9b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056255" comment="compat-openssl097g-32bit less than 0.9.7g-146.16.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056256" comment="compat-openssl097g less than 0.9.7g-146.16.1"/>
		</criteria>
	</criteria>
	<!-- 33752f926ef7d4dfa0db31b1c685e810 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059302" comment="java-1_6_0-sun-alsa less than 1.6.0.u19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059303" comment="java-1_6_0-sun-demo less than 1.6.0.u19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059305" comment="java-1_6_0-sun-jdbc less than 1.6.0.u19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059306" comment="java-1_6_0-sun-plugin less than 1.6.0.u19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059307" comment="java-1_6_0-sun-src less than 1.6.0.u19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059308" comment="java-1_6_0-sun less than 1.6.0.u19-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 79f88b4366b267744a8056a0b1669fb3 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009069583" comment="compat-openssl097g-32bit less than 0.9.7g-146.20.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009069584" comment="compat-openssl097g less than 0.9.7g-146.20.1"/>
		</criteria>
	</criteria>
	<!-- 8ead451f2aa5a3390fe43fc3d4eff649 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059477" comment="mozilla-xulrunner190-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059496" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059478" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059498" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059479" comment="mozilla-xulrunner190-translations less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059481" comment="mozilla-xulrunner190 less than 1.9.0.19-0.1.1"/>
		</criteria>
	</criteria>
	<!-- afa1b8679c41392c0a7c5bf73788d74b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009065171" comment="gnutls less than 2.4.1-24.32.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065172" comment="libgnutls26-32bit less than 2.4.1-24.32.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065174" comment="libgnutls26 less than 2.4.1-24.32.1"/>
		</criteria>
	</criteria>
	<!-- b2b07a19e980175398d729721ec11514 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063824" comment="java-1_6_0-sun-alsa less than 1.6.0.u22-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063825" comment="java-1_6_0-sun-demo less than 1.6.0.u22-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063827" comment="java-1_6_0-sun-jdbc less than 1.6.0.u22-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063828" comment="java-1_6_0-sun-plugin less than 1.6.0.u22-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063829" comment="java-1_6_0-sun-src less than 1.6.0.u22-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063830" comment="java-1_6_0-sun less than 1.6.0.u22-1.2.1"/>
		</criteria>
	</criteria>
	<!-- ba7daf7a40cb6e230a70a5af7587cb48 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063824" comment="java-1_6_0-sun-alsa less than 1.6.0.u22-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063825" comment="java-1_6_0-sun-demo less than 1.6.0.u22-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063827" comment="java-1_6_0-sun-jdbc less than 1.6.0.u22-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063828" comment="java-1_6_0-sun-plugin less than 1.6.0.u22-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063829" comment="java-1_6_0-sun-src less than 1.6.0.u22-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063830" comment="java-1_6_0-sun less than 1.6.0.u22-1.2.1"/>
		</criteria>
	</criteria>
	<!-- d0129289ed5f99e99f64649fe9227069 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056248" comment="libopenssl0_9_8-32bit less than 0.9.8h-30.15.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056250" comment="libopenssl0_9_8 less than 0.9.8h-30.15.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056252" comment="openssl less than 0.9.8h-30.15.1"/>
		</criteria>
	</criteria>
	<!-- e687f5d3988822ee23e0bd97566703f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059482" comment="MozillaFirefox-translations less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059483" comment="MozillaFirefox less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059484" comment="mozilla-xulrunner191-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059501" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059485" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059503" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059486" comment="mozilla-xulrunner191-translations less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059488" comment="mozilla-xulrunner191 less than 1.9.1.9-1.1.1"/>
		</criteria>
	</criteria>
	<!-- ed55e89901ea18fdd2a60bdd8a878403 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059415" comment="libfreebl3-32bit less than 3.12.6-3.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059417" comment="libfreebl3 less than 3.12.6-3.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059418" comment="mozilla-nss-32bit less than 3.12.6-3.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059419" comment="mozilla-nss-tools less than 3.12.6-3.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059421" comment="mozilla-nss less than 3.12.6-3.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059422" comment="zlib-32bit less than 1.2.3-106.34"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059424" comment="zlib less than 1.2.3-106.34"/>
		</criteria>
	</criteria>
	<!-- f0725ef2d5a4faab266acd72f09fb8ac -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009065171" comment="gnutls less than 2.4.1-24.32.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065172" comment="libgnutls26-32bit less than 2.4.1-24.32.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065174" comment="libgnutls26 less than 2.4.1-24.32.1"/>
		</criteria>
	</criteria>
	<!-- fba66235e940d7d2f4064d7e1e803b60 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059248" comment="libopenssl0_9_8-32bit less than 0.9.8h-30.22.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059250" comment="libopenssl0_9_8 less than 0.9.8h-30.22.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059252" comment="openssl less than 0.9.8h-30.22.21.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093560" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3560</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3560" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3560" source="CVE"/>
	<description>
	The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with malformed UTF-8 sequences that trigger a buffer over-read, related to the doProlog function in lib/xmlparse.c, a different vulnerability than CVE-2009-2625 and CVE-2009-3720.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 84cc1e78a5b951cb599ebd0537f0c213 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056872" comment="pyxml less than 0.8.4-194.19.1"/>
	</criteria>
	<!-- cc3e3bda8217aa28262b6982edd9bee5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060325" comment="libpython2_6-1_0-32bit less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060327" comment="libpython2_6-1_0 less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060329" comment="python-base-32bit less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060331" comment="python-base less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060332" comment="python-curses less than 2.6.0-8.9.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060429" comment="python-devel less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060338" comment="python-xml less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060339" comment="python less than 2.6.0-8.9.1.1"/>
		</criteria>
	</criteria>
	<!-- df7fac6ab40235408e8ea35318a13920 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056827" comment="expat less than 2.0.1-88.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056828" comment="libexpat1-32bit less than 2.0.1-88.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056830" comment="libexpat1 less than 2.0.1-88.23.1"/>
		</criteria>
	</criteria>
	<!-- fd770268071e50829313d8b6d3bc05c8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057200" comment="expat less than 2.0.1-88.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057201" comment="libexpat1-32bit less than 2.0.1-88.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057203" comment="libexpat1 less than 2.0.1-88.26.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093563" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3563</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3563" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3563" source="CVE"/>
	<description>
	ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by using MODE_PRIVATE to send a spoofed (1) request or (2) response packet that triggers a continuous exchange of MODE_PRIVATE error responses between two NTP daemons.
	</description>
 </metadata>
<!-- 56ca97c7cac4e3de1757053bc75f217f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009057189" comment="ntp-doc less than 4.2.4p6-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057190" comment="ntp less than 4.2.4p6-1.18.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093607" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3607</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3607" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3607" source="CVE"/>
	<description>
	Integer overflow in the create_surface_from_thumbnail_data function in glib/poppler-page.cc in Poppler 0.x allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.  NOTE: some of these details are obtained from third party information.
	</description>
 </metadata>
<!-- bde2b755a6dc83d88dd11394793d4482 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009057042" comment="libpoppler-glib4 less than 0.10.1-1.31.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057043" comment="libpoppler-qt4-3 less than 0.10.1-1.31.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057044" comment="libpoppler4 less than 0.10.1-1.31.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093608" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3608</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3608" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3608" source="CVE"/>
	<description>
	Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and teTeX, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.
	</description>
 </metadata>
<!-- bde2b755a6dc83d88dd11394793d4482 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009057042" comment="libpoppler-glib4 less than 0.10.1-1.31.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057043" comment="libpoppler-qt4-3 less than 0.10.1-1.31.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057044" comment="libpoppler4 less than 0.10.1-1.31.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093612" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3612</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3612" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3612" source="CVE"/>
	<description>
	The tcf_fill_node function in net/sched/cls_api.c in the netlink subsystem in the Linux kernel 2.6.x before 2.6.32-rc5, and 2.4.37.6 and earlier, does not initialize a certain tcm__pad2 structure member, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors.  NOTE: this issue exists because of an incomplete fix for CVE-2005-4881.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 114b9cf953db7d4a1a91082495d33414 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056549" comment="kernel-default-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056511" comment="kernel-xen-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056550" comment="kernel-xen-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056512" comment="kernel-xen less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- a3c4f0428e25dca1993e5018e76d6758 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056549" comment="kernel-default-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056519" comment="kernel-pae-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056552" comment="kernel-pae-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056520" comment="kernel-pae less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056511" comment="kernel-xen-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056550" comment="kernel-xen-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056512" comment="kernel-xen less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093615" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3615</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3615" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3615" source="CVE"/>
	<description>
	The OSCAR protocol plugin in libpurple in Pidgin before 2.6.3 and Adium before 1.3.7 allows remote attackers to cause a denial of service (application crash) via crafted contact-list data for (1) ICQ and possibly (2) AIM, as demonstrated by the SIM IM client.
	</description>
 </metadata>
<!-- 036b34b556d9338c53561c16d2f5a3ce -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056524" comment="cdparanoia-32bit less than IIIalpha9.8-691.22"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056526" comment="cdparanoia less than IIIalpha9.8-691.22"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056527" comment="desktop-file-utils less than 0.15-1.29"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056528" comment="fam-32bit less than 2.7.0-130.21"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056530" comment="fam less than 2.7.0-130.21"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056554" comment="finch less than 2.6.3-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056531" comment="gnome-vfs2-32bit less than 2.24.0-7.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056533" comment="gnome-vfs2 less than 2.24.0-7.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056555" comment="gstreamer-0_10-32bit less than 0.10.21-3.20"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056534" comment="gstreamer-0_10 less than 0.10.21-3.20"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056535" comment="libogg0-32bit less than 1.1.3-87.12"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056537" comment="libogg0 less than 1.1.3-87.12"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056538" comment="liboil-32bit less than 0.3.15-3.10"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056540" comment="liboil less than 0.3.15-3.10"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056558" comment="libpurple-lang less than 2.6.3-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056559" comment="libpurple less than 2.6.3-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056541" comment="libtheora0-32bit less than 1.0.beta2-4.28"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056543" comment="libtheora0 less than 1.0.beta2-4.28"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056562" comment="pidgin-otr less than 3.2.0-1.36.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056561" comment="pidgin less than 2.6.3-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093616" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3616</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3616" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3616" source="CVE"/>
	<description>
	Multiple use-after-free vulnerabilities in vnc.c in the VNC server in QEMU 0.10.6 and earlier might allow guest OS users to execute arbitrary code on the host OS by establishing a connection from a VNC client and then (1) disconnecting during data transfer, (2) sending a message using incorrect integer data types, or (3) using the Fuzzy Screen Mode protocol, related to double free vulnerabilities.
	</description>
 </metadata>
<!-- f4e5016874884c9afd74eae568a826e1 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056324" comment="kvm-kmp-default less than 78.2.6.30.1_2.6.27.37_0.1-0.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056325" comment="kvm-kmp-pae less than 78.2.6.30.1_2.6.27.37_0.1-0.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056326" comment="kvm less than 78.0.10.6-0.3.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093620" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3620</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3620" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3620" source="CVE"/>
	<description>
	The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE) state initialization, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly gain privileges via unspecified ioctl calls.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 114b9cf953db7d4a1a91082495d33414 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056549" comment="kernel-default-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056511" comment="kernel-xen-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056550" comment="kernel-xen-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056512" comment="kernel-xen less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- a3c4f0428e25dca1993e5018e76d6758 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056549" comment="kernel-default-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056519" comment="kernel-pae-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056552" comment="kernel-pae-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056520" comment="kernel-pae less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056511" comment="kernel-xen-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056550" comment="kernel-xen-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056512" comment="kernel-xen less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093621" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3621</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3621" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3621" source="CVE"/>
	<description>
	net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang) by creating an abstract-namespace AF_UNIX listening socket, performing a shutdown operation on this socket, and then performing a series of connect operations to this socket.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 114b9cf953db7d4a1a91082495d33414 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056549" comment="kernel-default-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056511" comment="kernel-xen-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056550" comment="kernel-xen-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056512" comment="kernel-xen less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- a3c4f0428e25dca1993e5018e76d6758 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056549" comment="kernel-default-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056519" comment="kernel-pae-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056552" comment="kernel-pae-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056520" comment="kernel-pae less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056511" comment="kernel-xen-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056550" comment="kernel-xen-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056512" comment="kernel-xen less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093627" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3627</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3627" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3627" source="CVE"/>
	<description>
	The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service (infinite loop) via an incomplete SGML numeric character reference, which triggers generation of an invalid UTF-8 character.
	</description>
 </metadata>
<!-- 58f42631ae5a6c4bdfd6fb69a2114c32 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056793" comment="perl-HTML-Parser less than 3.56-1.18.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093638" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3638</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3638" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3638" source="CVE"/>
	<description>
	Integer overflow in the kvm_dev_ioctl_get_supported_cpuid function in arch/x86/kvm/x86.c in the KVM subsystem in the Linux kernel before 2.6.31.4 allows local users to have an unspecified impact via a KVM_GET_SUPPORTED_CPUID request to the kvm_arch_dev_ioctl function.
	</description>
 </metadata>
<!-- f4e5016874884c9afd74eae568a826e1 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056324" comment="kvm-kmp-default less than 78.2.6.30.1_2.6.27.37_0.1-0.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056325" comment="kvm-kmp-pae less than 78.2.6.30.1_2.6.27.37_0.1-0.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056326" comment="kvm less than 78.0.10.6-0.3.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093640" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3640</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3640" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3640" source="CVE"/>
	<description>
	The update_cr8_intercept function in arch/x86/kvm/x86.c in the KVM subsystem in the Linux kernel before 2.6.32-rc1 does not properly handle the absence of an Advanced Programmable Interrupt Controller (APIC), which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly gain privileges via a call to the kvm_vcpu_ioctl function.
	</description>
 </metadata>
<!-- f4e5016874884c9afd74eae568a826e1 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056324" comment="kvm-kmp-default less than 78.2.6.30.1_2.6.27.37_0.1-0.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056325" comment="kvm-kmp-pae less than 78.2.6.30.1_2.6.27.37_0.1-0.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056326" comment="kvm less than 78.0.10.6-0.3.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093720" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3720</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3720" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3720" source="CVE"/>
	<description>
	The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 84cc1e78a5b951cb599ebd0537f0c213 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056872" comment="pyxml less than 0.8.4-194.19.1"/>
	</criteria>
	<!-- 9920a6312eee8fe0580ddf07cc011eb9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056327" comment="expat less than 2.0.1-88.22.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056328" comment="libexpat1-32bit less than 2.0.1-88.22.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056330" comment="libexpat1 less than 2.0.1-88.22.1"/>
		</criteria>
	</criteria>
	<!-- cc3e3bda8217aa28262b6982edd9bee5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060325" comment="libpython2_6-1_0-32bit less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060327" comment="libpython2_6-1_0 less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060329" comment="python-base-32bit less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060331" comment="python-base less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060332" comment="python-curses less than 2.6.0-8.9.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060429" comment="python-devel less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060338" comment="python-xml less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060339" comment="python less than 2.6.0-8.9.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093726" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3726</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3726" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3726" source="CVE"/>
	<description>
	The nfs4_proc_lock function in fs/nfs/nfs4proc.c in the NFSv4 client in the Linux kernel before 2.6.31-rc4 allows remote NFS servers to cause a denial of service (NULL pointer dereference and panic) by sending a certain response containing incorrect file attributes, which trigger attempted use of an open file that lacks NFSv4 state.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 114b9cf953db7d4a1a91082495d33414 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056549" comment="kernel-default-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056511" comment="kernel-xen-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056550" comment="kernel-xen-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056512" comment="kernel-xen less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- a3c4f0428e25dca1993e5018e76d6758 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056549" comment="kernel-default-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056519" comment="kernel-pae-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056552" comment="kernel-pae-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056520" comment="kernel-pae less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056511" comment="kernel-xen-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056550" comment="kernel-xen-extra less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056512" comment="kernel-xen less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093736" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3736</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3736" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3736" source="CVE"/>
	<description>
	ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, which allows local users to gain privileges via a Trojan horse file.
	</description>
 </metadata>
<!-- 47556f0ada22d5f48c6e9e760e265eda -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009057089" comment="libltdl7-32bit less than 2.2.6-2.131.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057091" comment="libltdl7 less than 2.2.6-2.131.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093743" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3743</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP2</platform>
	</affected>
	<reference ref_id="CVE-2009-3743" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3743" source="CVE"/>
	<description>
	Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript before 8.71 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a malformed TrueType font in a document that trigger an integer overflow and a heap-based buffer overflow.
	</description>
 </metadata>
<!-- d32438d017a666c248f87a90698dda0a -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009073459" comment="ghostscript-fonts-other less than 8.62-32.32.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009073460" comment="ghostscript-fonts-rus less than 8.62-32.32.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009073461" comment="ghostscript-fonts-std less than 8.62-32.32.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009073462" comment="ghostscript-library less than 8.62-32.32.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009073463" comment="ghostscript-omni less than 8.62-32.32.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009073464" comment="ghostscript-x11 less than 8.62-32.32.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009073465" comment="libgimpprint less than 4.2.7-32.32.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093793" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3793</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2009-3793" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3793" source="CVE"/>
	<description>
	Unspecified vulnerability in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory consumption) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 9fed1ac7d6ac263f8b42cb8e24927e67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
	<!-- dc5e2e29ebe98d9444b78ef5643bf4f1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093794" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3794</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3794" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3794" source="CVE"/>
	<description>
	Heap-based buffer overflow in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allows remote attackers to execute arbitrary code via crafted dimensions of JPEG data in an SWF file.
	</description>
 </metadata>
<!-- e05eaa5bc2d0120d8f1fa1d273bc07ff -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056943" comment="flash-player less than 10.0.42.34-0.3.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093796" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3796</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3796" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3796" source="CVE"/>
	<description>
	Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors, related to a "data injection vulnerability."
	</description>
 </metadata>
<!-- e05eaa5bc2d0120d8f1fa1d273bc07ff -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056943" comment="flash-player less than 10.0.42.34-0.3.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093797" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3797</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3797" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3797" source="CVE"/>
	<description>
	Adobe Flash Player 10.x before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors that trigger memory corruption.
	</description>
 </metadata>
<!-- e05eaa5bc2d0120d8f1fa1d273bc07ff -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056943" comment="flash-player less than 10.0.42.34-0.3.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093798" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3798</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3798" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3798" source="CVE"/>
	<description>
	Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors that trigger memory corruption.
	</description>
 </metadata>
<!-- e05eaa5bc2d0120d8f1fa1d273bc07ff -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056943" comment="flash-player less than 10.0.42.34-0.3.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093799" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3799</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3799" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3799" source="CVE"/>
	<description>
	Integer overflow in the Verifier::parseExceptionHandlers function in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allows remote attackers to execute arbitrary code via an SWF file with a large exception_count value that triggers memory corruption, related to "generation of ActionScript exception handlers."
	</description>
 </metadata>
<!-- e05eaa5bc2d0120d8f1fa1d273bc07ff -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056943" comment="flash-player less than 10.0.42.34-0.3.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093800" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3800</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3800" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3800" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allow attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
<!-- e05eaa5bc2d0120d8f1fa1d273bc07ff -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056943" comment="flash-player less than 10.0.42.34-0.3.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093829" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3829</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3829" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3829" source="CVE"/>
	<description>
	Integer overflow in wiretap/erf.c in Wireshark before 1.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted erf file, related to an "unsigned integer wrap vulnerability."
	</description>
 </metadata>
<!-- 21376954221689990a2fee3602c8189f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056792" comment="wireshark less than 1.0.5-1.31.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093864" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3864</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3864" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3864" source="CVE"/>
	<description>
	The Java Update functionality in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22 and JDK and JRE 6 before Update 17, when a non-English version of Windows is used, does not retrieve available new JRE versions, which allows remote attackers to leverage vulnerabilities in older releases of this software, aka Bug Id 6869694.
	</description>
 </metadata>
<!-- e41ba800019ecd12f67ec2e165434c74 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056292" comment="java-1_6_0-sun-alsa less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056319" comment="java-1_6_0-sun-demo less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056294" comment="java-1_6_0-sun-jdbc less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056295" comment="java-1_6_0-sun-plugin less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056296" comment="java-1_6_0-sun-src less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056297" comment="java-1_6_0-sun less than 1.6.0.u17-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093865" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3865</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3865" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3865" source="CVE"/>
	<description>
	The launch method in the Deployment Toolkit plugin in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 6 before Update 17 allows remote attackers to execute arbitrary commands via a crafted web page, aka Bug Id 6869752.
	</description>
 </metadata>
<!-- e41ba800019ecd12f67ec2e165434c74 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056292" comment="java-1_6_0-sun-alsa less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056319" comment="java-1_6_0-sun-demo less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056294" comment="java-1_6_0-sun-jdbc less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056295" comment="java-1_6_0-sun-plugin less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056296" comment="java-1_6_0-sun-src less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056297" comment="java-1_6_0-sun less than 1.6.0.u17-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093866" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3866</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3866" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3866" source="CVE"/>
	<description>
	The Java Web Start Installer in Sun Java SE in JDK and JRE 6 before Update 17 does not properly use security model permissions when removing installer extensions, which allows remote attackers to execute arbitrary code by modifying a certain JNLP file to have a URL field that points to an unintended trusted application, aka Bug Id 6872824.
	</description>
 </metadata>
<!-- e41ba800019ecd12f67ec2e165434c74 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056292" comment="java-1_6_0-sun-alsa less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056319" comment="java-1_6_0-sun-demo less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056294" comment="java-1_6_0-sun-jdbc less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056295" comment="java-1_6_0-sun-plugin less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056296" comment="java-1_6_0-sun-src less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056297" comment="java-1_6_0-sun less than 1.6.0.u17-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093867" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3867</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3867" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3867" source="CVE"/>
	<description>
	Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a long file: URL in an argument, aka Bug Id 6854303.
	</description>
 </metadata>
<!-- e41ba800019ecd12f67ec2e165434c74 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056292" comment="java-1_6_0-sun-alsa less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056319" comment="java-1_6_0-sun-demo less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056294" comment="java-1_6_0-sun-jdbc less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056295" comment="java-1_6_0-sun-plugin less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056296" comment="java-1_6_0-sun-src less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056297" comment="java-1_6_0-sun less than 1.6.0.u17-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093868" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3868</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3868" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3868" source="CVE"/>
	<description>
	Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 does not properly parse color profiles, which allows remote attackers to gain privileges via a crafted image file, aka Bug Id 6862970.
	</description>
 </metadata>
<!-- e41ba800019ecd12f67ec2e165434c74 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056292" comment="java-1_6_0-sun-alsa less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056319" comment="java-1_6_0-sun-demo less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056294" comment="java-1_6_0-sun-jdbc less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056295" comment="java-1_6_0-sun-plugin less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056296" comment="java-1_6_0-sun-src less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056297" comment="java-1_6_0-sun less than 1.6.0.u17-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093869" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3869</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3869" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3869" source="CVE"/>
	<description>
	Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a crafted argument, aka Bug Id 6872357.
	</description>
 </metadata>
<!-- e41ba800019ecd12f67ec2e165434c74 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056292" comment="java-1_6_0-sun-alsa less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056319" comment="java-1_6_0-sun-demo less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056294" comment="java-1_6_0-sun-jdbc less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056295" comment="java-1_6_0-sun-plugin less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056296" comment="java-1_6_0-sun-src less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056297" comment="java-1_6_0-sun less than 1.6.0.u17-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093871" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3871</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3871" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3871" source="CVE"/>
	<description>
	Heap-based buffer overflow in the setBytePixels function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via crafted arguments, aka Bug Id 6872358.
	</description>
 </metadata>
<!-- e41ba800019ecd12f67ec2e165434c74 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056292" comment="java-1_6_0-sun-alsa less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056319" comment="java-1_6_0-sun-demo less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056294" comment="java-1_6_0-sun-jdbc less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056295" comment="java-1_6_0-sun-plugin less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056296" comment="java-1_6_0-sun-src less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056297" comment="java-1_6_0-sun less than 1.6.0.u17-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093872" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3872</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3872" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3872" source="CVE"/>
	<description>
	Unspecified vulnerability in the JPEG JFIF Decoder in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, aka Bug Id 6862969.
	</description>
 </metadata>
<!-- e41ba800019ecd12f67ec2e165434c74 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056292" comment="java-1_6_0-sun-alsa less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056319" comment="java-1_6_0-sun-demo less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056294" comment="java-1_6_0-sun-jdbc less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056295" comment="java-1_6_0-sun-plugin less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056296" comment="java-1_6_0-sun-src less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056297" comment="java-1_6_0-sun less than 1.6.0.u17-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093873" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3873</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3873" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3873" source="CVE"/>
	<description>
	The JPEG Image Writer in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, related to a "quantization problem," aka Bug Id 6862968.
	</description>
 </metadata>
<!-- e41ba800019ecd12f67ec2e165434c74 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056292" comment="java-1_6_0-sun-alsa less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056319" comment="java-1_6_0-sun-demo less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056294" comment="java-1_6_0-sun-jdbc less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056295" comment="java-1_6_0-sun-plugin less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056296" comment="java-1_6_0-sun-src less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056297" comment="java-1_6_0-sun less than 1.6.0.u17-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093874" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3874</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3874" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3874" source="CVE"/>
	<description>
	Integer overflow in the JPEGImageReader implementation in the ImageI/O component in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via large subsample dimensions in a JPEG file that triggers a heap-based buffer overflow, aka Bug Id 6874643.
	</description>
 </metadata>
<!-- e41ba800019ecd12f67ec2e165434c74 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056292" comment="java-1_6_0-sun-alsa less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056319" comment="java-1_6_0-sun-demo less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056294" comment="java-1_6_0-sun-jdbc less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056295" comment="java-1_6_0-sun-plugin less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056296" comment="java-1_6_0-sun-src less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056297" comment="java-1_6_0-sun less than 1.6.0.u17-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093875" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3875</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3875" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3875" source="CVE"/>
	<description>
	The MessageDigest.isEqual function in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to spoof HMAC-based digital signatures, and possibly bypass authentication, via unspecified vectors related to "timing attack vulnerabilities," aka Bug Id 6863503.
	</description>
 </metadata>
<!-- e41ba800019ecd12f67ec2e165434c74 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056292" comment="java-1_6_0-sun-alsa less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056319" comment="java-1_6_0-sun-demo less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056294" comment="java-1_6_0-sun-jdbc less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056295" comment="java-1_6_0-sun-plugin less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056296" comment="java-1_6_0-sun-src less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056297" comment="java-1_6_0-sun less than 1.6.0.u17-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093876" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3876</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3876" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3876" source="CVE"/>
	<description>
	Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to cause a denial of service (memory consumption) via crafted DER encoded data, which is not properly decoded by the ASN.1 DER input stream parser, aka Bug Id 6864911.
	</description>
 </metadata>
<!-- e41ba800019ecd12f67ec2e165434c74 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056292" comment="java-1_6_0-sun-alsa less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056319" comment="java-1_6_0-sun-demo less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056294" comment="java-1_6_0-sun-jdbc less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056295" comment="java-1_6_0-sun-plugin less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056296" comment="java-1_6_0-sun-src less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056297" comment="java-1_6_0-sun less than 1.6.0.u17-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093877" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3877</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3877" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3877" source="CVE"/>
	<description>
	Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to cause a denial of service (memory consumption) via crafted HTTP headers, which are not properly parsed by the ASN.1 DER input stream parser, aka Bug Id 6864911.
	</description>
 </metadata>
<!-- e41ba800019ecd12f67ec2e165434c74 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056292" comment="java-1_6_0-sun-alsa less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056319" comment="java-1_6_0-sun-demo less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056294" comment="java-1_6_0-sun-jdbc less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056295" comment="java-1_6_0-sun-plugin less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056296" comment="java-1_6_0-sun-src less than 1.6.0.u17-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056297" comment="java-1_6_0-sun less than 1.6.0.u17-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093909" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3909</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3909" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3909" source="CVE"/>
	<description>
	Integer overflow in the read_channel_data function in plug-ins/file-psd/psd-load.c in GIMP 2.6.7 might allow remote attackers to execute arbitrary code via a crafted PSD file that triggers a heap-based buffer overflow.
	</description>
 </metadata>
<!-- 8ba40ccada7a302ad31567388357c039 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059682" comment="gimp-lang less than 2.6.2-3.28.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059683" comment="gimp-plugins-python less than 2.6.2-3.28.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059684" comment="gimp less than 2.6.2-3.28.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093938" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3938</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3938" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3938" source="CVE"/>
	<description>
	Buffer overflow in the ABWOutputDev::endWord function in poppler/ABWOutputDev.cc in Poppler (aka libpoppler) 0.10.6, 0.12.0, and possibly other versions, as used by the Abiword pdftoabw utility, allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted PDF file.
	</description>
 </metadata>
<!-- bde2b755a6dc83d88dd11394793d4482 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009057042" comment="libpoppler-glib4 less than 0.10.1-1.31.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057043" comment="libpoppler-qt4-3 less than 0.10.1-1.31.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057044" comment="libpoppler4 less than 0.10.1-1.31.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093939" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3939</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3939" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3939" source="CVE"/>
	<description>
	The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5bc8b282021bec5a0602dd1e1fb86cc0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058512" comment="kernel-default-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058513" comment="kernel-xen-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 8de370e0ec03088da9aa16f31064b5c4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058512" comment="kernel-default-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058501" comment="kernel-pae-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058515" comment="kernel-pae-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058502" comment="kernel-pae less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058513" comment="kernel-xen-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e7c5f7ef7eeb152d788f9406d2374894 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057219" comment="kernel-pae-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057220" comment="kernel-pae-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057221" comment="kernel-pae less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057232" comment="kernel-xen-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057233" comment="kernel-xen-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057234" comment="kernel-xen less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e87c441668f87fa162f810ea0e06c3ba -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057232" comment="kernel-xen-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057233" comment="kernel-xen-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057234" comment="kernel-xen less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093951" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3951</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3951" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3951" source="CVE"/>
	<description>
	Unspecified vulnerability in the Flash Player ActiveX control in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 on Windows allows remote attackers to obtain the names of local files via unknown vectors.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4820.
	</description>
 </metadata>
<!-- e05eaa5bc2d0120d8f1fa1d273bc07ff -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056943" comment="flash-player less than 10.0.42.34-0.3.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093953" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3953</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3953" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3953" source="CVE"/>
	<description>
	The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document, related to a CLODProgressiveMeshDeclaration "array boundary issue," a different vulnerability than CVE-2009-2994.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0e62c3af8b734325d297f36aa439e519 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057622" comment="acroread_ja less than 9.3-0.1.1"/>
	</criteria>
	<!-- 92cc3368337b3767a6a4451406360608 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057440" comment="acroread less than 9.3-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093954" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3954</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3954" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3954" source="CVE"/>
	<description>
	The 3D implementation in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, might allow attackers to execute arbitrary code via unspecified vectors, related to a "DLL-loading vulnerability."
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0e62c3af8b734325d297f36aa439e519 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057622" comment="acroread_ja less than 9.3-0.1.1"/>
	</criteria>
	<!-- 92cc3368337b3767a6a4451406360608 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057440" comment="acroread less than 9.3-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093955" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3955</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3955" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3955" source="CVE"/>
	<description>
	Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted JPC_MS_RGN marker in the Jp2c stream of a JpxDecode encoded data stream, which triggers an integer sign extension that bypasses a sanity check, leading to memory corruption.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0e62c3af8b734325d297f36aa439e519 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057622" comment="acroread_ja less than 9.3-0.1.1"/>
	</criteria>
	<!-- 92cc3368337b3767a6a4451406360608 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057440" comment="acroread less than 9.3-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093956" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3956</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3956" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3956" source="CVE"/>
	<description>
	The default configuration of Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, does not enable the Enhanced Security feature, which has unspecified impact and attack vectors, related to a "script injection vulnerability," as demonstrated by Acrobat Forms Data Format (FDF) behavior that allows cross-site scripting (XSS) by user-assisted remote attackers.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0e62c3af8b734325d297f36aa439e519 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057622" comment="acroread_ja less than 9.3-0.1.1"/>
	</criteria>
	<!-- 92cc3368337b3767a6a4451406360608 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057440" comment="acroread less than 9.3-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093957" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3957</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3957" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3957" source="CVE"/>
	<description>
	Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, might allow attackers to cause a denial of service (NULL pointer dereference) via unspecified vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0e62c3af8b734325d297f36aa439e519 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057622" comment="acroread_ja less than 9.3-0.1.1"/>
	</criteria>
	<!-- 92cc3368337b3767a6a4451406360608 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057440" comment="acroread less than 9.3-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093958" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3958</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3958" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3958" source="CVE"/>
	<description>
	Multiple stack-based buffer overflows in the NOS Microsystems getPlus Helper ActiveX control before 1.6.2.49 in gp.ocx in the Download Manager in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, might allow remote attackers to execute arbitrary code via unspecified initialization parameters.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0e62c3af8b734325d297f36aa439e519 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057622" comment="acroread_ja less than 9.3-0.1.1"/>
	</criteria>
	<!-- 92cc3368337b3767a6a4451406360608 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057440" comment="acroread less than 9.3-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093959" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3959</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3959" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3959" source="CVE"/>
	<description>
	Integer overflow in the U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a malformed PDF document.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0e62c3af8b734325d297f36aa439e519 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057622" comment="acroread_ja less than 9.3-0.1.1"/>
	</criteria>
	<!-- 92cc3368337b3767a6a4451406360608 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057440" comment="acroread less than 9.3-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093978" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3978</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3978" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3978" source="CVE"/>
	<description>
	The nsGIFDecoder2::GifWrite function in decoders/gif/nsGIFDecoder2.cpp in libpr0n in Mozilla Firefox before 3.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an animated GIF file with a large image size, a different vulnerability than CVE-2009-3373.
	</description>
 </metadata>
<!-- a8ef456fbe2f7e3278460baef881cddc -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056346" comment="MozillaFirefox-translations less than 3.5.5-1.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056347" comment="MozillaFirefox less than 3.5.5-1.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056348" comment="mozilla-xulrunner191-32bit less than 1.9.1.5-1.3.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056365" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.5-1.3.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056349" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.5-1.3.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056367" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.5-1.3.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056350" comment="mozilla-xulrunner191-translations less than 1.9.1.5-1.3.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056352" comment="mozilla-xulrunner191 less than 1.9.1.5-1.3.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093979" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3979</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3979" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3979" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5d919095d6df0dbca3e4ed34b00f367c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056886" comment="MozillaFirefox-translations less than 3.5.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056887" comment="MozillaFirefox less than 3.5.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056888" comment="mozilla-xulrunner191-32bit less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056906" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056889" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056927" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056890" comment="mozilla-xulrunner191-translations less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056892" comment="mozilla-xulrunner191 less than 1.9.1.6-1.1.1"/>
		</criteria>
	</criteria>
	<!-- f95e0523ee35275bfe5a5ff2cd4fe04f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056893" comment="mozilla-xulrunner190-32bit less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056954" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056894" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056956" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056895" comment="mozilla-xulrunner190-translations less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056897" comment="mozilla-xulrunner190 less than 1.9.0.16-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093980" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3980</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3980" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3980" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
<!-- 5d919095d6df0dbca3e4ed34b00f367c -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056886" comment="MozillaFirefox-translations less than 3.5.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056887" comment="MozillaFirefox less than 3.5.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056888" comment="mozilla-xulrunner191-32bit less than 1.9.1.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056906" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056889" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056927" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056890" comment="mozilla-xulrunner191-translations less than 1.9.1.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056892" comment="mozilla-xulrunner191 less than 1.9.1.6-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093981" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3981</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3981" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3981" source="CVE"/>
	<description>
	Unspecified vulnerability in the browser engine in Mozilla Firefox before 3.0.16, SeaMonkey before 2.0.1, and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
<!-- f95e0523ee35275bfe5a5ff2cd4fe04f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056893" comment="mozilla-xulrunner190-32bit less than 1.9.0.16-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056954" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.16-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056894" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.16-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056956" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.16-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056895" comment="mozilla-xulrunner190-translations less than 1.9.0.16-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056897" comment="mozilla-xulrunner190 less than 1.9.0.16-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093982" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3982</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3982" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3982" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
<!-- 5d919095d6df0dbca3e4ed34b00f367c -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056886" comment="MozillaFirefox-translations less than 3.5.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056887" comment="MozillaFirefox less than 3.5.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056888" comment="mozilla-xulrunner191-32bit less than 1.9.1.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056906" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056889" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056927" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056890" comment="mozilla-xulrunner191-translations less than 1.9.1.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056892" comment="mozilla-xulrunner191 less than 1.9.1.6-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093983" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3983</title>
	<affected family="unix">
		<platform>SLE 11 DESKTOP Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3983" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3983" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to send authenticated requests to arbitrary applications by replaying the NTLM credentials of a browser user.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5d919095d6df0dbca3e4ed34b00f367c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056886" comment="MozillaFirefox-translations less than 3.5.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056887" comment="MozillaFirefox less than 3.5.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056888" comment="mozilla-xulrunner191-32bit less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056906" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056889" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056927" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056890" comment="mozilla-xulrunner191-translations less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056892" comment="mozilla-xulrunner191 less than 1.9.1.6-1.1.1"/>
		</criteria>
	</criteria>
	<!-- f2377272fe27726ada5a22ead971d6aa -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059215" comment="MozillaThunderbird-translations less than 2.0.0.24-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059216" comment="MozillaThunderbird less than 2.0.0.24-0.1.1"/>
		</criteria>
	</criteria>
	<!-- f95e0523ee35275bfe5a5ff2cd4fe04f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056893" comment="mozilla-xulrunner190-32bit less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056954" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056894" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056956" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056895" comment="mozilla-xulrunner190-translations less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056897" comment="mozilla-xulrunner190 less than 1.9.0.16-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093984" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3984</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3984" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3984" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to spoof an SSL indicator for an http URL or a file URL by setting document.location to an https URL corresponding to a site that responds with a No Content (aka 204) status code and an empty body.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5d919095d6df0dbca3e4ed34b00f367c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056886" comment="MozillaFirefox-translations less than 3.5.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056887" comment="MozillaFirefox less than 3.5.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056888" comment="mozilla-xulrunner191-32bit less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056906" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056889" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056927" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056890" comment="mozilla-xulrunner191-translations less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056892" comment="mozilla-xulrunner191 less than 1.9.1.6-1.1.1"/>
		</criteria>
	</criteria>
	<!-- f95e0523ee35275bfe5a5ff2cd4fe04f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056893" comment="mozilla-xulrunner190-32bit less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056954" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056894" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056956" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056895" comment="mozilla-xulrunner190-translations less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056897" comment="mozilla-xulrunner190 less than 1.9.0.16-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093985" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3985</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3985" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3985" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to associate spoofed content with an invalid URL by setting document.location to this URL, and then writing arbitrary web script or HTML to the associated blank document, a related issue to CVE-2009-2654.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5d919095d6df0dbca3e4ed34b00f367c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056886" comment="MozillaFirefox-translations less than 3.5.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056887" comment="MozillaFirefox less than 3.5.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056888" comment="mozilla-xulrunner191-32bit less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056906" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056889" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056927" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056890" comment="mozilla-xulrunner191-translations less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056892" comment="mozilla-xulrunner191 less than 1.9.1.6-1.1.1"/>
		</criteria>
	</criteria>
	<!-- f95e0523ee35275bfe5a5ff2cd4fe04f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056893" comment="mozilla-xulrunner190-32bit less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056954" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056894" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056956" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056895" comment="mozilla-xulrunner190-translations less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056897" comment="mozilla-xulrunner190 less than 1.9.0.16-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093986" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3986</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3986" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3986" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to execute arbitrary JavaScript with chrome privileges by leveraging a reference to a chrome window from a content window, related to the window.opener property.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5d919095d6df0dbca3e4ed34b00f367c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056886" comment="MozillaFirefox-translations less than 3.5.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056887" comment="MozillaFirefox less than 3.5.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056888" comment="mozilla-xulrunner191-32bit less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056906" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056889" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056927" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056890" comment="mozilla-xulrunner191-translations less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056892" comment="mozilla-xulrunner191 less than 1.9.1.6-1.1.1"/>
		</criteria>
	</criteria>
	<!-- f95e0523ee35275bfe5a5ff2cd4fe04f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056893" comment="mozilla-xulrunner190-32bit less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056954" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056894" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056956" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056895" comment="mozilla-xulrunner190-translations less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056897" comment="mozilla-xulrunner190 less than 1.9.0.16-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093988" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3988</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3988" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3988" source="CVE"/>
	<description>
	Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly restrict read access to object properties in showModalDialog, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via crafted dialogArguments values.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5c9ba6a33f35e3ab788cbbefde6cf8a6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058351" comment="MozillaFirefox-translations less than 3.5.8-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058352" comment="MozillaFirefox less than 3.5.8-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058353" comment="mozilla-xulrunner191-32bit less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058436" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058354" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058438" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058355" comment="mozilla-xulrunner191-translations less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058357" comment="mozilla-xulrunner191 less than 1.9.1.8-1.1.1"/>
		</criteria>
	</criteria>
	<!-- deb36b8154e27ded345f064786253ca1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058358" comment="mozilla-xulrunner190-32bit less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058432" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058359" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058433" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058360" comment="mozilla-xulrunner190-translations less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058362" comment="mozilla-xulrunner190 less than 1.9.0.18-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093995" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3995</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3995" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3995" source="CVE"/>
	<description>
	Multiple heap-based buffer overflows in IN_MOD.DLL (aka the Module Decoder Plug-in) in Winamp before 5.57, and libmikmod 3.1.12, might allow remote attackers to execute arbitrary code via (1) crafted samples or (2) crafted instrument definitions in an Impulse Tracker file.  NOTE: some of these details are obtained from third party information.
	</description>
 </metadata>
<!-- c06e1fa610a55cbefe1d7d1129da83d9 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060146" comment="libmikmod-32bit less than 3.1.11a-116.2.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060145" comment="libmikmod less than 3.1.11a-116.2.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093996" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3996</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3996" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3996" source="CVE"/>
	<description>
	Heap-based buffer overflow in IN_MOD.DLL (aka the Module Decoder Plug-in) in Winamp before 5.57, and libmikmod 3.1.12, might allow remote attackers to execute arbitrary code via an Ultratracker file.
	</description>
 </metadata>
<!-- c06e1fa610a55cbefe1d7d1129da83d9 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060146" comment="libmikmod-32bit less than 3.1.11a-116.2.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060145" comment="libmikmod less than 3.1.11a-116.2.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094005" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4005</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4005" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4005" source="CVE"/>
	<description>
	The collect_rx_frame function in drivers/isdn/hisax/hfc_usb.c in the Linux kernel before 2.6.32-rc7 allows attackers to have an unspecified impact via a crafted HDLC packet that arrives over ISDN and triggers a buffer under-read.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- e7c5f7ef7eeb152d788f9406d2374894 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057219" comment="kernel-pae-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057220" comment="kernel-pae-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057221" comment="kernel-pae less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057232" comment="kernel-xen-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057233" comment="kernel-xen-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057234" comment="kernel-xen less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e87c441668f87fa162f810ea0e06c3ba -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057232" comment="kernel-xen-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057233" comment="kernel-xen-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057234" comment="kernel-xen less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094019" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4019</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4019" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4019" source="CVE"/>
	<description>
	mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with subqueries, and does not (2) preserve certain null_value flags during execution of statements that use the GeomFromWKB function, which allows remote authenticated users to cause a denial of service (daemon crash) via a crafted statement.
	</description>
 </metadata>
<!-- 920486ef8624fdf8d628849a50561aa6 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060043" comment="libmysqlclient15-32bit less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060045" comment="libmysqlclient15 less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060134" comment="libmysqlclient_r15-32bit less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060046" comment="libmysqlclient_r15 less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060048" comment="mysql-client less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060049" comment="mysql less than 5.0.67-13.17.7"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094020" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4020</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4020" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4020" source="CVE"/>
	<description>
	Stack-based buffer overflow in the hfs subsystem in the Linux kernel 2.6.32 allows remote attackers to have an unspecified impact via a crafted Hierarchical File System (HFS) filesystem, related to the hfs_readdir function in fs/hfs/dir.c.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- e7c5f7ef7eeb152d788f9406d2374894 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057219" comment="kernel-pae-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057220" comment="kernel-pae-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057221" comment="kernel-pae less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057232" comment="kernel-xen-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057233" comment="kernel-xen-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057234" comment="kernel-xen less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e87c441668f87fa162f810ea0e06c3ba -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057232" comment="kernel-xen-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057233" comment="kernel-xen-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057234" comment="kernel-xen less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094022" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4022</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4022" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4022" source="CVE"/>
	<description>
	Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 440b3d1daa2c9fed4b99f7865ea3a906 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057429" comment="bind-libs-32bit less than 9.5.0P2-20.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057431" comment="bind-libs less than 9.5.0P2-20.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057432" comment="bind-utils less than 9.5.0P2-20.7.1"/>
		</criteria>
	</criteria>
	<!-- 815e5fc596ff53d04190524da4e8d4bb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056413" comment="bind-libs-32bit less than 9.5.0P2-20.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056415" comment="bind-libs less than 9.5.0P2-20.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056416" comment="bind-utils less than 9.5.0P2-20.4.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094028" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4028</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4028" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4028" source="CVE"/>
	<description>
	The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41, when OpenSSL is used, accepts a value of zero for the depth of X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary SSL-based MySQL servers via a crafted certificate, as demonstrated by a certificate presented by a server linked against the yaSSL library.
	</description>
 </metadata>
<!-- 920486ef8624fdf8d628849a50561aa6 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060043" comment="libmysqlclient15-32bit less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060045" comment="libmysqlclient15 less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060134" comment="libmysqlclient_r15-32bit less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060046" comment="libmysqlclient_r15 less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060048" comment="mysql-client less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060049" comment="mysql less than 5.0.67-13.17.7"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094030" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4030</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4030" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4030" source="CVE"/>
	<description>
	MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL data home directory, related to incorrect calculation of the mysql_unpacked_real_data_home value.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4098 and CVE-2008-2079.
	</description>
 </metadata>
<!-- 920486ef8624fdf8d628849a50561aa6 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060043" comment="libmysqlclient15-32bit less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060045" comment="libmysqlclient15 less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060134" comment="libmysqlclient_r15-32bit less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060046" comment="libmysqlclient_r15 less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060048" comment="mysql-client less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060049" comment="mysql less than 5.0.67-13.17.7"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094034" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4034</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4034" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4034" source="CVE"/>
	<description>
	PostgreSQL 7.4.x before 7.4.27, 8.0.x before 8.0.23, 8.1.x before 8.1.19, 8.2.x before 8.2.15, 8.3.x before 8.3.9, and 8.4.x before 8.4.2 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-middle attackers to spoof arbitrary SSL-based PostgreSQL servers via a crafted server certificate issued by a legitimate Certification Authority, and (2) allows remote attackers to bypass intended client-hostname restrictions via a crafted client certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
	</description>
 </metadata>
<!-- 60350894f45471126371713fb1946bb0 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009057278" comment="postgresql-libs-32bit less than 8.3.9-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057280" comment="postgresql-libs less than 8.3.9-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057282" comment="postgresql less than 8.3.9-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094035" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4035</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4035" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4035" source="CVE"/>
	<description>
	The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, does not check the return value of the getNextLine function, which allows context-dependent attackers to execute arbitrary code via a PDF file with a crafted Type 1 font that can produce a negative value, leading to a signed-to-unsigned integer conversion error and a buffer overflow.
	</description>
 </metadata>
<!-- bde2b755a6dc83d88dd11394793d4482 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009057042" comment="libpoppler-glib4 less than 0.10.1-1.31.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057043" comment="libpoppler-qt4-3 less than 0.10.1-1.31.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057044" comment="libpoppler4 less than 0.10.1-1.31.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094136" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4136</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4136" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4136" source="CVE"/>
	<description>
	PostgreSQL 7.4.x before 7.4.27, 8.0.x before 8.0.23, 8.1.x before 8.1.19, 8.2.x before 8.2.15, 8.3.x before 8.3.9, and 8.4.x before 8.4.2 does not properly manage session-local state during execution of an index function by a database superuser, which allows remote authenticated users to gain privileges via a table with crafted index functions, as demonstrated by functions that modify (1) search_path or (2) a prepared statement, a related issue to CVE-2007-6600 and CVE-2009-3230.
	</description>
 </metadata>
<!-- 60350894f45471126371713fb1946bb0 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009057278" comment="postgresql-libs-32bit less than 8.3.9-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057280" comment="postgresql-libs less than 8.3.9-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057282" comment="postgresql less than 8.3.9-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094138" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4138</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4138" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4138" source="CVE"/>
	<description>
	drivers/firewire/ohci.c in the Linux kernel before 2.6.32-git9, when packet-per-buffer mode is used, allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unknown other impact via an unspecified ioctl associated with receiving an ISO packet that contains zero in the payload-length field.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- e7c5f7ef7eeb152d788f9406d2374894 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057219" comment="kernel-pae-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057220" comment="kernel-pae-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057221" comment="kernel-pae less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057232" comment="kernel-xen-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057233" comment="kernel-xen-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057234" comment="kernel-xen less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e87c441668f87fa162f810ea0e06c3ba -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057232" comment="kernel-xen-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057233" comment="kernel-xen-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057234" comment="kernel-xen less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094144" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4144</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4144" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4144" source="CVE"/>
	<description>
	NetworkManager (NM) 0.7.2 does not ensure that the configured Certification Authority (CA) certificate file for a (1) WPA Enterprise or (2) 802.1x network remains present upon a connection attempt, which might allow remote attackers to obtain sensitive information or cause a denial of service (connectivity disruption) by spoofing the identity of a wireless network.
	</description>
 </metadata>
<!-- 776b8b47d07dc7f9d184e6dc49981f25 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057532" comment="NetworkManager-gnome less than 0.7.0.r1053-11.11.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094145" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4145</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4145" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4145" source="CVE"/>
	<description>
	nm-connection-editor in NetworkManager (NM) 0.7.x exports connection objects over D-Bus upon actions in the connection editor GUI, which allows local users to obtain sensitive information by reading D-Bus signals, as demonstrated by using dbus-monitor to discover the password for the WiFi network.
	</description>
 </metadata>
<!-- 776b8b47d07dc7f9d184e6dc49981f25 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057532" comment="NetworkManager-gnome less than 0.7.0.r1053-11.11.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094212" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4212</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4212" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4212" source="CVE"/>
	<description>
	Multiple integer underflows in the (1) AES and (2) RC4 decryption functionality in the crypto library in MIT Kerberos 5 (aka krb5) 1.3 through 1.6.3, and 1.7 before 1.7.1, allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code by providing ciphertext with a length that is too short to be valid.
	</description>
 </metadata>
<!-- f95c0cbef4a252636c67dd8d77f705f6 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009057338" comment="krb5-32bit less than 1.6.3-133.26.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057341" comment="krb5-client less than 1.6.3-133.26.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057344" comment="krb5 less than 1.6.3-133.26.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094270" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4270</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2009-4270" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4270" source="CVE"/>
	<description>
	Stack-based buffer overflow in the errprintf function in base/gsmisc.c in ghostscript 8.64 through 8.70 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF file, as originally reported for debug logging code in gdevcups.c in the CUPS output driver.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 050a560119b003b7f093735ee4ea36d0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061853" comment="ghostscript-fonts-other less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061854" comment="ghostscript-fonts-rus less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061855" comment="ghostscript-fonts-std less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061856" comment="ghostscript-library less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061857" comment="ghostscript-omni less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061858" comment="ghostscript-x11 less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061859" comment="libgimpprint less than 4.2.7-32.28.1"/>
		</criteria>
	</criteria>
	<!-- 8ea47e7a8ca134ad54f518d9ea69e5c0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061860" comment="ghostscript-fonts-other less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061861" comment="ghostscript-fonts-rus less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061862" comment="ghostscript-fonts-std less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061863" comment="ghostscript-library less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061864" comment="ghostscript-omni less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061865" comment="ghostscript-x11 less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061866" comment="libgimpprint less than 4.2.7-32.27.26.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094274" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4274</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4274" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4274" source="CVE"/>
	<description>
	Stack-based buffer overflow in converter/ppm/xpmtoppm.c in netpbm before 10.47.07 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an XPM image file that contains a crafted header field associated with a large color index value.
	</description>
 </metadata>
<!-- c3b02633962feb1c3a979a3952f16b56 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009058585" comment="libnetpbm10-32bit less than 10.26.44-101.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058587" comment="libnetpbm10 less than 10.26.44-101.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058588" comment="netpbm less than 10.26.44-101.9.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094307" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4307</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4307" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4307" source="CVE"/>
	<description>
	The ext4_fill_flex_info function in fs/ext4/super.c in the Linux kernel before 2.6.32-git6 allows user-assisted remote attackers to cause a denial of service (divide-by-zero error and panic) via a malformed ext4 filesystem containing a super block with a large FLEX_BG group size (aka s_log_groups_per_flex value).
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- e7c5f7ef7eeb152d788f9406d2374894 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057219" comment="kernel-pae-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057220" comment="kernel-pae-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057221" comment="kernel-pae less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057232" comment="kernel-xen-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057233" comment="kernel-xen-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057234" comment="kernel-xen less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e87c441668f87fa162f810ea0e06c3ba -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057232" comment="kernel-xen-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057233" comment="kernel-xen-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057234" comment="kernel-xen less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094308" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4308</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4308" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4308" source="CVE"/>
	<description>
	The ext4_decode_error function in fs/ext4/super.c in the ext4 filesystem in the Linux kernel before 2.6.32 allows user-assisted remote attackers to cause a denial of service (NULL pointer dereference), and possibly have unspecified other impact, via a crafted read-only filesystem that lacks a journal.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- e7c5f7ef7eeb152d788f9406d2374894 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057219" comment="kernel-pae-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057220" comment="kernel-pae-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057221" comment="kernel-pae less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057232" comment="kernel-xen-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057233" comment="kernel-xen-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057234" comment="kernel-xen less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e87c441668f87fa162f810ea0e06c3ba -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057232" comment="kernel-xen-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057233" comment="kernel-xen-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057234" comment="kernel-xen less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094324" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4324</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4324" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4324" source="CVE"/>
	<description>
	Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0e62c3af8b734325d297f36aa439e519 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057622" comment="acroread_ja less than 9.3-0.1.1"/>
	</criteria>
	<!-- 92cc3368337b3767a6a4451406360608 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057440" comment="acroread less than 9.3-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094355" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4355</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4355" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4355" source="CVE"/>
	<description>
	Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote attackers to cause a denial of service (memory consumption) via vectors that trigger incorrect calls to the CRYPTO_cleanup_all_ex_data function, as demonstrated by use of SSLv3 and PHP with the Apache HTTP Server, a related issue to CVE-2008-1678.
	</description>
 </metadata>
<!-- 1ae6c4e9639b98001a2ac448ab1ed302 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009057434" comment="libopenssl0_9_8-32bit less than 0.9.8h-30.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057436" comment="libopenssl0_9_8 less than 0.9.8h-30.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057438" comment="openssl less than 0.9.8h-30.18.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094376" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4376</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4376" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4376" source="CVE"/>
	<description>
	Buffer overflow in the daintree_sna_read function in the Daintree SNA file parser in Wireshark 1.2.0 through 1.2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet.
	</description>
 </metadata>
<!-- 963ff40259d4863a011be226650534cb -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058844" comment="wireshark less than 1.0.5-1.34.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094377" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4377</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4377" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4377" source="CVE"/>
	<description>
	The (1) SMB and (2) SMB2 dissectors in Wireshark 0.9.0 through 1.2.4 allow remote attackers to cause a denial of service (crash) via a crafted packet that triggers a NULL pointer dereference, as demonstrated by fuzz-2009-12-07-11141.pcap.
	</description>
 </metadata>
<!-- 963ff40259d4863a011be226650534cb -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058844" comment="wireshark less than 1.0.5-1.34.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094411" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4411</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4411" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4411" source="CVE"/>
	<description>
	The (1) setfacl and (2) getfacl commands in XFS acl 2.2.47, when running in recursive (-R) mode, follow symbolic links even when the --physical (aka -P) or -L option is specified, which might allow local users to modify the ACL for arbitrary files or directories via a symlink attack.
	</description>
 </metadata>
<!-- fef3a822e18985ac5eff08598984741e -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009057533" comment="acl less than 2.2.47-30.5.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057534" comment="libacl-32bit less than 2.2.47-30.5.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057536" comment="libacl less than 2.2.47-30.5.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094492" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4492</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2009-4492" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4492" source="CVE"/>
	<description>
	WEBrick 1.3.1 in Ruby 1.8.6 through patchlevel 383, 1.8.7 through patchlevel 248, 1.8.8dev, 1.9.1 through patchlevel 376, and 1.9.2dev writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.
	</description>
 </metadata>
<!-- 5087d31530e2994f4eda91fda3425c12 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009068619" comment="ruby less than 1.8.7.p72-5.28.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094536" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4536</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4536" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4536" source="CVE"/>
	<description>
	drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel 2.6.32.3 and earlier handles Ethernet frames that exceed the MTU by processing certain trailing payload data as if it were a complete frame, which allows remote attackers to bypass packet filters via a large packet with a crafted payload.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2009-1385.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5bc8b282021bec5a0602dd1e1fb86cc0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058512" comment="kernel-default-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058513" comment="kernel-xen-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 8de370e0ec03088da9aa16f31064b5c4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058512" comment="kernel-default-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058501" comment="kernel-pae-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058515" comment="kernel-pae-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058502" comment="kernel-pae less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058513" comment="kernel-xen-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e7c5f7ef7eeb152d788f9406d2374894 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057219" comment="kernel-pae-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057220" comment="kernel-pae-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057221" comment="kernel-pae less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057232" comment="kernel-xen-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057233" comment="kernel-xen-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057234" comment="kernel-xen less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e87c441668f87fa162f810ea0e06c3ba -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057232" comment="kernel-xen-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057233" comment="kernel-xen-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057234" comment="kernel-xen less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094537" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4537</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4537" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4537" source="CVE"/>
	<description>
	drivers/net/r8169.c in the r8169 driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to (1) cause a denial of service (temporary network outage) via a packet with a crafted size, in conjunction with certain packets containing A characters and certain packets containing E characters; or (2) cause a denial of service (system crash) via a packet with a crafted size, in conjunction with certain packets containing '\0' characters, related to the value of the status register and erroneous behavior associated with the RxMaxSize register.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2009-1389.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 66504af0afe753b5175112b44bc8827d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061675" comment="kernel-default-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061679" comment="kernel-pae-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061680" comment="kernel-pae-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061681" comment="kernel-pae less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061693" comment="kernel-xen-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- c8a29eec659b0b2b3e85c610b67beacd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061675" comment="kernel-default-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061693" comment="kernel-xen-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094538" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4538</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4538" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4538" source="CVE"/>
	<description>
	drivers/net/e1000e/netdev.c in the e1000e driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to have an unspecified impact via crafted packets, a related issue to CVE-2009-4537.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5bc8b282021bec5a0602dd1e1fb86cc0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058512" comment="kernel-default-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058513" comment="kernel-xen-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 8de370e0ec03088da9aa16f31064b5c4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058512" comment="kernel-default-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058501" comment="kernel-pae-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058515" comment="kernel-pae-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058502" comment="kernel-pae less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058513" comment="kernel-xen-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e7c5f7ef7eeb152d788f9406d2374894 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057219" comment="kernel-pae-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057220" comment="kernel-pae-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057221" comment="kernel-pae less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057232" comment="kernel-xen-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057233" comment="kernel-xen-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057234" comment="kernel-xen less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e87c441668f87fa162f810ea0e06c3ba -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057232" comment="kernel-xen-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057233" comment="kernel-xen-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057234" comment="kernel-xen less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094835" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4835</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2009-4835" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4835" source="CVE"/>
	<description>
	The (1) htk_read_header, (2) alaw_init, (3) ulaw_init, (4) pcm_init, (5) float32_init, and (6) sds_read_header functions in libsndfile 1.0.20 allow context-dependent attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted audio file.
	</description>
 </metadata>
<!-- 2e050f9ffe143c431af2f12cbf7a3a42 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009069631" comment="libsndfile-32bit less than 1.0.20-2.4.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009069633" comment="libsndfile less than 1.0.20-2.4.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094895" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4895</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4895" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4895" source="CVE"/>
	<description>
	Race condition in the tty_fasync function in drivers/char/tty_io.c in the Linux kernel before 2.6.32.6 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via unknown vectors, related to the put_tty_queue and __f_setown functions.  NOTE: the vulnerability was addressed in a different way in 2.6.32.9.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 66504af0afe753b5175112b44bc8827d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061675" comment="kernel-default-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061679" comment="kernel-pae-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061680" comment="kernel-pae-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061681" comment="kernel-pae less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061693" comment="kernel-xen-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- c8a29eec659b0b2b3e85c610b67beacd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061675" comment="kernel-default-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061693" comment="kernel-xen-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094897" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4897</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2009-4897" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4897" source="CVE"/>
	<description>
	Buffer overflow in gs/psi/iscan.c in Ghostscript 8.64 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document containing a long name.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 050a560119b003b7f093735ee4ea36d0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061853" comment="ghostscript-fonts-other less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061854" comment="ghostscript-fonts-rus less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061855" comment="ghostscript-fonts-std less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061856" comment="ghostscript-library less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061857" comment="ghostscript-omni less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061858" comment="ghostscript-x11 less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061859" comment="libgimpprint less than 4.2.7-32.28.1"/>
		</criteria>
	</criteria>
	<!-- 8ea47e7a8ca134ad54f518d9ea69e5c0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061860" comment="ghostscript-fonts-other less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061861" comment="ghostscript-fonts-rus less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061862" comment="ghostscript-fonts-std less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061863" comment="ghostscript-library less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061864" comment="ghostscript-omni less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061865" comment="ghostscript-x11 less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061866" comment="libgimpprint less than 4.2.7-32.27.26.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20095063" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-5063</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2009-5063" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-5063" source="CVE"/>
	<description>
	Memory leak in pngwutil.c in libpng before 1.2.39beta5 allows context-dependent attackers to cause a denial of service (memory leak or segmentation fault) via a JPEG image containing an iCCP chunk with a negative embedded profile length.  NOTE: this is due to an incomplete fix for CVE-2006-7244.
	</description>
 </metadata>
<!-- 5b292f48bbbe6202317380a339315fad -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009069826" comment="libpng-devel less than 1.2.31-5.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009069805" comment="libpng12-0-32bit less than 1.2.31-5.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009069807" comment="libpng12-0 less than 1.2.31-5.25.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100001" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0001</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0001" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0001" source="CVE"/>
	<description>
	Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit platforms, as used in ncompress and probably others, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted archive that uses LZW compression, leading to an array index error.
	</description>
 </metadata>
<!-- 8388a149c9d32703af6f0ac8782851c4 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057426" comment="gzip less than 1.3.12-69.19.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100003" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0003</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0003" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0003" source="CVE"/>
	<description>
	The print_fatal_signal function in kernel/signal.c in the Linux kernel before 2.6.32.4 on the i386 platform, when print-fatal-signals is enabled, allows local users to discover the contents of arbitrary memory locations by jumping to an address and then reading a log file, and might allow local users to cause a denial of service (system slowdown or crash) by jumping to an address.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5bc8b282021bec5a0602dd1e1fb86cc0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058512" comment="kernel-default-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058513" comment="kernel-xen-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 8de370e0ec03088da9aa16f31064b5c4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058512" comment="kernel-default-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058501" comment="kernel-pae-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058515" comment="kernel-pae-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058502" comment="kernel-pae less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058513" comment="kernel-xen-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100007" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0007</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0007" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0007" source="CVE"/>
	<description>
	net/bridge/netfilter/ebtables.c in the ebtables module in the netfilter framework in the Linux kernel before 2.6.33-rc4 does not require the CAP_NET_ADMIN capability for setting or modifying rules, which allows local users to bypass intended access restrictions and configure arbitrary network-traffic filtering via a modified ebtables application.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5bc8b282021bec5a0602dd1e1fb86cc0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058512" comment="kernel-default-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058513" comment="kernel-xen-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 8de370e0ec03088da9aa16f31064b5c4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058512" comment="kernel-default-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058501" comment="kernel-pae-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058515" comment="kernel-pae-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058502" comment="kernel-pae less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058513" comment="kernel-xen-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100013" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0013</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0013" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0013" source="CVE"/>
	<description>
	Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in an application/x-msnmsgrp2p MSN emoticon (aka custom smiley) request, a related issue to CVE-2004-0122.  NOTE: it could be argued that this is resultant from a vulnerability in which an emoticon download request is processed even without a preceding text/x-mms-emoticon message that announced availability of the emoticon.
	</description>
 </metadata>
<!-- 885d32a2218fb0167f44eafd37c33a26 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009058533" comment="finch less than 2.6.6-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058535" comment="libpurple-lang less than 2.6.6-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058536" comment="libpurple less than 2.6.6-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058538" comment="pidgin less than 2.6.6-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100015" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0015</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-0015" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0015" source="CVE"/>
	<description>
	nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords of NIS accounts by calling the getpwnam function.
	</description>
 </metadata>
<!-- 6015df6da5266bf10b03367cfb25b171 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009069098" comment="glibc-32bit less than 2.11.1-0.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009069099" comment="glibc-devel-32bit less than 2.11.1-0.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009069100" comment="glibc-devel less than 2.11.1-0.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009069102" comment="glibc-i18ndata less than 2.11.1-0.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009069104" comment="glibc-locale-32bit less than 2.11.1-0.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009069106" comment="glibc-locale less than 2.11.1-0.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009069111" comment="glibc less than 2.11.1-0.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009069112" comment="nscd less than 2.11.1-0.30.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100082" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0082</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0082" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0082" source="CVE"/>
	<description>
	Unspecified vulnerability in the HotSpot Server component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
	</description>
 </metadata>
<!-- 33752f926ef7d4dfa0db31b1c685e810 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059302" comment="java-1_6_0-sun-alsa less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059303" comment="java-1_6_0-sun-demo less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059305" comment="java-1_6_0-sun-jdbc less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059306" comment="java-1_6_0-sun-plugin less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059307" comment="java-1_6_0-sun-src less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059308" comment="java-1_6_0-sun less than 1.6.0.u19-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100084" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0084</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0084" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0084" source="CVE"/>
	<description>
	Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality via unknown vectors.
	</description>
 </metadata>
<!-- 33752f926ef7d4dfa0db31b1c685e810 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059302" comment="java-1_6_0-sun-alsa less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059303" comment="java-1_6_0-sun-demo less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059305" comment="java-1_6_0-sun-jdbc less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059306" comment="java-1_6_0-sun-plugin less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059307" comment="java-1_6_0-sun-src less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059308" comment="java-1_6_0-sun less than 1.6.0.u19-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100085" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0085</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0085" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0085" source="CVE"/>
	<description>
	Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
	</description>
 </metadata>
<!-- 33752f926ef7d4dfa0db31b1c685e810 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059302" comment="java-1_6_0-sun-alsa less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059303" comment="java-1_6_0-sun-demo less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059305" comment="java-1_6_0-sun-jdbc less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059306" comment="java-1_6_0-sun-plugin less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059307" comment="java-1_6_0-sun-src less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059308" comment="java-1_6_0-sun less than 1.6.0.u19-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100087" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0087</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0087" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0087" source="CVE"/>
	<description>
	Unspecified vulnerability in the Java Web Start, Java Plug-in component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
	</description>
 </metadata>
<!-- 33752f926ef7d4dfa0db31b1c685e810 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059302" comment="java-1_6_0-sun-alsa less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059303" comment="java-1_6_0-sun-demo less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059305" comment="java-1_6_0-sun-jdbc less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059306" comment="java-1_6_0-sun-plugin less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059307" comment="java-1_6_0-sun-src less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059308" comment="java-1_6_0-sun less than 1.6.0.u19-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100088" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0088</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0088" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0088" source="CVE"/>
	<description>
	Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
	</description>
 </metadata>
<!-- 33752f926ef7d4dfa0db31b1c685e810 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059302" comment="java-1_6_0-sun-alsa less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059303" comment="java-1_6_0-sun-demo less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059305" comment="java-1_6_0-sun-jdbc less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059306" comment="java-1_6_0-sun-plugin less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059307" comment="java-1_6_0-sun-src less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059308" comment="java-1_6_0-sun less than 1.6.0.u19-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100089" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0089</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0089" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0089" source="CVE"/>
	<description>
	Unspecified vulnerability in the Java Web Start, Java Plug-in component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect availability via unknown vectors.
	</description>
 </metadata>
<!-- 33752f926ef7d4dfa0db31b1c685e810 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059302" comment="java-1_6_0-sun-alsa less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059303" comment="java-1_6_0-sun-demo less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059305" comment="java-1_6_0-sun-jdbc less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059306" comment="java-1_6_0-sun-plugin less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059307" comment="java-1_6_0-sun-src less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059308" comment="java-1_6_0-sun less than 1.6.0.u19-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100090" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0090</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0090" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0090" source="CVE"/>
	<description>
	Unspecified vulnerability in the Java Web Start, Java Plug-in component in Oracle Java SE and Java for Business 6 Update 18 allows remote attackers to affect integrity and availability via unknown vectors.
	</description>
 </metadata>
<!-- 33752f926ef7d4dfa0db31b1c685e810 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059302" comment="java-1_6_0-sun-alsa less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059303" comment="java-1_6_0-sun-demo less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059305" comment="java-1_6_0-sun-jdbc less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059306" comment="java-1_6_0-sun-plugin less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059307" comment="java-1_6_0-sun-src less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059308" comment="java-1_6_0-sun less than 1.6.0.u19-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100091" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0091</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0091" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0091" source="CVE"/>
	<description>
	Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality via unknown vectors.
	</description>
 </metadata>
<!-- 33752f926ef7d4dfa0db31b1c685e810 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059302" comment="java-1_6_0-sun-alsa less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059303" comment="java-1_6_0-sun-demo less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059305" comment="java-1_6_0-sun-jdbc less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059306" comment="java-1_6_0-sun-plugin less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059307" comment="java-1_6_0-sun-src less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059308" comment="java-1_6_0-sun less than 1.6.0.u19-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100092" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0092</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0092" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0092" source="CVE"/>
	<description>
	Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, and 5.0 Update 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
	</description>
 </metadata>
<!-- 33752f926ef7d4dfa0db31b1c685e810 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059302" comment="java-1_6_0-sun-alsa less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059303" comment="java-1_6_0-sun-demo less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059305" comment="java-1_6_0-sun-jdbc less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059306" comment="java-1_6_0-sun-plugin less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059307" comment="java-1_6_0-sun-src less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059308" comment="java-1_6_0-sun less than 1.6.0.u19-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100093" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0093</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0093" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0093" source="CVE"/>
	<description>
	Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
	</description>
 </metadata>
<!-- 33752f926ef7d4dfa0db31b1c685e810 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059302" comment="java-1_6_0-sun-alsa less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059303" comment="java-1_6_0-sun-demo less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059305" comment="java-1_6_0-sun-jdbc less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059306" comment="java-1_6_0-sun-plugin less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059307" comment="java-1_6_0-sun-src less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059308" comment="java-1_6_0-sun less than 1.6.0.u19-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100094" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0094</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0094" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0094" source="CVE"/>
	<description>
	Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18 and 5.0 Update 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is due to missing privilege checks during deserialization of RMIConnectionImpl objects, which allows remote attackers to call system-level Java functions via the ClassLoader of a constructor that is being deserialized.
	</description>
 </metadata>
<!-- 33752f926ef7d4dfa0db31b1c685e810 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059302" comment="java-1_6_0-sun-alsa less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059303" comment="java-1_6_0-sun-demo less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059305" comment="java-1_6_0-sun-jdbc less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059306" comment="java-1_6_0-sun-plugin less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059307" comment="java-1_6_0-sun-src less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059308" comment="java-1_6_0-sun less than 1.6.0.u19-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100095" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0095</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0095" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0095" source="CVE"/>
	<description>
	Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
	</description>
 </metadata>
<!-- 33752f926ef7d4dfa0db31b1c685e810 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059302" comment="java-1_6_0-sun-alsa less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059303" comment="java-1_6_0-sun-demo less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059305" comment="java-1_6_0-sun-jdbc less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059306" comment="java-1_6_0-sun-plugin less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059307" comment="java-1_6_0-sun-src less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059308" comment="java-1_6_0-sun less than 1.6.0.u19-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100097" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0097</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0097" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0097" source="CVE"/>
	<description>
	ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged NXDOMAIN response for an existing domain.
	</description>
 </metadata>
<!-- 440b3d1daa2c9fed4b99f7865ea3a906 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009057429" comment="bind-libs-32bit less than 9.5.0P2-20.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057431" comment="bind-libs less than 9.5.0P2-20.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057432" comment="bind-utils less than 9.5.0P2-20.7.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100136" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0136</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0136" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0136" source="CVE"/>
	<description>
	OpenOffice.org (OOo) 2.0.4, 2.4.1, and 3.1.1 does not properly enforce Visual Basic for Applications (VBA) macro security settings, which allows remote attackers to run arbitrary macros via a crafted document.
	</description>
 </metadata>
<!-- b3f5b1e481a1ae74918748c80997e6c7 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009058823" comment="OpenOffice_org-LanguageTool-de less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058824" comment="OpenOffice_org-LanguageTool-en less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058825" comment="OpenOffice_org-LanguageTool-es less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058826" comment="OpenOffice_org-LanguageTool-fr less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058827" comment="OpenOffice_org-LanguageTool-it less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058828" comment="OpenOffice_org-LanguageTool-nl less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058829" comment="OpenOffice_org-LanguageTool-pl less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058830" comment="OpenOffice_org-LanguageTool-sv less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058831" comment="OpenOffice_org-LanguageTool less than 1.0.0-1.1.6"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058832" comment="OpenOffice_org-base-drivers-postgresql less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058833" comment="OpenOffice_org-base-extensions less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058741" comment="OpenOffice_org-base less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058834" comment="OpenOffice_org-calc-extensions less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058744" comment="OpenOffice_org-calc less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058746" comment="OpenOffice_org-components less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058835" comment="OpenOffice_org-draw-extensions less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058747" comment="OpenOffice_org-draw less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058749" comment="OpenOffice_org-filters-optional less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058750" comment="OpenOffice_org-filters less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058751" comment="OpenOffice_org-gnome less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058752" comment="OpenOffice_org-help-ar less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058753" comment="OpenOffice_org-help-cs less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058754" comment="OpenOffice_org-help-da less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058755" comment="OpenOffice_org-help-de less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058756" comment="OpenOffice_org-help-en-GB less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058757" comment="OpenOffice_org-help-en-US-devel less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058758" comment="OpenOffice_org-help-en-US less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058759" comment="OpenOffice_org-help-es less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058760" comment="OpenOffice_org-help-fr less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058836" comment="OpenOffice_org-help-gu-IN less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058837" comment="OpenOffice_org-help-hi-IN less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058761" comment="OpenOffice_org-help-hu less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058762" comment="OpenOffice_org-help-it less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058763" comment="OpenOffice_org-help-ja less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058838" comment="OpenOffice_org-help-ko less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058764" comment="OpenOffice_org-help-nl less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058765" comment="OpenOffice_org-help-pl less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058766" comment="OpenOffice_org-help-pt-BR less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058767" comment="OpenOffice_org-help-pt less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058768" comment="OpenOffice_org-help-ru less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058769" comment="OpenOffice_org-help-sv less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058770" comment="OpenOffice_org-help-zh-CN less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058771" comment="OpenOffice_org-help-zh-TW less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058772" comment="OpenOffice_org-icon-themes less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058839" comment="OpenOffice_org-impress-extensions less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058774" comment="OpenOffice_org-impress less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058775" comment="OpenOffice_org-kde less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058776" comment="OpenOffice_org-l10n-af less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058777" comment="OpenOffice_org-l10n-ar less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058778" comment="OpenOffice_org-l10n-ca less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058779" comment="OpenOffice_org-l10n-cs less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058780" comment="OpenOffice_org-l10n-da less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058781" comment="OpenOffice_org-l10n-de less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058782" comment="OpenOffice_org-l10n-el less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058783" comment="OpenOffice_org-l10n-en-GB less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058784" comment="OpenOffice_org-l10n-es less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058786" comment="OpenOffice_org-l10n-extras less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058787" comment="OpenOffice_org-l10n-fi less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058788" comment="OpenOffice_org-l10n-fr less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058840" comment="OpenOffice_org-l10n-gu-IN less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058841" comment="OpenOffice_org-l10n-hi-IN less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058789" comment="OpenOffice_org-l10n-hu less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058790" comment="OpenOffice_org-l10n-it less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058791" comment="OpenOffice_org-l10n-ja less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058842" comment="OpenOffice_org-l10n-ko less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058792" comment="OpenOffice_org-l10n-nb less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058793" comment="OpenOffice_org-l10n-nl less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058794" comment="OpenOffice_org-l10n-nn less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058795" comment="OpenOffice_org-l10n-pl less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058796" comment="OpenOffice_org-l10n-pt-BR less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058797" comment="OpenOffice_org-l10n-pt less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058798" comment="OpenOffice_org-l10n-ru less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058799" comment="OpenOffice_org-l10n-sk less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058800" comment="OpenOffice_org-l10n-sv less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058801" comment="OpenOffice_org-l10n-xh less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058802" comment="OpenOffice_org-l10n-zh-CN less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058803" comment="OpenOffice_org-l10n-zh-TW less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058804" comment="OpenOffice_org-l10n-zu less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058806" comment="OpenOffice_org-libs-core less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058808" comment="OpenOffice_org-libs-extern less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058810" comment="OpenOffice_org-libs-gui less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058811" comment="OpenOffice_org-mailmerge less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058812" comment="OpenOffice_org-math less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058813" comment="OpenOffice_org-mono less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058814" comment="OpenOffice_org-officebean less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058815" comment="OpenOffice_org-openclipart less than 3-1.25.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058816" comment="OpenOffice_org-pyuno less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058819" comment="OpenOffice_org-ure less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058843" comment="OpenOffice_org-writer-extensions less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058821" comment="OpenOffice_org-writer less than 3.2.0.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058822" comment="OpenOffice_org less than 3.2.0.7-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100156" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0156</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0156" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0156" source="CVE"/>
	<description>
	Puppet 0.24.x before 0.24.9 and 0.25.x before 0.25.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/daemonout, (2) /tmp/puppetdoc.txt, (3) /tmp/puppetdoc.tex, or (4) /tmp/puppetdoc.aux temporary file.
	</description>
 </metadata>
<!-- 79091fa279f2a9833e22da9ea3f83d3a -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060820" comment="puppet less than 0.24.5-5.7.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100159" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0159</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0159" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0159" source="CVE"/>
	<description>
	The browser engine in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the nsBlockFrame::StealFrame function in layout/generic/nsBlockFrame.cpp, and unspecified other vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5c9ba6a33f35e3ab788cbbefde6cf8a6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058351" comment="MozillaFirefox-translations less than 3.5.8-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058352" comment="MozillaFirefox less than 3.5.8-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058353" comment="mozilla-xulrunner191-32bit less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058436" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058354" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058438" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058355" comment="mozilla-xulrunner191-translations less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058357" comment="mozilla-xulrunner191 less than 1.9.1.8-1.1.1"/>
		</criteria>
	</criteria>
	<!-- deb36b8154e27ded345f064786253ca1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058358" comment="mozilla-xulrunner190-32bit less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058432" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058359" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058433" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058360" comment="mozilla-xulrunner190-translations less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058362" comment="mozilla-xulrunner190 less than 1.9.0.18-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100160" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0160</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0160" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0160" source="CVE"/>
	<description>
	The Web Worker functionality in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly handle array data types for posted messages, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5c9ba6a33f35e3ab788cbbefde6cf8a6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058351" comment="MozillaFirefox-translations less than 3.5.8-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058352" comment="MozillaFirefox less than 3.5.8-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058353" comment="mozilla-xulrunner191-32bit less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058436" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058354" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058438" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058355" comment="mozilla-xulrunner191-translations less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058357" comment="mozilla-xulrunner191 less than 1.9.1.8-1.1.1"/>
		</criteria>
	</criteria>
	<!-- deb36b8154e27ded345f064786253ca1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058358" comment="mozilla-xulrunner190-32bit less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058432" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058359" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058433" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058360" comment="mozilla-xulrunner190-translations less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058362" comment="mozilla-xulrunner190 less than 1.9.0.18-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100161" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0161</title>
	<affected family="unix">
		<platform>SLE 11 DESKTOP Unsupported Extras</platform>
	</affected>
	<reference ref_id="CVE-2010-0161" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0161" source="CVE"/>
	<description>
	The nsAuthSSPI::Unwrap function in extensions/auth/nsAuthSSPI.cpp in Mozilla Thunderbird before 2.0.0.24 and SeaMonkey before 1.1.19 on Windows Vista, Windows Server 2008 R2, and Windows 7 allows remote SMTP, IMAP, and POP servers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via crafted data in a session that uses SSPI.
	</description>
 </metadata>
<!-- f2377272fe27726ada5a22ead971d6aa -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11-extra is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059215" comment="MozillaThunderbird-translations less than 2.0.0.24-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059216" comment="MozillaThunderbird less than 2.0.0.24-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100162" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0162</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0162" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0162" source="CVE"/>
	<description>
	Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly support the application/octet-stream content type as a protection mechanism against execution of web script in certain circumstances involving SVG and the EMBED element, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via an embedded SVG document.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5c9ba6a33f35e3ab788cbbefde6cf8a6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058351" comment="MozillaFirefox-translations less than 3.5.8-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058352" comment="MozillaFirefox less than 3.5.8-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058353" comment="mozilla-xulrunner191-32bit less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058436" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058354" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058438" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058355" comment="mozilla-xulrunner191-translations less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058357" comment="mozilla-xulrunner191 less than 1.9.1.8-1.1.1"/>
		</criteria>
	</criteria>
	<!-- deb36b8154e27ded345f064786253ca1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058358" comment="mozilla-xulrunner190-32bit less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058432" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058359" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058433" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058360" comment="mozilla-xulrunner190-translations less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058362" comment="mozilla-xulrunner190 less than 1.9.0.18-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100163" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0163</title>
	<affected family="unix">
		<platform>SLE 11 DESKTOP Unsupported Extras</platform>
	</affected>
	<reference ref_id="CVE-2010-0163" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0163" source="CVE"/>
	<description>
	Mozilla Thunderbird before 2.0.0.24 and SeaMonkey before 1.1.19 process e-mail attachments with a parser that performs casts and line termination incorrectly, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted message, related to message indexing.
	</description>
 </metadata>
<!-- f2377272fe27726ada5a22ead971d6aa -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11-extra is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059215" comment="MozillaThunderbird-translations less than 2.0.0.24-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059216" comment="MozillaThunderbird less than 2.0.0.24-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100173" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0173</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0173" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0173" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8ead451f2aa5a3390fe43fc3d4eff649 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059477" comment="mozilla-xulrunner190-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059496" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059478" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059498" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059479" comment="mozilla-xulrunner190-translations less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059481" comment="mozilla-xulrunner190 less than 1.9.0.19-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e687f5d3988822ee23e0bd97566703f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059482" comment="MozillaFirefox-translations less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059483" comment="MozillaFirefox less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059484" comment="mozilla-xulrunner191-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059501" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059485" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059503" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059486" comment="mozilla-xulrunner191-translations less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059488" comment="mozilla-xulrunner191 less than 1.9.1.9-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100174" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0174</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0174" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0174" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4; and SeaMonkey before 2.0.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8ead451f2aa5a3390fe43fc3d4eff649 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059477" comment="mozilla-xulrunner190-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059496" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059478" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059498" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059479" comment="mozilla-xulrunner190-translations less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059481" comment="mozilla-xulrunner190 less than 1.9.0.19-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e687f5d3988822ee23e0bd97566703f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059482" comment="MozillaFirefox-translations less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059483" comment="MozillaFirefox less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059484" comment="mozilla-xulrunner191-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059501" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059485" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059503" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059486" comment="mozilla-xulrunner191-translations less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059488" comment="mozilla-xulrunner191 less than 1.9.1.9-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100175" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0175</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0175" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0175" source="CVE"/>
	<description>
	Use-after-free vulnerability in the nsTreeSelection implementation in Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.9, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors that trigger a call to the handler for the select event for XUL tree items.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8ead451f2aa5a3390fe43fc3d4eff649 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059477" comment="mozilla-xulrunner190-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059496" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059478" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059498" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059479" comment="mozilla-xulrunner190-translations less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059481" comment="mozilla-xulrunner190 less than 1.9.0.19-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e687f5d3988822ee23e0bd97566703f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059482" comment="MozillaFirefox-translations less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059483" comment="MozillaFirefox less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059484" comment="mozilla-xulrunner191-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059501" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059485" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059503" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059486" comment="mozilla-xulrunner191-translations less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059488" comment="mozilla-xulrunner191 less than 1.9.1.9-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100176" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0176</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0176" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0176" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4; and SeaMonkey before 2.0.4 do not properly manage reference counts for option elements in a XUL tree optgroup, which might allow remote attackers to execute arbitrary code via unspecified vectors that trigger access to deleted elements, related to a "dangling pointer vulnerability."
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8ead451f2aa5a3390fe43fc3d4eff649 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059477" comment="mozilla-xulrunner190-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059496" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059478" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059498" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059479" comment="mozilla-xulrunner190-translations less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059481" comment="mozilla-xulrunner190 less than 1.9.0.19-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e687f5d3988822ee23e0bd97566703f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059482" comment="MozillaFirefox-translations less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059483" comment="MozillaFirefox less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059484" comment="mozilla-xulrunner191-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059501" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059485" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059503" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059486" comment="mozilla-xulrunner191-translations less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059488" comment="mozilla-xulrunner191 less than 1.9.1.9-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100177" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0177</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0177" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0177" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, frees the contents of the window.navigator.plugins array while a reference to an array element is still active, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors, related to a "dangling pointer vulnerability."
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8ead451f2aa5a3390fe43fc3d4eff649 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059477" comment="mozilla-xulrunner190-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059496" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059478" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059498" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059479" comment="mozilla-xulrunner190-translations less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059481" comment="mozilla-xulrunner190 less than 1.9.0.19-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e687f5d3988822ee23e0bd97566703f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059482" comment="MozillaFirefox-translations less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059483" comment="MozillaFirefox less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059484" comment="mozilla-xulrunner191-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059501" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059485" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059503" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059486" comment="mozilla-xulrunner191-translations less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059488" comment="mozilla-xulrunner191 less than 1.9.1.9-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100178" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0178</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0178" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0178" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, does not prevent applets from interpreting mouse clicks as drag-and-drop actions, which allows remote attackers to execute arbitrary JavaScript with Chrome privileges by loading a chrome: URL and then loading a javascript: URL.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8ead451f2aa5a3390fe43fc3d4eff649 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059477" comment="mozilla-xulrunner190-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059496" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059478" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059498" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059479" comment="mozilla-xulrunner190-translations less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059481" comment="mozilla-xulrunner190 less than 1.9.0.19-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e687f5d3988822ee23e0bd97566703f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059482" comment="MozillaFirefox-translations less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059483" comment="MozillaFirefox less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059484" comment="mozilla-xulrunner191-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059501" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059485" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059503" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059486" comment="mozilla-xulrunner191-translations less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059488" comment="mozilla-xulrunner191 less than 1.9.1.9-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100179" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0179</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-0179" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0179" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, when the XMLHttpRequestSpy module in the Firebug add-on is used, does not properly handle interaction between the XMLHttpRequestSpy object and chrome privileged objects, which allows remote attackers to execute arbitrary JavaScript via a crafted HTTP response.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 60c97a6dd73ffa7ac423d55d993471d0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009065329" comment="MozillaFirefox-translations less than 3.6.13-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065330" comment="MozillaFirefox less than 3.6.13-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065331" comment="mozilla-xulrunner192-32bit less than 1.9.2.13-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065403" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.13-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065332" comment="mozilla-xulrunner192-gnome less than 1.9.2.13-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065405" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.13-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065333" comment="mozilla-xulrunner192-translations less than 1.9.2.13-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065335" comment="mozilla-xulrunner192 less than 1.9.2.13-1.7.1"/>
		</criteria>
	</criteria>
	<!-- 8ead451f2aa5a3390fe43fc3d4eff649 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059477" comment="mozilla-xulrunner190-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059496" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059478" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059498" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059479" comment="mozilla-xulrunner190-translations less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059481" comment="mozilla-xulrunner190 less than 1.9.0.19-0.1.1"/>
		</criteria>
	</criteria>
	<!-- b2953cad2a3b3bd6c26f1ac2807a1556 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009065250" comment="mozilla-xulrunner191-32bit less than 1.9.1.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065252" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065253" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065419" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065336" comment="mozilla-xulrunner191-translations less than 1.9.1.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065256" comment="mozilla-xulrunner191 less than 1.9.1.16-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e687f5d3988822ee23e0bd97566703f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059482" comment="MozillaFirefox-translations less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059483" comment="MozillaFirefox less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059484" comment="mozilla-xulrunner191-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059501" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059485" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059503" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059486" comment="mozilla-xulrunner191-translations less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059488" comment="mozilla-xulrunner191 less than 1.9.1.9-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100181" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0181</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0181" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0181" source="CVE"/>
	<description>
	Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, executes a mail application in situations where an IMG element has a SRC attribute that is a redirect to a mailto: URL, which allows remote attackers to cause a denial of service (excessive application launches) via an HTML document with many images.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8ead451f2aa5a3390fe43fc3d4eff649 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059477" comment="mozilla-xulrunner190-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059496" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059478" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059498" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059479" comment="mozilla-xulrunner190-translations less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059481" comment="mozilla-xulrunner190 less than 1.9.0.19-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e687f5d3988822ee23e0bd97566703f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059482" comment="MozillaFirefox-translations less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059483" comment="MozillaFirefox less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059484" comment="mozilla-xulrunner191-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059501" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059485" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059503" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059486" comment="mozilla-xulrunner191-translations less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059488" comment="mozilla-xulrunner191 less than 1.9.1.9-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100182" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0182</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0182" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0182" source="CVE"/>
	<description>
	The XMLDocument::load function in Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 does not perform the expected nsIContentPolicy checks during loading of content by XML documents, which allows attackers to bypass intended access restrictions via crafted content.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8ead451f2aa5a3390fe43fc3d4eff649 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059477" comment="mozilla-xulrunner190-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059496" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059478" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059498" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059479" comment="mozilla-xulrunner190-translations less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059481" comment="mozilla-xulrunner190 less than 1.9.0.19-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e687f5d3988822ee23e0bd97566703f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059482" comment="MozillaFirefox-translations less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059483" comment="MozillaFirefox less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059484" comment="mozilla-xulrunner191-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059501" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059485" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059503" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059486" comment="mozilla-xulrunner191-translations less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059488" comment="mozilla-xulrunner191 less than 1.9.1.9-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100183" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0183</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-0183" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0183" source="CVE"/>
	<description>
	Use-after-free vulnerability in the nsCycleCollector::MarkRoots function in Mozilla Firefox 3.5.x before 3.5.10 and SeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code via a crafted HTML document, related to an improper frame construction process for menus.
	</description>
 </metadata>
<!-- f9b2b1aaa535612c1bff26161e7cb381 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009061668" comment="MozillaFirefox-translations less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061192" comment="MozillaFirefox less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070643" comment="mozilla-xulrunner191-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070716" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070644" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070718" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061669" comment="mozilla-xulrunner191-translations less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061670" comment="mozilla-xulrunner191 less than 1.9.1.10-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100186" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0186</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0186" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0186" source="CVE"/>
	<description>
	Cross-domain vulnerability in Adobe Flash Player before 10.0.45.2, Adobe AIR before 1.5.3.9130, and Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows remote attackers to bypass intended sandbox restrictions and make cross-domain requests via unspecified vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 422ef8d6967fd7ce3910d3d354f9af82 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058543" comment="acroread-cmaps less than 9.3.1-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058544" comment="acroread-fonts-ja less than 9.3.1-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058545" comment="acroread-fonts-ko less than 9.3.1-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058546" comment="acroread-fonts-zh_CN less than 9.3.1-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058547" comment="acroread-fonts-zh_TW less than 9.3.1-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058548" comment="acroread less than 9.3.1-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 91ad5f1e71d4dd39b9a6e918e0b7ad8f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057994" comment="flash-player less than 10.0.45.2-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100187" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0187</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0187" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0187" source="CVE"/>
	<description>
	Adobe Flash Player before 10.0.45.2 and Adobe AIR before 1.5.3.9130 allow remote attackers to cause a denial of service (application crash) via a modified SWF file.
	</description>
 </metadata>
<!-- 91ad5f1e71d4dd39b9a6e918e0b7ad8f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057994" comment="flash-player less than 10.0.45.2-0.1.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100188" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0188</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0188" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0188" source="CVE"/>
	<description>
	Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
<!-- 422ef8d6967fd7ce3910d3d354f9af82 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009058543" comment="acroread-cmaps less than 9.3.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058544" comment="acroread-fonts-ja less than 9.3.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058545" comment="acroread-fonts-ko less than 9.3.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058546" comment="acroread-fonts-zh_CN less than 9.3.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058547" comment="acroread-fonts-zh_TW less than 9.3.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058548" comment="acroread less than 9.3.1-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100190" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0190</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0190" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0190" source="CVE"/>
	<description>
	Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0e9154563fae0e1dd880d336e6cf63c0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059788" comment="acroread_ja less than 9.3.2-0.1.1"/>
	</criteria>
	<!-- b058bb7270eba0f7d737bff88e2592e4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059796" comment="acroread-cmaps less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059797" comment="acroread-fonts-ja less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059798" comment="acroread-fonts-ko less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059799" comment="acroread-fonts-zh_CN less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059800" comment="acroread-fonts-zh_TW less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059801" comment="acroread less than 9.3.2-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100191" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0191</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0191" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0191" source="CVE"/>
	<description>
	Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to execute arbitrary code via unspecified vectors, related to a "prefix protocol handler vulnerability."
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0e9154563fae0e1dd880d336e6cf63c0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059788" comment="acroread_ja less than 9.3.2-0.1.1"/>
	</criteria>
	<!-- b058bb7270eba0f7d737bff88e2592e4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059796" comment="acroread-cmaps less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059797" comment="acroread-fonts-ja less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059798" comment="acroread-fonts-ko less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059799" comment="acroread-fonts-zh_CN less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059800" comment="acroread-fonts-zh_TW less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059801" comment="acroread less than 9.3.2-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100192" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0192</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0192" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0192" source="CVE"/>
	<description>
	Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2010-0193 and CVE-2010-0196.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0e9154563fae0e1dd880d336e6cf63c0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059788" comment="acroread_ja less than 9.3.2-0.1.1"/>
	</criteria>
	<!-- b058bb7270eba0f7d737bff88e2592e4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059796" comment="acroread-cmaps less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059797" comment="acroread-fonts-ja less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059798" comment="acroread-fonts-ko less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059799" comment="acroread-fonts-zh_CN less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059800" comment="acroread-fonts-zh_TW less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059801" comment="acroread less than 9.3.2-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100193" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0193</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0193" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0193" source="CVE"/>
	<description>
	Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2010-0192 and CVE-2010-0196.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0e9154563fae0e1dd880d336e6cf63c0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059788" comment="acroread_ja less than 9.3.2-0.1.1"/>
	</criteria>
	<!-- b058bb7270eba0f7d737bff88e2592e4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059796" comment="acroread-cmaps less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059797" comment="acroread-fonts-ja less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059798" comment="acroread-fonts-ko less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059799" comment="acroread-fonts-zh_CN less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059800" comment="acroread-fonts-zh_TW less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059801" comment="acroread less than 9.3.2-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100194" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0194</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0194" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0194" source="CVE"/>
	<description>
	Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to cause a denial of service (memory corruption) or execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0197, CVE-2010-0201, and CVE-2010-0204.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0e9154563fae0e1dd880d336e6cf63c0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059788" comment="acroread_ja less than 9.3.2-0.1.1"/>
	</criteria>
	<!-- b058bb7270eba0f7d737bff88e2592e4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059796" comment="acroread-cmaps less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059797" comment="acroread-fonts-ja less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059798" comment="acroread-fonts-ko less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059799" comment="acroread-fonts-zh_CN less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059800" comment="acroread-fonts-zh_TW less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059801" comment="acroread less than 9.3.2-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100195" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0195</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0195" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0195" source="CVE"/>
	<description>
	Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, do not properly handle fonts, which allows attackers to execute arbitrary code via unspecified vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0e9154563fae0e1dd880d336e6cf63c0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059788" comment="acroread_ja less than 9.3.2-0.1.1"/>
	</criteria>
	<!-- b058bb7270eba0f7d737bff88e2592e4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059796" comment="acroread-cmaps less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059797" comment="acroread-fonts-ja less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059798" comment="acroread-fonts-ko less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059799" comment="acroread-fonts-zh_CN less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059800" comment="acroread-fonts-zh_TW less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059801" comment="acroread less than 9.3.2-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100196" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0196</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0196" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0196" source="CVE"/>
	<description>
	Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2010-0192 and CVE-2010-0193.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0e9154563fae0e1dd880d336e6cf63c0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059788" comment="acroread_ja less than 9.3.2-0.1.1"/>
	</criteria>
	<!-- b058bb7270eba0f7d737bff88e2592e4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059796" comment="acroread-cmaps less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059797" comment="acroread-fonts-ja less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059798" comment="acroread-fonts-ko less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059799" comment="acroread-fonts-zh_CN less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059800" comment="acroread-fonts-zh_TW less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059801" comment="acroread less than 9.3.2-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100197" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0197</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0197" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0197" source="CVE"/>
	<description>
	Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to cause a denial of service (memory corruption) or execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0194, CVE-2010-0201, and CVE-2010-0204.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0e9154563fae0e1dd880d336e6cf63c0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059788" comment="acroread_ja less than 9.3.2-0.1.1"/>
	</criteria>
	<!-- b058bb7270eba0f7d737bff88e2592e4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059796" comment="acroread-cmaps less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059797" comment="acroread-fonts-ja less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059798" comment="acroread-fonts-ko less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059799" comment="acroread-fonts-zh_CN less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059800" comment="acroread-fonts-zh_TW less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059801" comment="acroread less than 9.3.2-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100198" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0198</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0198" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0198" source="CVE"/>
	<description>
	Buffer overflow in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0199, CVE-2010-0202, and CVE-2010-0203.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0e9154563fae0e1dd880d336e6cf63c0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059788" comment="acroread_ja less than 9.3.2-0.1.1"/>
	</criteria>
	<!-- b058bb7270eba0f7d737bff88e2592e4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059796" comment="acroread-cmaps less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059797" comment="acroread-fonts-ja less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059798" comment="acroread-fonts-ko less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059799" comment="acroread-fonts-zh_CN less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059800" comment="acroread-fonts-zh_TW less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059801" comment="acroread less than 9.3.2-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100199" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0199</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0199" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0199" source="CVE"/>
	<description>
	Buffer overflow in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0198, CVE-2010-0202, and CVE-2010-0203.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0e9154563fae0e1dd880d336e6cf63c0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059788" comment="acroread_ja less than 9.3.2-0.1.1"/>
	</criteria>
	<!-- b058bb7270eba0f7d737bff88e2592e4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059796" comment="acroread-cmaps less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059797" comment="acroread-fonts-ja less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059798" comment="acroread-fonts-ko less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059799" comment="acroread-fonts-zh_CN less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059800" comment="acroread-fonts-zh_TW less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059801" comment="acroread less than 9.3.2-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100201" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0201</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0201" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0201" source="CVE"/>
	<description>
	Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to cause a denial of service (memory corruption) or execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0194, CVE-2010-0197, and CVE-2010-0204.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0e9154563fae0e1dd880d336e6cf63c0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059788" comment="acroread_ja less than 9.3.2-0.1.1"/>
	</criteria>
	<!-- b058bb7270eba0f7d737bff88e2592e4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059796" comment="acroread-cmaps less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059797" comment="acroread-fonts-ja less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059798" comment="acroread-fonts-ko less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059799" comment="acroread-fonts-zh_CN less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059800" comment="acroread-fonts-zh_TW less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059801" comment="acroread less than 9.3.2-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100202" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0202</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0202" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0202" source="CVE"/>
	<description>
	Buffer overflow in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0198, CVE-2010-0199, and CVE-2010-0203.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0e9154563fae0e1dd880d336e6cf63c0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059788" comment="acroread_ja less than 9.3.2-0.1.1"/>
	</criteria>
	<!-- b058bb7270eba0f7d737bff88e2592e4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059796" comment="acroread-cmaps less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059797" comment="acroread-fonts-ja less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059798" comment="acroread-fonts-ko less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059799" comment="acroread-fonts-zh_CN less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059800" comment="acroread-fonts-zh_TW less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059801" comment="acroread less than 9.3.2-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100203" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0203</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0203" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0203" source="CVE"/>
	<description>
	Buffer overflow in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0198, CVE-2010-0199, and CVE-2010-0202.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0e9154563fae0e1dd880d336e6cf63c0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059788" comment="acroread_ja less than 9.3.2-0.1.1"/>
	</criteria>
	<!-- b058bb7270eba0f7d737bff88e2592e4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059796" comment="acroread-cmaps less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059797" comment="acroread-fonts-ja less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059798" comment="acroread-fonts-ko less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059799" comment="acroread-fonts-zh_CN less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059800" comment="acroread-fonts-zh_TW less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059801" comment="acroread less than 9.3.2-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100204" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0204</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0204" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0204" source="CVE"/>
	<description>
	Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to cause a denial of service (memory corruption) or execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0194, CVE-2010-0197, and CVE-2010-0201.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0e9154563fae0e1dd880d336e6cf63c0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059788" comment="acroread_ja less than 9.3.2-0.1.1"/>
	</criteria>
	<!-- b058bb7270eba0f7d737bff88e2592e4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059796" comment="acroread-cmaps less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059797" comment="acroread-fonts-ja less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059798" comment="acroread-fonts-ko less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059799" comment="acroread-fonts-zh_CN less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059800" comment="acroread-fonts-zh_TW less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059801" comment="acroread less than 9.3.2-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100205" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0205</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-0205" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0205" source="CVE"/>
	<description>
	The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before 1.0.53, 1.2.x before 1.2.43, and 1.4.x before 1.4.1 does not properly handle compressed ancillary-chunk data that has a disproportionately large uncompressed representation, which allows remote attackers to cause a denial of service (memory and CPU consumption, and application hang) via a crafted PNG file, as demonstrated by use of the deflate compression method on data composed of many occurrences of the same character, related to a "decompression bomb" attack.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2ff72c65eaac8a3250b7581cf700e537 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060585" comment="libpng-devel less than 1.2.31-5.13.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060500" comment="libpng12-0-32bit less than 1.2.31-5.13.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060502" comment="libpng12-0 less than 1.2.31-5.13.1"/>
		</criteria>
	</criteria>
	<!-- 39927ae1b61dda08c4e9dac36efc1440 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060500" comment="libpng12-0-32bit less than 1.2.31-5.13.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060502" comment="libpng12-0 less than 1.2.31-5.13.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100209" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0209</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-0209" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0209" source="CVE"/>
	<description>
	Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2213, CVE-2010-2214, and CVE-2010-2216.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 095cf91c7a73fc7f8adfcb7b68dd1ea9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062194" comment="acroread_ja less than 9.3.4-0.1.1"/>
	</criteria>
	<!-- 36a9cbb312d6ad766eed81d158f1dc01 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062194" comment="acroread_ja less than 9.3.4-0.1.1"/>
	</criteria>
	<!-- 85ef4e12e2a5ef29d8861660c8ba0fec -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061978" comment="flash-player less than 10.1.82.76-0.1.1"/>
	</criteria>
	<!-- acc35314c2f71240e3fdc5d3f7877332 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061978" comment="flash-player less than 10.1.82.76-0.1.1"/>
	</criteria>
	<!-- df4199604d1ebfce8b612958957eb533 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062202" comment="acroread-cmaps less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062203" comment="acroread-fonts-ja less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062204" comment="acroread-fonts-ko less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062205" comment="acroread-fonts-zh_CN less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062206" comment="acroread-fonts-zh_TW less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062207" comment="acroread less than 9.3.4-0.6.1"/>
		</criteria>
	</criteria>
	<!-- f1ea8f5a6e6b82355c9b5987cea86fa1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062202" comment="acroread-cmaps less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062203" comment="acroread-fonts-ja less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062204" comment="acroread-fonts-ko less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062205" comment="acroread-fonts-zh_CN less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062206" comment="acroread-fonts-zh_TW less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062207" comment="acroread less than 9.3.4-0.6.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100211" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0211</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-0211" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0211" source="CVE"/>
	<description>
	The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a modrdn call with an RDN string containing invalid UTF-8 sequences, which triggers a free of an invalid, uninitialized pointer in the slap_mods_free function, as demonstrated using the Codenomicon LDAPv3 test suite.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 3d0b230dddb8bfaf7b9b6420a2be3879 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062031" comment="libldap-2_4-2-32bit less than 2.4.20-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062033" comment="libldap-2_4-2 less than 2.4.20-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062035" comment="openldap2-client less than 2.4.20-0.5.1"/>
		</criteria>
	</criteria>
	<!-- 5d20411a5d0284c2041d73e082cadc62 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062037" comment="libldap-2_4-2-32bit less than 2.4.12-7.19.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062039" comment="libldap-2_4-2 less than 2.4.12-7.19.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062041" comment="openldap2-client less than 2.4.12-7.19.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100212" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0212</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-0212" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0212" source="CVE"/>
	<description>
	OpenLDAP 2.4.22 allows remote attackers to cause a denial of service (crash) via a modrdn call with a zero-length RDN destination string, which is not properly handled by the smr_normalize function and triggers a NULL pointer dereference in the IA5StringNormalize function in schema_init.c, as demonstrated using the Codenomicon LDAPv3 test suite.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 3d0b230dddb8bfaf7b9b6420a2be3879 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062031" comment="libldap-2_4-2-32bit less than 2.4.20-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062033" comment="libldap-2_4-2 less than 2.4.20-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062035" comment="openldap2-client less than 2.4.20-0.5.1"/>
		</criteria>
	</criteria>
	<!-- 5d20411a5d0284c2041d73e082cadc62 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062037" comment="libldap-2_4-2-32bit less than 2.4.12-7.19.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062039" comment="libldap-2_4-2 less than 2.4.12-7.19.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062041" comment="openldap2-client less than 2.4.12-7.19.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100220" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0220</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0220" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0220" source="CVE"/>
	<description>
	The nsObserverList::FillObserverArray function in xpcom/ds/nsObserverList.cpp in Mozilla Firefox before 3.5.7 allows remote attackers to cause a denial of service (application crash) via a crafted web site that triggers memory consumption and an accompanying Low Memory alert dialog, and also triggers attempted removal of an observer from an empty observers array.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 300024d3172356ca0ae65b91542e36fc -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057537" comment="mozilla-xulrunner190-32bit less than 1.9.0.17-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057656" comment="mozilla-xulrunner190-gnomevfs-32bit less than 1.9.0.17-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057538" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.17-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057658" comment="mozilla-xulrunner190-translations-32bit less than 1.9.0.17-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057539" comment="mozilla-xulrunner190-translations less than 1.9.0.17-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057541" comment="mozilla-xulrunner190 less than 1.9.0.17-0.1.1"/>
		</criteria>
	</criteria>
	<!-- c3933fedd02a93f5348103c05533810e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057542" comment="MozillaFirefox-translations less than 3.5.7-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057543" comment="MozillaFirefox less than 3.5.7-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057544" comment="mozilla-xulrunner191-32bit less than 1.9.1.7-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057556" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.7-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057545" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.7-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057688" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.7-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057546" comment="mozilla-xulrunner191-translations less than 1.9.1.7-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057548" comment="mozilla-xulrunner191 less than 1.9.1.7-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100277" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0277</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0277" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0277" source="CVE"/>
	<description>
	slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.6, including 2.6.4, and Adium 1.3.8 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a malformed MSNSLP INVITE request in an SLP message, a different issue than CVE-2010-0013.
	</description>
 </metadata>
<!-- 885d32a2218fb0167f44eafd37c33a26 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009058533" comment="finch less than 2.6.6-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058535" comment="libpurple-lang less than 2.6.6-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058536" comment="libpurple less than 2.6.6-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058538" comment="pidgin less than 2.6.6-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100285" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0285</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0285" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0285" source="CVE"/>
	<description>
	gnome-screensaver 2.14.3, 2.22.2, 2.27.x, 2.28.0, and 2.28.3, when the X configuration enables the extend screen option, allows physically proximate attackers to bypass screen locking, access an unattended workstation, and view half of the GNOME desktop by attaching an external monitor.
	</description>
 </metadata>
<!-- f705327a2d63bde40e29516554760c29 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059225" comment="gnome-screensaver-lang less than 2.24.0-14.27.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059226" comment="gnome-screensaver less than 2.24.0-14.27.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100290" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0290</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0290" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0290" source="CVE"/>
	<description>
	Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains (1) CNAME or (2) DNAME records, which do not have the intended validation before caching, aka Bug 20737.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-4022.
	</description>
 </metadata>
<!-- 440b3d1daa2c9fed4b99f7865ea3a906 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009057429" comment="bind-libs-32bit less than 9.5.0P2-20.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057431" comment="bind-libs less than 9.5.0P2-20.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057432" comment="bind-utils less than 9.5.0P2-20.7.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100296" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0296</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-0296" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0296" source="CVE"/>
	<description>
	The encode_name macro in misc/mntent_r.c in the GNU C Library (aka glibc or libc6) 2.11.1 and earlier, as used by ncpmount and mount.cifs, does not properly handle newline characters in mountpoint names, which allows local users to cause a denial of service (mtab corruption), or possibly modify mount options and gain privileges, via a crafted mount request.
	</description>
 </metadata>
<!-- c1fdb4af91c950cd02ba7b76cde49c3b -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009070646" comment="glibc-32bit less than 2.11.1-0.18.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070647" comment="glibc-devel-32bit less than 2.11.1-0.18.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070648" comment="glibc-devel less than 2.11.1-0.18.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070650" comment="glibc-i18ndata less than 2.11.1-0.18.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070652" comment="glibc-locale-32bit less than 2.11.1-0.18.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070654" comment="glibc-locale less than 2.11.1-0.18.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070659" comment="glibc less than 2.11.1-0.18.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070660" comment="nscd less than 2.11.1-0.18.2"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100302" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0302</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0302" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0302" source="CVE"/>
	<description>
	Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS before 1.4.4, when kqueue or epoll is used, allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, related to improperly maintaining a reference count. NOTE: some of these details are obtained from third party information. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-3553.
	</description>
 </metadata>
<!-- a3fa76d8e915d3f22a35726188aa910b -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009058941" comment="cups-client less than 1.3.9-8.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058942" comment="cups-libs-32bit less than 1.3.9-8.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058944" comment="cups-libs less than 1.3.9-8.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058945" comment="cups less than 1.3.9-8.30.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100304" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0304</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0304" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0304" source="CVE"/>
	<description>
	Multiple buffer overflows in the LWRES dissector in Wireshark 0.9.15 through 1.0.10 and 1.2.0 through 1.2.5 allow remote attackers to cause a denial of service (crash) via a malformed packet, as demonstrated using a stack-based buffer overflow to the dissect_getaddrsbyname_request function.
	</description>
 </metadata>
<!-- 963ff40259d4863a011be226650534cb -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058844" comment="wireshark less than 1.0.5-1.34.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100307" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0307</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0307" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0307" source="CVE"/>
	<description>
	The load_elf_binary function in fs/binfmt_elf.c in the Linux kernel before 2.6.32.8 on the x86_64 platform does not ensure that the ELF interpreter is available before a call to the SET_PERSONALITY macro, which allows local users to cause a denial of service (system crash) via a 32-bit application that attempts to execute a 64-bit application and then triggers a segmentation fault, as demonstrated by amd64_killer, related to the flush_old_exec function.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5bc8b282021bec5a0602dd1e1fb86cc0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058512" comment="kernel-default-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058513" comment="kernel-xen-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 8de370e0ec03088da9aa16f31064b5c4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058512" comment="kernel-default-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058501" comment="kernel-pae-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058515" comment="kernel-pae-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058502" comment="kernel-pae less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058513" comment="kernel-xen-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100393" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0393</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0393" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0393" source="CVE"/>
	<description>
	The _cupsGetlang function, as used by lppasswd.c in lppasswd in CUPS 1.2.2, 1.3.7, 1.3.9, and 1.4.1, relies on an environment variable to determine the file that provides localized message strings, which allows local users to gain privileges via a file that contains crafted localization data with format string specifiers.
	</description>
 </metadata>
<!-- a3fa76d8e915d3f22a35726188aa910b -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009058941" comment="cups-client less than 1.3.9-8.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058942" comment="cups-libs-32bit less than 1.3.9-8.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058944" comment="cups-libs less than 1.3.9-8.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058945" comment="cups less than 1.3.9-8.30.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100395" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0395</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-0395" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0395" source="CVE"/>
	<description>
	OpenOffice.org 2.x and 3.0 before 3.2.1 allows user-assisted remote attackers to bypass Python macro security restrictions and execute arbitrary Python code via a crafted OpenDocument Text (ODT) file that triggers code execution when the macro directory structure is previewed.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 487e402b82edcff0b929d3dc16a55c82 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061516" comment="OpenOffice_org-base-drivers-postgresql less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061517" comment="OpenOffice_org-base-extensions less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061433" comment="OpenOffice_org-base less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061435" comment="OpenOffice_org-branding-SLED less than 3.2.1-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061518" comment="OpenOffice_org-calc-extensions less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061438" comment="OpenOffice_org-calc less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061440" comment="OpenOffice_org-components less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061519" comment="OpenOffice_org-converter less than 3.0-4.9.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061520" comment="OpenOffice_org-draw-extensions less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061441" comment="OpenOffice_org-draw less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061443" comment="OpenOffice_org-filters-optional less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061444" comment="OpenOffice_org-filters less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061445" comment="OpenOffice_org-gnome less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061446" comment="OpenOffice_org-help-ar less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061447" comment="OpenOffice_org-help-cs less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061448" comment="OpenOffice_org-help-da less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061449" comment="OpenOffice_org-help-de less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061450" comment="OpenOffice_org-help-en-GB less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061452" comment="OpenOffice_org-help-en-US less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061453" comment="OpenOffice_org-help-es less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061454" comment="OpenOffice_org-help-fr less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061521" comment="OpenOffice_org-help-gu-IN less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061522" comment="OpenOffice_org-help-hi-IN less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061455" comment="OpenOffice_org-help-hu less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061456" comment="OpenOffice_org-help-it less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061457" comment="OpenOffice_org-help-ja less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061523" comment="OpenOffice_org-help-ko less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061458" comment="OpenOffice_org-help-nl less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061459" comment="OpenOffice_org-help-pl less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061460" comment="OpenOffice_org-help-pt-BR less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061461" comment="OpenOffice_org-help-pt less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061462" comment="OpenOffice_org-help-ru less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061463" comment="OpenOffice_org-help-sv less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061464" comment="OpenOffice_org-help-zh-CN less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061465" comment="OpenOffice_org-help-zh-TW less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061466" comment="OpenOffice_org-icon-themes less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061524" comment="OpenOffice_org-impress-extensions less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061468" comment="OpenOffice_org-impress less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061469" comment="OpenOffice_org-kde less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061470" comment="OpenOffice_org-l10n-af less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061471" comment="OpenOffice_org-l10n-ar less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061472" comment="OpenOffice_org-l10n-ca less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061473" comment="OpenOffice_org-l10n-cs less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061474" comment="OpenOffice_org-l10n-da less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061475" comment="OpenOffice_org-l10n-de less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061477" comment="OpenOffice_org-l10n-en-GB less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061478" comment="OpenOffice_org-l10n-es less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061480" comment="OpenOffice_org-l10n-extras less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061481" comment="OpenOffice_org-l10n-fi less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061482" comment="OpenOffice_org-l10n-fr less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061525" comment="OpenOffice_org-l10n-gu-IN less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061526" comment="OpenOffice_org-l10n-hi-IN less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061483" comment="OpenOffice_org-l10n-hu less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061484" comment="OpenOffice_org-l10n-it less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061485" comment="OpenOffice_org-l10n-ja less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061527" comment="OpenOffice_org-l10n-ko less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061486" comment="OpenOffice_org-l10n-nb less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061487" comment="OpenOffice_org-l10n-nl less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061488" comment="OpenOffice_org-l10n-nn less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061489" comment="OpenOffice_org-l10n-pl less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061490" comment="OpenOffice_org-l10n-pt-BR less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061491" comment="OpenOffice_org-l10n-pt less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061492" comment="OpenOffice_org-l10n-ru less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061493" comment="OpenOffice_org-l10n-sk less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061494" comment="OpenOffice_org-l10n-sv less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061495" comment="OpenOffice_org-l10n-xh less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061496" comment="OpenOffice_org-l10n-zh-CN less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061497" comment="OpenOffice_org-l10n-zh-TW less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061498" comment="OpenOffice_org-l10n-zu less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061500" comment="OpenOffice_org-libs-core less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061502" comment="OpenOffice_org-libs-extern less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061504" comment="OpenOffice_org-libs-gui less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061505" comment="OpenOffice_org-mailmerge less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061506" comment="OpenOffice_org-math less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061507" comment="OpenOffice_org-mono less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061508" comment="OpenOffice_org-officebean less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061509" comment="OpenOffice_org-pyuno less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061512" comment="OpenOffice_org-ure less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061528" comment="OpenOffice_org-writer-extensions less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061514" comment="OpenOffice_org-writer less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061515" comment="OpenOffice_org less than 3.2.1.4-1.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061429" comment="libpython2_6-1_0-32bit less than 2.6.0-8.9.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061430" comment="libpython2_6-1_0 less than 2.6.0-8.9.20"/>
		</criteria>
	</criteria>
	<!-- d1d7f4c1120c78cfce452fda5c190097 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061648" comment="OpenOffice_org-base-drivers-postgresql less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061649" comment="OpenOffice_org-base-extensions less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061567" comment="OpenOffice_org-base less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061435" comment="OpenOffice_org-branding-SLED less than 3.2.1-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061650" comment="OpenOffice_org-calc-extensions less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061570" comment="OpenOffice_org-calc less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061572" comment="OpenOffice_org-components less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061651" comment="OpenOffice_org-converter less than 3.0-4.8.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061652" comment="OpenOffice_org-draw-extensions less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061573" comment="OpenOffice_org-draw less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061575" comment="OpenOffice_org-filters-optional less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061576" comment="OpenOffice_org-filters less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061577" comment="OpenOffice_org-gnome less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061578" comment="OpenOffice_org-help-ar less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061579" comment="OpenOffice_org-help-cs less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061580" comment="OpenOffice_org-help-da less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061581" comment="OpenOffice_org-help-de less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061582" comment="OpenOffice_org-help-en-GB less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061583" comment="OpenOffice_org-help-en-US-devel less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061584" comment="OpenOffice_org-help-en-US less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061585" comment="OpenOffice_org-help-es less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061586" comment="OpenOffice_org-help-fr less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061653" comment="OpenOffice_org-help-gu-IN less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061654" comment="OpenOffice_org-help-hi-IN less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061587" comment="OpenOffice_org-help-hu less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061588" comment="OpenOffice_org-help-it less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061589" comment="OpenOffice_org-help-ja less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061655" comment="OpenOffice_org-help-ko less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061590" comment="OpenOffice_org-help-nl less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061591" comment="OpenOffice_org-help-pl less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061592" comment="OpenOffice_org-help-pt-BR less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061593" comment="OpenOffice_org-help-pt less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061594" comment="OpenOffice_org-help-ru less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061595" comment="OpenOffice_org-help-sv less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061596" comment="OpenOffice_org-help-zh-CN less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061597" comment="OpenOffice_org-help-zh-TW less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061598" comment="OpenOffice_org-icon-themes less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061656" comment="OpenOffice_org-impress-extensions less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061600" comment="OpenOffice_org-impress less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061601" comment="OpenOffice_org-kde less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061602" comment="OpenOffice_org-l10n-af less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061603" comment="OpenOffice_org-l10n-ar less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061604" comment="OpenOffice_org-l10n-ca less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061605" comment="OpenOffice_org-l10n-cs less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061606" comment="OpenOffice_org-l10n-da less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061607" comment="OpenOffice_org-l10n-de less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061608" comment="OpenOffice_org-l10n-el less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061609" comment="OpenOffice_org-l10n-en-GB less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061610" comment="OpenOffice_org-l10n-es less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061612" comment="OpenOffice_org-l10n-extras less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061613" comment="OpenOffice_org-l10n-fi less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061614" comment="OpenOffice_org-l10n-fr less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061657" comment="OpenOffice_org-l10n-gu-IN less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061658" comment="OpenOffice_org-l10n-hi-IN less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061615" comment="OpenOffice_org-l10n-hu less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061616" comment="OpenOffice_org-l10n-it less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061617" comment="OpenOffice_org-l10n-ja less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061659" comment="OpenOffice_org-l10n-ko less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061618" comment="OpenOffice_org-l10n-nb less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061619" comment="OpenOffice_org-l10n-nl less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061620" comment="OpenOffice_org-l10n-nn less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061621" comment="OpenOffice_org-l10n-pl less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061622" comment="OpenOffice_org-l10n-pt-BR less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061623" comment="OpenOffice_org-l10n-pt less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061624" comment="OpenOffice_org-l10n-ru less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061625" comment="OpenOffice_org-l10n-sk less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061626" comment="OpenOffice_org-l10n-sv less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061627" comment="OpenOffice_org-l10n-xh less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061628" comment="OpenOffice_org-l10n-zh-CN less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061629" comment="OpenOffice_org-l10n-zh-TW less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061630" comment="OpenOffice_org-l10n-zu less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061632" comment="OpenOffice_org-libs-core less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061634" comment="OpenOffice_org-libs-extern less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061636" comment="OpenOffice_org-libs-gui less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061637" comment="OpenOffice_org-mailmerge less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061638" comment="OpenOffice_org-math less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061639" comment="OpenOffice_org-mono less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061640" comment="OpenOffice_org-officebean less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061641" comment="OpenOffice_org-pyuno less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061644" comment="OpenOffice_org-ure less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061660" comment="OpenOffice_org-writer-extensions less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061646" comment="OpenOffice_org-writer less than 3.2.1.4-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061647" comment="OpenOffice_org less than 3.2.1.4-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100405" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0405</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-0405" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0405" source="CVE"/>
	<description>
	Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and libbzip2 before 1.0.6 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted compressed file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 123cd276cbae1468f2b50c9cef92be0a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063185" comment="bzip2 less than 1.0.5-34.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063186" comment="libbz2-1-32bit less than 1.0.5-34.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063188" comment="libbz2-1 less than 1.0.5-34.1.1"/>
		</criteria>
	</criteria>
	<!-- 5e3804e832da6c82fc607378dd2897e6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063185" comment="bzip2 less than 1.0.5-34.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063186" comment="libbz2-1-32bit less than 1.0.5-34.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063188" comment="libbz2-1 less than 1.0.5-34.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100407" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0407</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-0407" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0407" source="CVE"/>
	<description>
	Multiple buffer overflows in the MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 allow local users to gain privileges via crafted message data, which is improperly demarshalled.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1aae07165beeecaf80a4ad95aea3dafa -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009070661" comment="pcsc-lite-32bit less than 1.4.102-1.31.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063350" comment="pcsc-lite less than 1.4.102-1.31.2"/>
		</criteria>
	</criteria>
	<!-- e9cad3b00872763bd334e851d50993b2 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062627" comment="pcsc-lite-32bit less than 1.4.102-1.31.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062629" comment="pcsc-lite less than 1.4.102-1.31.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100409" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0409</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0409" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0409" source="CVE"/>
	<description>
	Buffer overflow in the GMIME_UUENCODE_LEN macro in gmime/gmime-encodings.h in GMime before 2.4.15 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via input data for a uuencode operation.
	</description>
 </metadata>
<!-- 4a50644a493369f63a3b64e93a29e6c7 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009058457" comment="gmime-sharp less than 2.2.23-1.41.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058364" comment="gmime less than 2.2.23-1.41.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058365" comment="libgmime-2_0-3 less than 2.2.23-1.41.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100410" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0410</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0410" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0410" source="CVE"/>
	<description>
	drivers/connector/connector.c in the Linux kernel before 2.6.32.8 allows local users to cause a denial of service (memory consumption and system crash) by sending the kernel many NETLINK_CONNECTOR messages.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5bc8b282021bec5a0602dd1e1fb86cc0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058512" comment="kernel-default-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058513" comment="kernel-xen-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 8de370e0ec03088da9aa16f31064b5c4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058512" comment="kernel-default-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058501" comment="kernel-pae-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058515" comment="kernel-pae-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058502" comment="kernel-pae less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058513" comment="kernel-xen-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100415" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0415</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0415" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0415" source="CVE"/>
	<description>
	The do_pages_move function in mm/migrate.c in the Linux kernel before 2.6.33-rc7 does not validate node values, which allows local users to read arbitrary kernel memory locations, cause a denial of service (OOPS), and possibly have unspecified other impact by specifying a node that is not part of the kernel's node set.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5bc8b282021bec5a0602dd1e1fb86cc0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058512" comment="kernel-default-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058513" comment="kernel-xen-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 8de370e0ec03088da9aa16f31064b5c4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058512" comment="kernel-default-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058501" comment="kernel-pae-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058515" comment="kernel-pae-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058502" comment="kernel-pae less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058513" comment="kernel-xen-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100420" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0420</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0420" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0420" source="CVE"/>
	<description>
	libpurple in Finch in Pidgin before 2.6.6, when an XMPP multi-user chat (MUC) room is used, does not properly parse nicknames containing &lt;br&gt; sequences, which allows remote attackers to cause a denial of service (application crash) via a crafted nickname.
	</description>
 </metadata>
<!-- 885d32a2218fb0167f44eafd37c33a26 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009058533" comment="finch less than 2.6.6-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058535" comment="libpurple-lang less than 2.6.6-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058536" comment="libpurple less than 2.6.6-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058538" comment="pidgin less than 2.6.6-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100423" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0423</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0423" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0423" source="CVE"/>
	<description>
	gtkimhtml.c in Pidgin before 2.6.6 allows remote attackers to cause a denial of service (CPU consumption and application hang) by sending many smileys in a (1) IM or (2) chat.
	</description>
 </metadata>
<!-- 885d32a2218fb0167f44eafd37c33a26 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009058533" comment="finch less than 2.6.6-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058535" comment="libpurple-lang less than 2.6.6-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058536" comment="libpurple less than 2.6.6-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058538" comment="pidgin less than 2.6.6-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100424" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0424</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0424" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0424" source="CVE"/>
	<description>
	The edit_cmd function in crontab.c in (1) cronie before 1.4.4 and (2) Vixie cron (vixie-cron) allows local users to change the modification times of arbitrary files, and consequently cause a denial of service, via a symlink attack on a temporary file in the /tmp directory.
	</description>
 </metadata>
<!-- 7cf9f62c2ff35beb69feaf4d1bce62d8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058917" comment="cron less than 4.1-194.19.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100426" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0426</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0426" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0426" source="CVE"/>
	<description>
	sudo 1.6.x before 1.6.9p21 and 1.7.x before 1.7.2p4, when a pseudo-command is enabled, permits a match between the name of the pseudo-command and the name of an executable file in an arbitrary directory, which allows local users to gain privileges via a crafted executable file, as demonstrated by a file named sudoedit in a user's home directory.
	</description>
 </metadata>
<!-- c8c6fbc73a661cae2a40cf505fb5aa0b -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058612" comment="sudo less than 1.6.9p17-21.3.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100427" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0427</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0427" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0427" source="CVE"/>
	<description>
	sudo 1.6.x before 1.6.9p21, when the runas_default option is used, does not properly set group memberships, which allows local users to gain privileges via a sudo command.
	</description>
 </metadata>
<!-- c8c6fbc73a661cae2a40cf505fb5aa0b -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058612" comment="sudo less than 1.6.9p17-21.3.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100436" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0436</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0436" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0436" source="CVE"/>
	<description>
	Race condition in backend/ctrl.c in KDM in KDE Software Compilation (SC) 2.2.0 through 4.4.2 allows local users to change the permissions of arbitrary files, and consequently gain privileges, by blocking the removal of a certain directory that contains a control socket, related to improper interaction with ksm.
	</description>
 </metadata>
<!-- ab2f899bb4f8e06c4770285b8bdb7fbf -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059657" comment="kde4-kdm less than 4.1.3-18.8.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059658" comment="kde4-kgreeter-plugins less than 4.1.3-18.8.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059659" comment="kde4-kwin less than 4.1.3-18.8.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059660" comment="kdebase4-workspace-ksysguardd less than 4.1.3-18.8.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059661" comment="kdebase4-workspace less than 4.1.3-18.8.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100540" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0540</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-0540" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0540" source="CVE"/>
	<description>
	Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, allows remote attackers to hijack the authentication of administrators for requests that change settings.
	</description>
 </metadata>
<!-- e50c58ccd03dea996e547017df4bffff -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009070956" comment="cups-client less than 1.3.9-8.44.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070957" comment="cups-libs-32bit less than 1.3.9-8.44.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070959" comment="cups-libs less than 1.3.9-8.44.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070960" comment="cups less than 1.3.9-8.44.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100541" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0541</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-0541" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0541" source="CVE"/>
	<description>
	Cross-site scripting (XSS) vulnerability in the WEBrick HTTP server in Ruby in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, allows remote attackers to inject arbitrary web script or HTML via a crafted URI that triggers a UTF-7 error page.
	</description>
 </metadata>
<!-- 5087d31530e2994f4eda91fda3425c12 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009068619" comment="ruby less than 1.8.7.p72-5.28.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100542" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0542</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-0542" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0542" source="CVE"/>
	<description>
	The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem in CUPS before 1.4.4 does not check the return values of certain calloc calls, which allows remote attackers to cause a denial of service (NULL pointer dereference or heap memory corruption) or possibly execute arbitrary code via a crafted file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- d603aeff8a309d9d04651d4469e31973 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064776" comment="cups-client less than 1.3.9-8.37.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064777" comment="cups-libs-32bit less than 1.3.9-8.37.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064779" comment="cups-libs less than 1.3.9-8.37.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064780" comment="cups less than 1.3.9-8.37.1"/>
		</criteria>
	</criteria>
	<!-- e290f3059978b800480c09727b4b714a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064776" comment="cups-client less than 1.3.9-8.37.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064777" comment="cups-libs-32bit less than 1.3.9-8.37.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064779" comment="cups-libs less than 1.3.9-8.37.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064780" comment="cups less than 1.3.9-8.37.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100547" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0547</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0547" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0547" source="CVE"/>
	<description>
	client/mount.cifs.c in mount.cifs in smbfs in Samba 3.4.5 and earlier does not verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of service (mtab corruption) via a crafted string.
	</description>
 </metadata>
<!-- dcc8a519c5c6d5ce485655060c83d71a -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059012" comment="cifs-mount less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059014" comment="libsmbclient0-32bit less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059016" comment="libsmbclient0 less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059017" comment="libtalloc1-32bit less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059019" comment="libtalloc1 less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059020" comment="libtdb1-32bit less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059022" comment="libtdb1 less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059023" comment="libwbclient0-32bit less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059025" comment="libwbclient0 less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059026" comment="samba-32bit less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059027" comment="samba-client-32bit less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059029" comment="samba-client less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059030" comment="samba-krb-printing less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059083" comment="samba-vscan less than 0.3.6b-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059031" comment="samba-winbind-32bit less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059033" comment="samba-winbind less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059035" comment="samba less than 3.2.7-11.9.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100622" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0622</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0622" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0622" source="CVE"/>
	<description>
	The wake_futex_pi function in kernel/futex.c in the Linux kernel before 2.6.33-rc7 does not properly handle certain unlock operations for a Priority Inheritance (PI) futex, which allows local users to cause a denial of service (OOPS) and possibly have unspecified other impact via vectors involving modification of the futex value from user space.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5bc8b282021bec5a0602dd1e1fb86cc0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058512" comment="kernel-default-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058513" comment="kernel-xen-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 8de370e0ec03088da9aa16f31064b5c4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058512" comment="kernel-default-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058501" comment="kernel-pae-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058515" comment="kernel-pae-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058502" comment="kernel-pae less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058513" comment="kernel-xen-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100624" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0624</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0624" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0624" source="CVE"/>
	<description>
	Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.11 allows remote rmt servers to cause a denial of service (memory corruption) or possibly execute arbitrary code by sending more data than was requested, related to archive filenames that contain a : (colon) character.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- a8068f50be3aa5856bfbafbb986ccede -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060021" comment="tar less than 1.20-23.23.1"/>
	</criteria>
	<!-- b00019e2d90a9075cadf119bab5ef806 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060050" comment="cpio-lang less than 2.9-75.27.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060051" comment="cpio less than 2.9-75.27.24.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100629" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0629</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0629" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0629" source="CVE"/>
	<description>
	Use-after-free vulnerability in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote authenticated users to cause a denial of service (daemon crash) via a request from a kadmin client that sends an invalid API version number.
	</description>
 </metadata>
<!-- b80f25d43febd27bf80775d0df4efc48 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059523" comment="krb5-32bit less than 1.6.3-133.27.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059526" comment="krb5-client less than 1.6.3-133.27.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059529" comment="krb5 less than 1.6.3-133.27.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100654" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0654</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-0654" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0654" source="CVE"/>
	<description>
	Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 permit cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote attackers to obtain sensitive information via a crafted document.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0d0d8706df2d64128121ceea3338a129 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061819" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061840" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
	<!-- f23d3ef3410fecb23cf62a058d285514 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061819" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061840" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100732" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0732</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0732" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0732" source="CVE"/>
	<description>
	gdk/gdkwindow.c in GTK+ before 2.18.5, as used in gnome-screensaver before 2.28.1, performs implicit paints on windows of type GDK_WINDOW_FOREIGN, which triggers an X error in certain circumstances and consequently allows physically proximate attackers to bypass screen locking and access an unattended workstation by pressing the Enter key many times.
	</description>
 </metadata>
<!-- f705327a2d63bde40e29516554760c29 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059225" comment="gnome-screensaver-lang less than 2.24.0-14.27.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059226" comment="gnome-screensaver less than 2.24.0-14.27.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100733" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0733</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-0733" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0733" source="CVE"/>
	<description>
	Integer overflow in src/backend/executor/nodeHash.c in PostgreSQL 8.4.1 and earlier, and 8.5 through 8.5alpha2, allows remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with many LEFT JOIN clauses, related to certain hashtable size calculations.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1623a9038b26e4b2fb345e388ebf6ca9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061273" comment="postgresql-libs-32bit less than 8.3.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061275" comment="postgresql-libs less than 8.3.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061277" comment="postgresql less than 8.3.11-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 3583616cbc2a604051aee34d4ba07c2c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061277" comment="postgresql less than 8.3.11-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100739" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0739</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0739" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0739" source="CVE"/>
	<description>
	Integer overflow in the predospecial function in dospecial.c in dvips in (1) TeX Live and (2) teTeX might allow user-assisted remote attackers to execute arbitrary code via a crafted DVI file that triggers a heap-based buffer overflow.  NOTE: some of these details are obtained from third party information.
	</description>
 </metadata>
<!-- b9c522a3bd2322d1a9203c227b8a5c35 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060471" comment="texlive-cjk less than 2007-219.32.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060476" comment="texlive-jadetex less than 2007-219.32.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060478" comment="texlive-latex less than 2007-219.32.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060484" comment="texlive-tools less than 2007-219.32.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060487" comment="texlive less than 2007-219.32.13.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100743" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0743</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-0743" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0743" source="CVE"/>
	<description>
	Multiple format string vulnerabilities in isns.c in (1) Linux SCSI target framework (aka tgt or scsi-target-utils) 1.0.3, 0.9.5, and earlier and (2) iSCSI Enterprise Target (aka iscsitarget) 0.4.16 allow remote attackers to cause a denial of service (tgtd daemon crash) or possibly have unspecified other impact via vectors that involve the isns_attr_query and qry_rsp_handle functions, and are related to (a) client appearance and (b) client disappearance messages.
	</description>
 </metadata>
<!-- b2720d1cb13b664616006efc437aaeb0 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009062383" comment="iscsitarget-kmp-default less than 1.4.19_2.6.32.13_0.5-0.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062386" comment="iscsitarget-kmp-xen less than 1.4.19_2.6.32.13_0.5-0.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062387" comment="iscsitarget less than 1.4.19-0.7.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100787" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0787</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0787" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0787" source="CVE"/>
	<description>
	client/mount.cifs.c in mount.cifs in smbfs in Samba 3.0.22, 3.0.28a, 3.2.3, 3.3.2, 3.4.0, and 3.4.5 allows local users to mount a CIFS share on an arbitrary mountpoint, and gain privileges, via a symlink attack on the mountpoint directory file.
	</description>
 </metadata>
<!-- 38b274074b3d5ef4abafff31fa80e561 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060901" comment="cifs-mount less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060903" comment="libsmbclient0-32bit less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060905" comment="libsmbclient0 less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060906" comment="libtalloc1-32bit less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060908" comment="libtalloc1 less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060909" comment="libtdb1-32bit less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060911" comment="libtdb1 less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060912" comment="libwbclient0-32bit less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060914" comment="libwbclient0 less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060915" comment="samba-32bit less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060916" comment="samba-client-32bit less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060918" comment="samba-client less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060919" comment="samba-krb-printing less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060997" comment="samba-vscan less than 0.3.6b-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060920" comment="samba-winbind-32bit less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060922" comment="samba-winbind less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060924" comment="samba less than 3.2.7-11.20.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100788" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0788</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-0788" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0788" source="CVE"/>
	<description>
	ncpfs 2.2.6 allows local users to cause a denial of service, obtain sensitive information, or possibly gain privileges via symlink attacks involving the (1) ncpmount and (2) ncpumount programs.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 6973124d9e45526cd60d695fae236853 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060662" comment="ncpfs-32bit less than 2.2.6-147.20.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060661" comment="ncpfs less than 2.2.6-147.20.1"/>
		</criteria>
	</criteria>
	<!-- e63555cd2e6129dc46a7e007c5df5585 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060662" comment="ncpfs-32bit less than 2.2.6-147.20.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060661" comment="ncpfs less than 2.2.6-147.20.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100790" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0790</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-0790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0790" source="CVE"/>
	<description>
	sutil/ncpumount.c in ncpumount in ncpfs 2.2.6 produces certain detailed error messages about the results of privileged file-access attempts, which allows local users to determine the existence of arbitrary files via the mountpoint name.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 6973124d9e45526cd60d695fae236853 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060662" comment="ncpfs-32bit less than 2.2.6-147.20.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060661" comment="ncpfs less than 2.2.6-147.20.1"/>
		</criteria>
	</criteria>
	<!-- e63555cd2e6129dc46a7e007c5df5585 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060662" comment="ncpfs-32bit less than 2.2.6-147.20.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060661" comment="ncpfs less than 2.2.6-147.20.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100791" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0791</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-0791" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0791" source="CVE"/>
	<description>
	The (1) ncpmount, (2) ncpumount, and (3) ncplogin programs in ncpfs 2.2.6 do not properly create lock files, which allows local users to cause a denial of service (application failure) via unspecified vectors that trigger the creation of a /etc/mtab~ file that persists after the program exits.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 6973124d9e45526cd60d695fae236853 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060662" comment="ncpfs-32bit less than 2.2.6-147.20.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060661" comment="ncpfs less than 2.2.6-147.20.1"/>
		</criteria>
	</criteria>
	<!-- e63555cd2e6129dc46a7e007c5df5585 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060662" comment="ncpfs-32bit less than 2.2.6-147.20.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060661" comment="ncpfs less than 2.2.6-147.20.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100827" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0827</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0827" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0827" source="CVE"/>
	<description>
	Integer overflow in dvips in TeX Live 2009 and earlier, and teTeX, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted virtual font (VF) file associated with a DVI file.
	</description>
 </metadata>
<!-- b9c522a3bd2322d1a9203c227b8a5c35 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060471" comment="texlive-cjk less than 2007-219.32.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060476" comment="texlive-jadetex less than 2007-219.32.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060478" comment="texlive-latex less than 2007-219.32.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060484" comment="texlive-tools less than 2007-219.32.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060487" comment="texlive less than 2007-219.32.13.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100829" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0829</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0829" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0829" source="CVE"/>
	<description>
	Multiple array index errors in set.c in dvipng 1.11 and 1.12, and teTeX, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed DVI file.
	</description>
 </metadata>
<!-- b9c522a3bd2322d1a9203c227b8a5c35 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060471" comment="texlive-cjk less than 2007-219.32.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060476" comment="texlive-jadetex less than 2007-219.32.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060478" comment="texlive-latex less than 2007-219.32.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060484" comment="texlive-tools less than 2007-219.32.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060487" comment="texlive less than 2007-219.32.13.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100830" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0830</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-0830" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0830" source="CVE"/>
	<description>
	Integer signedness error in the elf_get_dynamic_info function in elf/dynamic-link.h in ld.so in the GNU C Library (aka glibc or libc6) 2.0.1 through 2.11.1, when the --verify option is used, allows user-assisted remote attackers to execute arbitrary code via a crafted ELF program with a negative value for a certain d_tag structure member in the ELF header.
	</description>
 </metadata>
<!-- c1fdb4af91c950cd02ba7b76cde49c3b -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009070646" comment="glibc-32bit less than 2.11.1-0.18.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070647" comment="glibc-devel-32bit less than 2.11.1-0.18.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070648" comment="glibc-devel less than 2.11.1-0.18.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070650" comment="glibc-i18ndata less than 2.11.1-0.18.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070652" comment="glibc-locale-32bit less than 2.11.1-0.18.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070654" comment="glibc-locale less than 2.11.1-0.18.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070659" comment="glibc less than 2.11.1-0.18.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070660" comment="nscd less than 2.11.1-0.18.2"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100837" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0837</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0837" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0837" source="CVE"/>
	<description>
	Unspecified vulnerability in the Pack200 component in Oracle Java SE and Java for Business 6 Update 18, 5.0, Update, and 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
	</description>
 </metadata>
<!-- 33752f926ef7d4dfa0db31b1c685e810 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059302" comment="java-1_6_0-sun-alsa less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059303" comment="java-1_6_0-sun-demo less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059305" comment="java-1_6_0-sun-jdbc less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059306" comment="java-1_6_0-sun-plugin less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059307" comment="java-1_6_0-sun-src less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059308" comment="java-1_6_0-sun less than 1.6.0.u19-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100838" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0838</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0838" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0838" source="CVE"/>
	<description>
	Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0, Update, and 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is a stack-based buffer overflow using an untrusted size value in the readMabCurveData function in the CMM module in the JVM.
	</description>
 </metadata>
<!-- 33752f926ef7d4dfa0db31b1c685e810 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059302" comment="java-1_6_0-sun-alsa less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059303" comment="java-1_6_0-sun-demo less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059305" comment="java-1_6_0-sun-jdbc less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059306" comment="java-1_6_0-sun-plugin less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059307" comment="java-1_6_0-sun-src less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059308" comment="java-1_6_0-sun less than 1.6.0.u19-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100839" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0839</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0839" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0839" source="CVE"/>
	<description>
	Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
	</description>
 </metadata>
<!-- 33752f926ef7d4dfa0db31b1c685e810 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059302" comment="java-1_6_0-sun-alsa less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059303" comment="java-1_6_0-sun-demo less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059305" comment="java-1_6_0-sun-jdbc less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059306" comment="java-1_6_0-sun-plugin less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059307" comment="java-1_6_0-sun-src less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059308" comment="java-1_6_0-sun less than 1.6.0.u19-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100840" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0840</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0840" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0840" source="CVE"/>
	<description>
	Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is related to improper checks when executing privileged methods in the Java Runtime Environment (JRE), which allows attackers to execute arbitrary code via (1) an untrusted object that extends the trusted class but has not modified a certain method, or (2) "a similar trust issue with interfaces," aka "Trusted Methods Chaining Remote Code Execution Vulnerability."
	</description>
 </metadata>
<!-- 33752f926ef7d4dfa0db31b1c685e810 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059302" comment="java-1_6_0-sun-alsa less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059303" comment="java-1_6_0-sun-demo less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059305" comment="java-1_6_0-sun-jdbc less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059306" comment="java-1_6_0-sun-plugin less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059307" comment="java-1_6_0-sun-src less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059308" comment="java-1_6_0-sun less than 1.6.0.u19-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100841" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0841</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0841" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0841" source="CVE"/>
	<description>
	Unspecified vulnerability in the ImageIO component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is an integer overflow in the Java Runtime Environment that allows remote attackers to execute arbitrary code via a JPEG image that contains subsample dimensions with large values, related to JPEGImageReader and "stepX".
	</description>
 </metadata>
<!-- 33752f926ef7d4dfa0db31b1c685e810 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059302" comment="java-1_6_0-sun-alsa less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059303" comment="java-1_6_0-sun-demo less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059305" comment="java-1_6_0-sun-jdbc less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059306" comment="java-1_6_0-sun-plugin less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059307" comment="java-1_6_0-sun-src less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059308" comment="java-1_6_0-sun less than 1.6.0.u19-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100842" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0842</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0842" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0842" source="CVE"/>
	<description>
	Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is an uncontrolled array index that allows remote attackers to execute arbitrary code via a MIDI file with a crafted MixerSequencer object, related to the GM_Song structure.
	</description>
 </metadata>
<!-- 33752f926ef7d4dfa0db31b1c685e810 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059302" comment="java-1_6_0-sun-alsa less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059303" comment="java-1_6_0-sun-demo less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059305" comment="java-1_6_0-sun-jdbc less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059306" comment="java-1_6_0-sun-plugin less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059307" comment="java-1_6_0-sun-src less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059308" comment="java-1_6_0-sun less than 1.6.0.u19-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100843" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0843</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0843" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0843" source="CVE"/>
	<description>
	Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is related to XNewPtr and improper handling of an integer parameter when allocating heap memory in the com.sun.media.sound libraries, which allows remote attackers to execute arbitrary code.
	</description>
 </metadata>
<!-- 33752f926ef7d4dfa0db31b1c685e810 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059302" comment="java-1_6_0-sun-alsa less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059303" comment="java-1_6_0-sun-demo less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059305" comment="java-1_6_0-sun-jdbc less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059306" comment="java-1_6_0-sun-plugin less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059307" comment="java-1_6_0-sun-src less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059308" comment="java-1_6_0-sun less than 1.6.0.u19-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100844" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0844</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0844" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0844" source="CVE"/>
	<description>
	Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is for improper parsing of a crafted MIDI stream when creating a MixerSequencer object, which causes a pointer to be corrupted and allows a NULL byte to be written to arbitrary memory.
	</description>
 </metadata>
<!-- 33752f926ef7d4dfa0db31b1c685e810 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059302" comment="java-1_6_0-sun-alsa less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059303" comment="java-1_6_0-sun-demo less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059305" comment="java-1_6_0-sun-jdbc less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059306" comment="java-1_6_0-sun-plugin less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059307" comment="java-1_6_0-sun-src less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059308" comment="java-1_6_0-sun less than 1.6.0.u19-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100845" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0845</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0845" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0845" source="CVE"/>
	<description>
	Unspecified vulnerability in the HotSpot Server component in Oracle Java SE and Java for Business 6 Update 18, 5.0, Update, and 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
	</description>
 </metadata>
<!-- 33752f926ef7d4dfa0db31b1c685e810 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059302" comment="java-1_6_0-sun-alsa less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059303" comment="java-1_6_0-sun-demo less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059305" comment="java-1_6_0-sun-jdbc less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059306" comment="java-1_6_0-sun-plugin less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059307" comment="java-1_6_0-sun-src less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059308" comment="java-1_6_0-sun less than 1.6.0.u19-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100846" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0846</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0846" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0846" source="CVE"/>
	<description>
	Unspecified vulnerability in the ImageIO component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is a heap-based buffer overflow that allows remote attackers to execute arbitrary code, related to an "invalid assignment" and inconsistent length values in a JPEG image encoder (JPEGImageEncoderImpl).
	</description>
 </metadata>
<!-- 33752f926ef7d4dfa0db31b1c685e810 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059302" comment="java-1_6_0-sun-alsa less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059303" comment="java-1_6_0-sun-demo less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059305" comment="java-1_6_0-sun-jdbc less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059306" comment="java-1_6_0-sun-plugin less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059307" comment="java-1_6_0-sun-src less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059308" comment="java-1_6_0-sun less than 1.6.0.u19-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100847" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0847</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0847" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0847" source="CVE"/>
	<description>
	Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is a heap-based buffer overflow that allows arbitrary code execution via a crafted image.
	</description>
 </metadata>
<!-- 33752f926ef7d4dfa0db31b1c685e810 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059302" comment="java-1_6_0-sun-alsa less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059303" comment="java-1_6_0-sun-demo less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059305" comment="java-1_6_0-sun-jdbc less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059306" comment="java-1_6_0-sun-plugin less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059307" comment="java-1_6_0-sun-src less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059308" comment="java-1_6_0-sun less than 1.6.0.u19-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100848" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0848</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0848" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0848" source="CVE"/>
	<description>
	Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
	</description>
 </metadata>
<!-- 33752f926ef7d4dfa0db31b1c685e810 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059302" comment="java-1_6_0-sun-alsa less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059303" comment="java-1_6_0-sun-demo less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059305" comment="java-1_6_0-sun-jdbc less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059306" comment="java-1_6_0-sun-plugin less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059307" comment="java-1_6_0-sun-src less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059308" comment="java-1_6_0-sun less than 1.6.0.u19-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100849" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0849</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0849" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0849" source="CVE"/>
	<description>
	Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is a heap-based buffer overflow in a decoding routine used by the JPEGImageDecoderImpl interface, which allows code execution via a crafted JPEG image.
	</description>
 </metadata>
<!-- 33752f926ef7d4dfa0db31b1c685e810 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059302" comment="java-1_6_0-sun-alsa less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059303" comment="java-1_6_0-sun-demo less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059305" comment="java-1_6_0-sun-jdbc less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059306" comment="java-1_6_0-sun-plugin less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059307" comment="java-1_6_0-sun-src less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059308" comment="java-1_6_0-sun less than 1.6.0.u19-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100850" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0850</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0850" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0850" source="CVE"/>
	<description>
	Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
	</description>
 </metadata>
<!-- 33752f926ef7d4dfa0db31b1c685e810 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059302" comment="java-1_6_0-sun-alsa less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059303" comment="java-1_6_0-sun-demo less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059305" comment="java-1_6_0-sun-jdbc less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059306" comment="java-1_6_0-sun-plugin less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059307" comment="java-1_6_0-sun-src less than 1.6.0.u19-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059308" comment="java-1_6_0-sun less than 1.6.0.u19-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100887" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0887</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0887" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0887" source="CVE"/>
	<description>
	Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business JDK and JRE 6 Update 18 and 19 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
	</description>
 </metadata>
<!-- d244631dc7b250b86fb6f86508330b32 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059808" comment="java-1_6_0-sun-alsa less than 1.6.0.u20-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059809" comment="java-1_6_0-sun-demo less than 1.6.0.u20-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059811" comment="java-1_6_0-sun-jdbc less than 1.6.0.u20-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059812" comment="java-1_6_0-sun-plugin less than 1.6.0.u20-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059813" comment="java-1_6_0-sun-src less than 1.6.0.u20-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059814" comment="java-1_6_0-sun less than 1.6.0.u20-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100926" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0926</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0926" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0926" source="CVE"/>
	<description>
	The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, and 3.5.x before 3.5.0rc3, when a writable share exists, allows remote authenticated users to leverage a directory traversal vulnerability, and access arbitrary files, by using the symlink command in smbclient to create a symlink containing .. (dot dot) sequences, related to the combination of the unix extensions and wide links options.
	</description>
 </metadata>
<!-- dcc8a519c5c6d5ce485655060c83d71a -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059012" comment="cifs-mount less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059014" comment="libsmbclient0-32bit less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059016" comment="libsmbclient0 less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059017" comment="libtalloc1-32bit less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059019" comment="libtalloc1 less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059020" comment="libtdb1-32bit less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059022" comment="libtdb1 less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059023" comment="libwbclient0-32bit less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059025" comment="libwbclient0 less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059026" comment="samba-32bit less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059027" comment="samba-client-32bit less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059029" comment="samba-client less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059030" comment="samba-krb-printing less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059083" comment="samba-vscan less than 0.3.6b-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059031" comment="samba-winbind-32bit less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059033" comment="samba-winbind less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059035" comment="samba less than 3.2.7-11.9.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101000" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1000</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1000" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1000" source="CVE"/>
	<description>
	Directory traversal vulnerability in KGet in KDE SC 4.0.0 through 4.4.3 allows remote attackers to create arbitrary files via directory traversal sequences in the name attribute of a file element in a metalink file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2fb2523f388f4f507725821f053b7b30 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009065196" comment="kdenetwork4-filesharing less than 4.3.5-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065197" comment="kget less than 4.3.5-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065198" comment="kopete less than 4.3.5-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065204" comment="kppp less than 4.3.5-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065199" comment="krdc less than 4.3.5-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065200" comment="krfb less than 4.3.5-0.4.1"/>
		</criteria>
	</criteria>
	<!-- fb44440d868c7c3b0efae521994af0a4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009065165" comment="kde4-kget less than 4.1.3-7.9.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065166" comment="kde4-knewsticker less than 4.1.3-7.9.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065167" comment="kde4-kopete less than 4.1.3-7.9.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065186" comment="kde4-kppp less than 4.1.3-7.9.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065168" comment="kde4-krdc less than 4.1.3-7.9.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065169" comment="kde4-krfb less than 4.1.3-7.9.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065170" comment="kdenetwork4-filesharing less than 4.1.3-7.9.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101085" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1085</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-1085" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1085" source="CVE"/>
	<description>
	The azx_position_ok function in hda_intel.c in Linux kernel 2.6.33-rc4 and earlier, when running on the AMD780V chip set, allows context-dependent attackers to cause a denial of service (crash) via unknown manipulations that trigger a divide-by-zero error.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5bc8b282021bec5a0602dd1e1fb86cc0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058512" comment="kernel-default-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058513" comment="kernel-xen-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 8de370e0ec03088da9aa16f31064b5c4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058512" comment="kernel-default-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058501" comment="kernel-pae-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058515" comment="kernel-pae-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058502" comment="kernel-pae less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058513" comment="kernel-xen-extra less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101087" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1087</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-1087" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1087" source="CVE"/>
	<description>
	The nfs_wait_on_request function in fs/nfs/pagelist.c in Linux kernel 2.6.x through 2.6.33-rc5 allows attackers to cause a denial of service (Oops) via unknown vectors related to truncating a file and an operation that is not interruptible.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 66504af0afe753b5175112b44bc8827d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061675" comment="kernel-default-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061679" comment="kernel-pae-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061680" comment="kernel-pae-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061681" comment="kernel-pae less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061693" comment="kernel-xen-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- c8a29eec659b0b2b3e85c610b67beacd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061675" comment="kernel-default-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061693" comment="kernel-xen-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101121" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1121</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1121" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1121" source="CVE"/>
	<description>
	Mozilla Firefox 3.6.x before 3.6.3 does not properly manage the scopes of DOM nodes that are moved from one document to another, which allows remote attackers to conduct use-after-free attacks and execute arbitrary code via unspecified vectors involving improper interaction with garbage collection, as demonstrated by Nils during a Pwn2Own competition at CanSecWest 2010.
	</description>
 </metadata>
<!-- f9b2b1aaa535612c1bff26161e7cb381 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009061668" comment="MozillaFirefox-translations less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061192" comment="MozillaFirefox less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070643" comment="mozilla-xulrunner191-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070716" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070644" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070718" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061669" comment="mozilla-xulrunner191-translations less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061670" comment="mozilla-xulrunner191 less than 1.9.1.10-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101125" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1125</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1125" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1125" source="CVE"/>
	<description>
	The JavaScript implementation in Mozilla Firefox 3.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, allows remote attackers to send selected keystrokes to a form field in a hidden frame, instead of the intended form field in a visible frame, via certain calls to the focus method.
	</description>
 </metadata>
<!-- f9b2b1aaa535612c1bff26161e7cb381 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009061668" comment="MozillaFirefox-translations less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061192" comment="MozillaFirefox less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070643" comment="mozilla-xulrunner191-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070716" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070644" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070718" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061669" comment="mozilla-xulrunner191-translations less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061670" comment="mozilla-xulrunner191 less than 1.9.1.10-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101162" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1162</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-1162" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1162" source="CVE"/>
	<description>
	The release_one_tty function in drivers/char/tty_io.c in the Linux kernel before 2.6.34-rc4 omits certain required calls to the put_pid function, which has unspecified impact and local attack vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 66504af0afe753b5175112b44bc8827d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061675" comment="kernel-default-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061679" comment="kernel-pae-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061680" comment="kernel-pae-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061681" comment="kernel-pae less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061693" comment="kernel-xen-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- c8a29eec659b0b2b3e85c610b67beacd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061675" comment="kernel-default-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061693" comment="kernel-xen-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101166" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1166</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1166" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1166" source="CVE"/>
	<description>
	The fbComposite function in fbpict.c in the Render extension in the X server in X.Org X11R7.1 allows remote authenticated users to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a crafted request, related to an incorrect macro definition.
	</description>
 </metadata>
<!-- 0174468eca4a0d10570a92e001f081dd -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009063235" comment="xorg-x11-Xvnc less than 7.4-27.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009063236" comment="xorg-x11-server-extra less than 7.4-27.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009063237" comment="xorg-x11-server less than 7.4-27.24.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101168" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1168</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1168" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1168" source="CVE"/>
	<description>
	The Safe (aka Safe.pm) module before 2.25 for Perl allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access restrictions, and inject and execute arbitrary code, via vectors involving implicitly called methods and implicitly blessed objects, as demonstrated by the (a) DESTROY and (b) AUTOLOAD methods, related to "automagic methods."
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 20ed7ae57e909277c40c8e5c6d74b113 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061998" comment="perl-32bit less than 5.10.0-64.48.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061999" comment="perl-base less than 5.10.0-64.48.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062000" comment="perl-doc less than 5.10.0-64.48.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062002" comment="perl less than 5.10.0-64.48.1"/>
		</criteria>
	</criteria>
	<!-- fc6f7dab4b52caad2fdcf02ae40651a3 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062003" comment="perl-32bit less than 5.10.0-64.44.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062004" comment="perl-base less than 5.10.0-64.44.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062005" comment="perl-doc less than 5.10.0-64.44.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062007" comment="perl less than 5.10.0-64.44.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101169" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1169</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1169" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1169" source="CVE"/>
	<description>
	PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, 8.4 before 8.4.4, and 9.0 Beta before 9.0 Beta 2 does not properly restrict PL/perl procedures, which allows remote authenticated users, with database-creation privileges, to execute arbitrary Perl code via a crafted script, related to the Safe module (aka Safe.pm) for Perl. NOTE: some sources report that this issue is the same as CVE-2010-1447.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1623a9038b26e4b2fb345e388ebf6ca9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061273" comment="postgresql-libs-32bit less than 8.3.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061275" comment="postgresql-libs less than 8.3.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061277" comment="postgresql less than 8.3.11-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 3583616cbc2a604051aee34d4ba07c2c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061277" comment="postgresql less than 8.3.11-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101170" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1170</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1170" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1170" source="CVE"/>
	<description>
	The PL/Tcl implementation in PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, 8.4 before 8.4.4, and 9.0 Beta before 9.0 Beta 2 loads Tcl code from the pltcl_modules table regardless of the table's ownership and permissions, which allows remote authenticated users, with database-creation privileges, to execute arbitrary Tcl code by creating this table and inserting a crafted Tcl script.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1623a9038b26e4b2fb345e388ebf6ca9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061273" comment="postgresql-libs-32bit less than 8.3.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061275" comment="postgresql-libs less than 8.3.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061277" comment="postgresql less than 8.3.11-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 3583616cbc2a604051aee34d4ba07c2c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061277" comment="postgresql less than 8.3.11-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101172" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1172</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1172" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1172" source="CVE"/>
	<description>
	DBus-GLib 0.73 disregards the access flag of exported GObject properties, which allows local users to bypass intended access restrictions and possibly cause a denial of service by modifying properties, as demonstrated by properties of the (1) DeviceKit-Power, (2) NetworkManager, and (3) ModemManager services.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0cf7b7dbbdf78d0e48405afacc77e953 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009070663" comment="NetworkManager-glib less than 0.7.0.r4359-15.25.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070664" comment="NetworkManager less than 0.7.0.r4359-15.25.1"/>
		</criteria>
	</criteria>
	<!-- 21a8a97ab9a50a767beec4f66444c8fb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063818" comment="dbus-1-glib-32bit less than 0.76-34.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063820" comment="dbus-1-glib less than 0.76-34.4.1"/>
		</criteria>
	</criteria>
	<!-- 6ebbb42d94bbf91e258916a349f1d793 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064045" comment="NetworkManager-glib less than 0.7.0.r4359-15.20.10.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064046" comment="NetworkManager less than 0.7.0.r4359-15.20.10.12"/>
		</criteria>
	</criteria>
	<!-- 7d54ac00be064ed8a9d0f93e8a7a259f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064413" comment="gdm-branding-upstream less than 2.24.0-24.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064414" comment="gdm-lang less than 2.24.0-24.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064415" comment="gdm less than 2.24.0-24.28.1"/>
		</criteria>
	</criteria>
	<!-- 82a8dce49738846083382071155ad5b3 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064416" comment="gdm-branding-upstream less than 2.24.0-24.39.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064417" comment="gdm-lang less than 2.24.0-24.39.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064418" comment="gdm less than 2.24.0-24.39.1"/>
		</criteria>
	</criteria>
	<!-- f13b7d380aa83e653649de2c3932f66d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063821" comment="dbus-1-glib-32bit less than 0.76-34.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063823" comment="dbus-1-glib less than 0.76-34.7.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101173" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1173</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1173" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1173" source="CVE"/>
	<description>
	The sctp_process_unk_param function in net/sctp/sm_make_chunk.c in the Linux kernel 2.6.33.3 and earlier, when SCTP is enabled, allows remote attackers to cause a denial of service (system crash) via an SCTPChunkInit packet containing multiple invalid parameters that require a large amount of error data.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 22846882965710e8a968106e5fa9b938 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009070665" comment="btrfs-kmp-default less than 0_2.6.32.13_0.4-0.3.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070676" comment="btrfs-kmp-pae less than 0_2.6.32.13_0.4-0.3.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070677" comment="btrfs-kmp-xen less than 0_2.6.32.13_0.4-0.3.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070680" comment="hyper-v-kmp-default less than 0_2.6.32.13_0.4-0.7.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070681" comment="hyper-v-kmp-pae less than 0_2.6.32.13_0.4-0.7.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070667" comment="kernel-default-base less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070668" comment="kernel-default-devel less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070741" comment="kernel-default-extra less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070670" comment="kernel-default less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070742" comment="kernel-desktop-devel less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070682" comment="kernel-pae-base less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070683" comment="kernel-pae-devel less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070743" comment="kernel-pae-extra less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070684" comment="kernel-pae less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070671" comment="kernel-source less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070672" comment="kernel-syms less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070685" comment="kernel-xen-base less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070686" comment="kernel-xen-devel less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070744" comment="kernel-xen-extra less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070687" comment="kernel-xen less than 2.6.32.13-0.4.1"/>
		</criteria>
	</criteria>
	<!-- 6d234b253abdbb9f30537479384ed1bd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009070665" comment="btrfs-kmp-default less than 0_2.6.32.13_0.4-0.3.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070677" comment="btrfs-kmp-xen less than 0_2.6.32.13_0.4-0.3.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070680" comment="hyper-v-kmp-default less than 0_2.6.32.13_0.4-0.7.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070667" comment="kernel-default-base less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070668" comment="kernel-default-devel less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070741" comment="kernel-default-extra less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070670" comment="kernel-default less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070742" comment="kernel-desktop-devel less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070671" comment="kernel-source less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070672" comment="kernel-syms less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070685" comment="kernel-xen-base less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070686" comment="kernel-xen-devel less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070744" comment="kernel-xen-extra less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070687" comment="kernel-xen less than 2.6.32.13-0.4.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101196" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1196</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1196" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1196" source="CVE"/>
	<description>
	Integer overflow in the nsGenericDOMDataNode::SetTextInternal function in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code via a DOM node with a long text value that triggers a heap-based buffer overflow.
	</description>
 </metadata>
<!-- f9b2b1aaa535612c1bff26161e7cb381 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009061668" comment="MozillaFirefox-translations less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061192" comment="MozillaFirefox less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070643" comment="mozilla-xulrunner191-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070716" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070644" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070718" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061669" comment="mozilla-xulrunner191-translations less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061670" comment="mozilla-xulrunner191 less than 1.9.1.10-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101197" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1197</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1197" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1197" source="CVE"/>
	<description>
	Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, does not properly handle situations in which both "Content-Disposition: attachment" and "Content-Type: multipart" are present in HTTP headers, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an uploaded HTML document.
	</description>
 </metadata>
<!-- f9b2b1aaa535612c1bff26161e7cb381 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009061668" comment="MozillaFirefox-translations less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061192" comment="MozillaFirefox less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070643" comment="mozilla-xulrunner191-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070716" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070644" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070718" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061669" comment="mozilla-xulrunner191-translations less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061670" comment="mozilla-xulrunner191 less than 1.9.1.10-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101198" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1198</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1198" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1198" source="CVE"/>
	<description>
	Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, allows remote attackers to execute arbitrary code via vectors involving multiple plugin instances.
	</description>
 </metadata>
<!-- f9b2b1aaa535612c1bff26161e7cb381 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009061668" comment="MozillaFirefox-translations less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061192" comment="MozillaFirefox less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070643" comment="mozilla-xulrunner191-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070716" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070644" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070718" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061669" comment="mozilla-xulrunner191-translations less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061670" comment="mozilla-xulrunner191 less than 1.9.1.10-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101199" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1199</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1199" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1199" source="CVE"/>
	<description>
	Integer overflow in the XSLT node sorting implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code via a large text value for a node.
	</description>
 </metadata>
<!-- f9b2b1aaa535612c1bff26161e7cb381 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009061668" comment="MozillaFirefox-translations less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061192" comment="MozillaFirefox less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070643" comment="mozilla-xulrunner191-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070716" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070644" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070718" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061669" comment="mozilla-xulrunner191-translations less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061670" comment="mozilla-xulrunner191 less than 1.9.1.10-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101200" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1200</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1200" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1200" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
<!-- f9b2b1aaa535612c1bff26161e7cb381 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009061668" comment="MozillaFirefox-translations less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061192" comment="MozillaFirefox less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070643" comment="mozilla-xulrunner191-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070716" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070644" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070718" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061669" comment="mozilla-xulrunner191-translations less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061670" comment="mozilla-xulrunner191 less than 1.9.1.10-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101201" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1201</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1201" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1201" source="CVE"/>
	<description>
	Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.10, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
<!-- f9b2b1aaa535612c1bff26161e7cb381 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009061668" comment="MozillaFirefox-translations less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061192" comment="MozillaFirefox less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070643" comment="mozilla-xulrunner191-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070716" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070644" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070718" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061669" comment="mozilla-xulrunner191-translations less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061670" comment="mozilla-xulrunner191 less than 1.9.1.10-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101202" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1202</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1202" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1202" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
<!-- f9b2b1aaa535612c1bff26161e7cb381 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009061668" comment="MozillaFirefox-translations less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061192" comment="MozillaFirefox less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070643" comment="mozilla-xulrunner191-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070716" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070644" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070718" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061669" comment="mozilla-xulrunner191-translations less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061670" comment="mozilla-xulrunner191 less than 1.9.1.10-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101203" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1203</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1203" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1203" source="CVE"/>
	<description>
	The JavaScript engine in Mozilla Firefox 3.6.x before 3.6.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors that trigger an assertion failure in jstracer.cpp.
	</description>
 </metadata>
<!-- f9b2b1aaa535612c1bff26161e7cb381 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009061668" comment="MozillaFirefox-translations less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061192" comment="MozillaFirefox less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070643" comment="mozilla-xulrunner191-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070716" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070644" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070718" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061669" comment="mozilla-xulrunner191-translations less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061670" comment="mozilla-xulrunner191 less than 1.9.1.10-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101205" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1205</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1205" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1205" source="CVE"/>
	<description>
	Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 05599e35a510ca089ac92c0708d24d96 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062299" comment="libpng-devel less than 1.2.31-5.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062258" comment="libpng12-0-32bit less than 1.2.31-5.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062260" comment="libpng12-0 less than 1.2.31-5.18.1"/>
		</criteria>
	</criteria>
	<!-- 0d0d8706df2d64128121ceea3338a129 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061819" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061840" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 1827d5255702922bfdc18e59d59e6a20 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062299" comment="libpng-devel less than 1.2.31-5.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062258" comment="libpng12-0-32bit less than 1.2.31-5.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062260" comment="libpng12-0 less than 1.2.31-5.18.1"/>
		</criteria>
	</criteria>
	<!-- f23d3ef3410fecb23cf62a058d285514 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061819" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061840" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101206" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1206</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1206" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1206" source="CVE"/>
	<description>
	The startDocumentLoad function in browser/base/content/browser.js in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, does not properly implement the Same Origin Policy in certain circumstances related to the about:blank document and a document that is currently loading, which allows (1) remote web servers to conduct spoofing attacks via vectors involving a 204 (aka No Content) status code, and allows (2) remote attackers to conduct spoofing attacks via vectors involving a window.stop call.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0d0d8706df2d64128121ceea3338a129 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061819" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061840" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
	<!-- f23d3ef3410fecb23cf62a058d285514 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061819" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061840" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101208" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1208</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1208" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1208" source="CVE"/>
	<description>
	Use-after-free vulnerability in the attribute-cloning functionality in the DOM implementation in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via vectors related to deletion of an event attribute node with a nonzero reference count.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0d0d8706df2d64128121ceea3338a129 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061819" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061840" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
	<!-- f23d3ef3410fecb23cf62a058d285514 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061819" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061840" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101209" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1209</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1209" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1209" source="CVE"/>
	<description>
	Use-after-free vulnerability in the NodeIterator implementation in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via a crafted NodeFilter that detaches DOM nodes, related to the NodeIterator interface and a javascript callback.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0d0d8706df2d64128121ceea3338a129 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061819" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061840" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
	<!-- f23d3ef3410fecb23cf62a058d285514 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061819" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061840" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101211" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1211</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1211" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1211" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0d0d8706df2d64128121ceea3338a129 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061819" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061840" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
	<!-- f23d3ef3410fecb23cf62a058d285514 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061819" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061840" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101213" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1213</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1213" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1213" source="CVE"/>
	<description>
	The importScripts Web Worker method in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 does not verify that content is valid JavaScript code, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted HTML document.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0d0d8706df2d64128121ceea3338a129 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061819" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061840" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
	<!-- f23d3ef3410fecb23cf62a058d285514 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061819" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061840" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101214" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1214</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1214" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1214" source="CVE"/>
	<description>
	Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via plugin content with many parameter elements.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0d0d8706df2d64128121ceea3338a129 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061819" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061840" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
	<!-- f23d3ef3410fecb23cf62a058d285514 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061819" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061840" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101240" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1240</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1240" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1240" source="CVE"/>
	<description>
	Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of one text field in the Launch File warning dialog, which makes it easier for remote attackers to trick users into executing an arbitrary local program that was specified in a PDF document, as demonstrated by a text field that claims that the Open button will enable the user to read an encrypted message.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 095cf91c7a73fc7f8adfcb7b68dd1ea9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062194" comment="acroread_ja less than 9.3.4-0.1.1"/>
	</criteria>
	<!-- 33cfd1f00fc11a44db9cae1331100365 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061127" comment="acroread-cmaps less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061128" comment="acroread-fonts-ja less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061129" comment="acroread-fonts-ko less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061130" comment="acroread-fonts-zh_CN less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061131" comment="acroread-fonts-zh_TW less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061132" comment="acroread less than 9.3.3-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 36a9cbb312d6ad766eed81d158f1dc01 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062194" comment="acroread_ja less than 9.3.4-0.1.1"/>
	</criteria>
	<!-- 738a9bfc615adca49b1c8c24702d69ab -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061133" comment="acroread_ja less than 9.3.3-0.1.1"/>
	</criteria>
	<!-- af3e139e036f69030f0263d2bf39de4b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061127" comment="acroread-cmaps less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061128" comment="acroread-fonts-ja less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061129" comment="acroread-fonts-ko less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061130" comment="acroread-fonts-zh_CN less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061131" comment="acroread-fonts-zh_TW less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061132" comment="acroread less than 9.3.3-0.1.1"/>
		</criteria>
	</criteria>
	<!-- df4199604d1ebfce8b612958957eb533 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062202" comment="acroread-cmaps less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062203" comment="acroread-fonts-ja less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062204" comment="acroread-fonts-ko less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062205" comment="acroread-fonts-zh_CN less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062206" comment="acroread-fonts-zh_TW less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062207" comment="acroread less than 9.3.4-0.6.1"/>
		</criteria>
	</criteria>
	<!-- f1ea8f5a6e6b82355c9b5987cea86fa1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062202" comment="acroread-cmaps less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062203" comment="acroread-fonts-ja less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062204" comment="acroread-fonts-ko less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062205" comment="acroread-fonts-zh_CN less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062206" comment="acroread-fonts-zh_TW less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062207" comment="acroread less than 9.3.4-0.6.1"/>
		</criteria>
	</criteria>
	<!-- faf9c7e8401c2a5fc98e2cd4840b594b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061133" comment="acroread_ja less than 9.3.3-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101241" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1241</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-1241" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1241" source="CVE"/>
	<description>
	Heap-based buffer overflow in the custom heap management system in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document, aka FG-VD-10-005.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0e9154563fae0e1dd880d336e6cf63c0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059788" comment="acroread_ja less than 9.3.2-0.1.1"/>
	</criteria>
	<!-- b058bb7270eba0f7d737bff88e2592e4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059796" comment="acroread-cmaps less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059797" comment="acroread-fonts-ja less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059798" comment="acroread-fonts-ko less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059799" comment="acroread-fonts-zh_CN less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059800" comment="acroread-fonts-zh_TW less than 9.3.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059801" comment="acroread less than 9.3.2-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101285" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1285</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1285" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1285" source="CVE"/>
	<description>
	Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code via unspecified manipulations involving the newclass (0x58) operator and an "invalid pointer vulnerability" that triggers memory corruption, a different vulnerability than CVE-2010-2168 and CVE-2010-2201.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 33cfd1f00fc11a44db9cae1331100365 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061127" comment="acroread-cmaps less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061128" comment="acroread-fonts-ja less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061129" comment="acroread-fonts-ko less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061130" comment="acroread-fonts-zh_CN less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061131" comment="acroread-fonts-zh_TW less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061132" comment="acroread less than 9.3.3-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 738a9bfc615adca49b1c8c24702d69ab -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061133" comment="acroread_ja less than 9.3.3-0.1.1"/>
	</criteria>
	<!-- af3e139e036f69030f0263d2bf39de4b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061127" comment="acroread-cmaps less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061128" comment="acroread-fonts-ja less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061129" comment="acroread-fonts-ko less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061130" comment="acroread-fonts-zh_CN less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061131" comment="acroread-fonts-zh_TW less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061132" comment="acroread less than 9.3.3-0.1.1"/>
		</criteria>
	</criteria>
	<!-- faf9c7e8401c2a5fc98e2cd4840b594b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061133" comment="acroread_ja less than 9.3.3-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101295" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1295</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1295" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1295" source="CVE"/>
	<description>
	Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2202, CVE-2010-2207, CVE-2010-2209, CVE-2010-2210, CVE-2010-2211, and CVE-2010-2212.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 33cfd1f00fc11a44db9cae1331100365 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061127" comment="acroread-cmaps less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061128" comment="acroread-fonts-ja less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061129" comment="acroread-fonts-ko less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061130" comment="acroread-fonts-zh_CN less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061131" comment="acroread-fonts-zh_TW less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061132" comment="acroread less than 9.3.3-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 738a9bfc615adca49b1c8c24702d69ab -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061133" comment="acroread_ja less than 9.3.3-0.1.1"/>
	</criteria>
	<!-- af3e139e036f69030f0263d2bf39de4b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061127" comment="acroread-cmaps less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061128" comment="acroread-fonts-ja less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061129" comment="acroread-fonts-ko less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061130" comment="acroread-fonts-zh_CN less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061131" comment="acroread-fonts-zh_TW less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061132" comment="acroread less than 9.3.3-0.1.1"/>
		</criteria>
	</criteria>
	<!-- faf9c7e8401c2a5fc98e2cd4840b594b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061133" comment="acroread_ja less than 9.3.3-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101297" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1297</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1297" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1297" source="CVE"/>
	<description>
	Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted SWF content, related to authplay.dll and the ActionScript Virtual Machine 2 (AVM2) newfunction instruction, as exploited in the wild in June 2010.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 33cfd1f00fc11a44db9cae1331100365 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061127" comment="acroread-cmaps less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061128" comment="acroread-fonts-ja less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061129" comment="acroread-fonts-ko less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061130" comment="acroread-fonts-zh_CN less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061131" comment="acroread-fonts-zh_TW less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061132" comment="acroread less than 9.3.3-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 738a9bfc615adca49b1c8c24702d69ab -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061133" comment="acroread_ja less than 9.3.3-0.1.1"/>
	</criteria>
	<!-- 9fed1ac7d6ac263f8b42cb8e24927e67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
	<!-- af3e139e036f69030f0263d2bf39de4b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061127" comment="acroread-cmaps less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061128" comment="acroread-fonts-ja less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061129" comment="acroread-fonts-ko less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061130" comment="acroread-fonts-zh_CN less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061131" comment="acroread-fonts-zh_TW less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061132" comment="acroread less than 9.3.3-0.1.1"/>
		</criteria>
	</criteria>
	<!-- dc5e2e29ebe98d9444b78ef5643bf4f1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
	<!-- faf9c7e8401c2a5fc98e2cd4840b594b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061133" comment="acroread_ja less than 9.3.3-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101321" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1321</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1321" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1321" source="CVE"/>
	<description>
	The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (aka krb5) through 1.7.1 and 1.8 before 1.8.2, as used in kadmind and other applications, does not properly check for invalid GSS-API tokens, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via an AP-REQ message in which the authenticator's checksum field is missing.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 7d2fb2e31f042d9b40de3903d2d7d5fd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060710" comment="krb5-32bit less than 1.6.3-133.33.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060713" comment="krb5-client less than 1.6.3-133.33.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060716" comment="krb5 less than 1.6.3-133.33.1"/>
		</criteria>
	</criteria>
	<!-- b2b07a19e980175398d729721ec11514 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063824" comment="java-1_6_0-sun-alsa less than 1.6.0.u22-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063825" comment="java-1_6_0-sun-demo less than 1.6.0.u22-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063827" comment="java-1_6_0-sun-jdbc less than 1.6.0.u22-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063828" comment="java-1_6_0-sun-plugin less than 1.6.0.u22-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063829" comment="java-1_6_0-sun-src less than 1.6.0.u22-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063830" comment="java-1_6_0-sun less than 1.6.0.u22-1.2.1"/>
		</criteria>
	</criteria>
	<!-- ba7daf7a40cb6e230a70a5af7587cb48 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063824" comment="java-1_6_0-sun-alsa less than 1.6.0.u22-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063825" comment="java-1_6_0-sun-demo less than 1.6.0.u22-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063827" comment="java-1_6_0-sun-jdbc less than 1.6.0.u22-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063828" comment="java-1_6_0-sun-plugin less than 1.6.0.u22-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063829" comment="java-1_6_0-sun-src less than 1.6.0.u22-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063830" comment="java-1_6_0-sun less than 1.6.0.u22-1.2.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101323" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1323</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1323" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1323" source="CVE"/>
	<description>
	MIT Kerberos 5 (aka krb5) 1.3.x, 1.4.x, 1.5.x, 1.6.x, 1.7.x, and 1.8.x through 1.8.3 does not properly determine the acceptability of checksums, which might allow remote attackers to modify user-visible prompt text, modify a response to a Key Distribution Center (KDC), or forge a KRB-SAFE message via certain checksums that (1) are unkeyed or (2) use RC4 keys.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 23219794593188e3b87f7770060cff7a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064607" comment="krb5-32bit less than 1.6.3-133.39.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064610" comment="krb5-client less than 1.6.3-133.39.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064613" comment="krb5 less than 1.6.3-133.39.1"/>
		</criteria>
	</criteria>
	<!-- 2c00c569cf8c668fd2c6865d49aaf3ed -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064607" comment="krb5-32bit less than 1.6.3-133.39.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064610" comment="krb5-client less than 1.6.3-133.39.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064613" comment="krb5 less than 1.6.3-133.39.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101324" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1324</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1324" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1324" source="CVE"/>
	<description>
	MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x through 1.8.3 does not properly determine the acceptability of checksums, which might allow remote attackers to forge GSS tokens, gain privileges, or have unspecified other impact via (1) an unkeyed checksum, (2) an unkeyed PAC checksum, or (3) a KrbFastArmoredReq checksum based on an RC4 key.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 23219794593188e3b87f7770060cff7a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064607" comment="krb5-32bit less than 1.6.3-133.39.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064610" comment="krb5-client less than 1.6.3-133.39.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064613" comment="krb5 less than 1.6.3-133.39.1"/>
		</criteria>
	</criteria>
	<!-- 2c00c569cf8c668fd2c6865d49aaf3ed -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064607" comment="krb5-32bit less than 1.6.3-133.39.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064610" comment="krb5-client less than 1.6.3-133.39.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064613" comment="krb5 less than 1.6.3-133.39.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101437" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1437</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-1437" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1437" source="CVE"/>
	<description>
	Race condition in the find_keyring_by_name function in security/keys/keyring.c in the Linux kernel 2.6.34-rc5 and earlier allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via keyctl session commands that trigger access to a dead keyring that is undergoing deletion by the key_cleanup function.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 66504af0afe753b5175112b44bc8827d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061675" comment="kernel-default-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061679" comment="kernel-pae-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061680" comment="kernel-pae-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061681" comment="kernel-pae less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061693" comment="kernel-xen-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- c8a29eec659b0b2b3e85c610b67beacd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061675" comment="kernel-default-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061693" comment="kernel-xen-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101440" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1440</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-1440" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1440" source="CVE"/>
	<description>
	Multiple integer overflows in dvipsk/dospecial.c in dvips in TeX Live 2009 and earlier, and teTeX, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a special command in a DVI file, related to the (1) predospecial and (2) bbdospecial functions, a different vulnerability than CVE-2010-0739.
	</description>
 </metadata>
<!-- b9c522a3bd2322d1a9203c227b8a5c35 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060471" comment="texlive-cjk less than 2007-219.32.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060476" comment="texlive-jadetex less than 2007-219.32.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060478" comment="texlive-latex less than 2007-219.32.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060484" comment="texlive-tools less than 2007-219.32.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060487" comment="texlive less than 2007-219.32.13.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101446" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1446</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-1446" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1446" source="CVE"/>
	<description>
	arch/powerpc/mm/fsl_booke_mmu.c in KGDB in the Linux kernel 2.6.30 and other versions before 2.6.33, when running on PowerPC, does not properly perform a security check for access to a kernel page, which allows local users to overwrite arbitrary kernel memory, related to Fsl booke.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 66504af0afe753b5175112b44bc8827d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061675" comment="kernel-default-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061679" comment="kernel-pae-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061680" comment="kernel-pae-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061681" comment="kernel-pae less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061693" comment="kernel-xen-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- c8a29eec659b0b2b3e85c610b67beacd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061675" comment="kernel-default-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061693" comment="kernel-xen-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101447" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1447</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1447" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1447" source="CVE"/>
	<description>
	The Safe (aka Safe.pm) module 2.26, and certain earlier versions, for Perl, as used in PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, 8.4 before 8.4.4, and 9.0 Beta before 9.0 Beta 2, allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access restrictions, and inject and execute arbitrary code, via vectors involving subroutine references and delayed execution.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 20ed7ae57e909277c40c8e5c6d74b113 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061998" comment="perl-32bit less than 5.10.0-64.48.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061999" comment="perl-base less than 5.10.0-64.48.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062000" comment="perl-doc less than 5.10.0-64.48.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062002" comment="perl less than 5.10.0-64.48.1"/>
		</criteria>
	</criteria>
	<!-- fc6f7dab4b52caad2fdcf02ae40651a3 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062003" comment="perl-32bit less than 5.10.0-64.44.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062004" comment="perl-base less than 5.10.0-64.44.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062005" comment="perl-doc less than 5.10.0-64.44.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062007" comment="perl less than 5.10.0-64.44.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101455" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1455</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1455" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1455" source="CVE"/>
	<description>
	The DOCSIS dissector in Wireshark 0.9.6 through 1.0.12 and 1.2.0 through 1.2.7 allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed packet trace file.
	</description>
 </metadata>
<!-- 6e5fc6e202651e8b93c830786b3ea82f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066948" comment="wireshark less than 1.4.4-0.2.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101459" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1459</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1459" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1459" source="CVE"/>
	<description>
	The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by the __VIEWSTATE parameter to 2.0/menu/menu1.aspx in the XSP sample project.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 055ed9dbd62292a40d356dcbe57b5733 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060638" comment="bytefx-data-mysql less than 2.0.1-1.20.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060645" comment="ibm-data-db2 less than 2.0.1-1.20.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060503" comment="mono-core less than 2.0.1-1.20.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060639" comment="mono-data-firebird less than 2.0.1-1.20.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060640" comment="mono-data-oracle less than 2.0.1-1.20.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060504" comment="mono-data-postgresql less than 2.0.1-1.20.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060505" comment="mono-data-sqlite less than 2.0.1-1.20.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060641" comment="mono-data-sybase less than 2.0.1-1.20.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060506" comment="mono-data less than 2.0.1-1.20.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060642" comment="mono-devel less than 2.0.1-1.20.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060643" comment="mono-extras less than 2.0.1-1.20.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060644" comment="mono-jscript less than 2.0.1-1.20.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060507" comment="mono-locale-extras less than 2.0.1-1.20.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060508" comment="mono-nunit less than 2.0.1-1.20.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060509" comment="mono-web less than 2.0.1-1.20.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060510" comment="mono-winforms less than 2.0.1-1.20.1"/>
		</criteria>
	</criteria>
	<!-- a9c344651b16899f6cc23f4e77a26a21 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060811" comment="bytefx-data-mysql less than 2.0.1-1.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060818" comment="ibm-data-db2 less than 2.0.1-1.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060801" comment="mono-core less than 2.0.1-1.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060812" comment="mono-data-firebird less than 2.0.1-1.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060813" comment="mono-data-oracle less than 2.0.1-1.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060802" comment="mono-data-postgresql less than 2.0.1-1.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060803" comment="mono-data-sqlite less than 2.0.1-1.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060814" comment="mono-data-sybase less than 2.0.1-1.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060804" comment="mono-data less than 2.0.1-1.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060815" comment="mono-devel less than 2.0.1-1.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060816" comment="mono-extras less than 2.0.1-1.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060817" comment="mono-jscript less than 2.0.1-1.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060805" comment="mono-locale-extras less than 2.0.1-1.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060806" comment="mono-nunit less than 2.0.1-1.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060807" comment="mono-web less than 2.0.1-1.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060808" comment="mono-winforms less than 2.0.1-1.26.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101526" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1526</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1526" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1526" source="CVE"/>
	<description>
	Multiple integer overflows in libgdiplus 2.6.7, as used in Mono, allow attackers to execute arbitrary code via (1) a crafted TIFF file, related to the gdip_load_tiff_image function in tiffcodec.c; (2) a crafted JPEG file, related to the gdip_load_jpeg_image_internal function in jpegcodec.c; or (3) a crafted BMP file, related to the gdip_read_bmp_image function in bmpcodec.c, leading to heap-based buffer overflows.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 496c6871f3bf4f76f48a079d50e33a77 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063122" comment="libgdiplus0 less than 2.0-11.20.1"/>
	</criteria>
	<!-- 596590317a41da978b922e975ea21a2f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063122" comment="libgdiplus0 less than 2.0-11.20.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101585" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1585</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1585" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1585" source="CVE"/>
	<description>
	The nsIScriptableUnescapeHTML.parseFragment method in the ParanoidFragmentSink protection mechanism in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 does not properly sanitize HTML in a chrome document, which makes it easier for remote attackers to execute arbitrary JavaScript with chrome privileges via a javascript: URI in input to an extension, as demonstrated by a javascript:alert sequence in (1) the HREF attribute of an A element or (2) the ACTION attribute of a FORM element.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5b3126494e7cb37fbd4e5a7a4552f1b5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009066062" comment="mozilla-xulrunner191-32bit less than 1.9.1.17-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066100" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.17-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066063" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.17-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066119" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.17-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066064" comment="mozilla-xulrunner191-translations less than 1.9.1.17-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066066" comment="mozilla-xulrunner191 less than 1.9.1.17-0.2.1"/>
		</criteria>
	</criteria>
	<!-- d48e349f4201c980257257ac4c9d7559 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009066067" comment="MozillaFirefox-translations less than 3.6.15-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066068" comment="MozillaFirefox less than 3.6.15-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066069" comment="mozilla-xulrunner192-32bit less than 1.9.2.15-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066113" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.15-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066070" comment="mozilla-xulrunner192-gnome less than 1.9.2.15-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066122" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.15-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066071" comment="mozilla-xulrunner192-translations less than 1.9.2.15-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066073" comment="mozilla-xulrunner192 less than 1.9.2.15-0.2.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101624" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1624</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1624" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1624" source="CVE"/>
	<description>
	The msn_emoticon_msg function in slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.7.0 allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a custom emoticon in a malformed SLP message.
	</description>
 </metadata>
<!-- 6cdaa4e3a37a6a1c95ec78534a5076c8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009071805" comment="finch less than 2.6.6-0.9.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009071807" comment="libpurple-lang less than 2.6.6-0.9.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009071811" comment="libpurple-meanwhile less than 2.6.6-0.9.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009071812" comment="libpurple-tcl less than 2.6.6-0.9.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009071808" comment="libpurple less than 2.6.6-0.9.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009071810" comment="pidgin less than 2.6.6-0.9.2"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101626" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1626</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1626" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1626" source="CVE"/>
	<description>
	MySQL before 5.1.46 allows local users to delete the data and index files of another user's MyISAM table via a symlink attack in conjunction with the DROP TABLE command, a different vulnerability than CVE-2008-4098 and CVE-2008-7247.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1873ab41de744ae673270530913eb01c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063483" comment="libmysqlclient15-32bit less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063485" comment="libmysqlclient15 less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063557" comment="libmysqlclient_r15-32bit less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063486" comment="libmysqlclient_r15 less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063488" comment="mysql-client less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063489" comment="mysql less than 5.0.67-13.26.1"/>
		</criteria>
	</criteria>
	<!-- 471c09c97921274cec802d6f971c4d92 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063483" comment="libmysqlclient15-32bit less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063485" comment="libmysqlclient15 less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063557" comment="libmysqlclient_r15-32bit less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063486" comment="libmysqlclient_r15 less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063488" comment="mysql-client less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063489" comment="mysql less than 5.0.67-13.26.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101628" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1628</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1628" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1628" source="CVE"/>
	<description>
	Ghostscript 8.64, 8.70, and possibly other versions allows context-dependent attackers to execute arbitrary code via a PostScript file containing unlimited recursive procedure invocations, which trigger memory corruption in the stack of the interpreter.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 050a560119b003b7f093735ee4ea36d0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061853" comment="ghostscript-fonts-other less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061854" comment="ghostscript-fonts-rus less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061855" comment="ghostscript-fonts-std less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061856" comment="ghostscript-library less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061857" comment="ghostscript-omni less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061858" comment="ghostscript-x11 less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061859" comment="libgimpprint less than 4.2.7-32.28.1"/>
		</criteria>
	</criteria>
	<!-- 8ea47e7a8ca134ad54f518d9ea69e5c0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061860" comment="ghostscript-fonts-other less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061861" comment="ghostscript-fonts-rus less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061862" comment="ghostscript-fonts-std less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061863" comment="ghostscript-library less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061864" comment="ghostscript-omni less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061865" comment="ghostscript-x11 less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061866" comment="libgimpprint less than 4.2.7-32.27.26.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101634" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1634</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1634" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1634" source="CVE"/>
	<description>
	Multiple integer overflows in audioop.c in the audioop module in Python 2.6, 2.7, 3.1, and 3.2 allow context-dependent attackers to cause a denial of service (application crash) via a large fragment, as demonstrated by a call to audioop.lin2lin with a long string in the first argument, leading to a buffer overflow.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-3143.5.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2aff67bb465d1d97e63189fa1499680b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064997" comment="libpython2_6-1_0-32bit less than 2.6.0-8.8.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064999" comment="libpython2_6-1_0 less than 2.6.0-8.8.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065001" comment="python-base-32bit less than 2.6.0-8.8.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065003" comment="python-base less than 2.6.0-8.8.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065004" comment="python-curses less than 2.6.0-8.9.6.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065053" comment="python-devel less than 2.6.0-8.8.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065010" comment="python-xml less than 2.6.0-8.8.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065011" comment="python less than 2.6.0-8.9.6.2"/>
		</criteria>
	</criteria>
	<!-- bf45eab61dc9da04aa81b9581e8eab85 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009065012" comment="libpython2_6-1_0-32bit less than 2.6.0-8.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065014" comment="libpython2_6-1_0 less than 2.6.0-8.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065016" comment="python-base-32bit less than 2.6.0-8.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065018" comment="python-base less than 2.6.0-8.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065019" comment="python-curses less than 2.6.0-8.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065054" comment="python-devel less than 2.6.0-8.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065023" comment="python-tk less than 2.6.0-8.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065025" comment="python-xml less than 2.6.0-8.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065026" comment="python less than 2.6.0-8.10.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101635" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1635</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1635" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1635" source="CVE"/>
	<description>
	The chain_reply function in process.c in smbd in Samba before 3.4.8 and 3.5.x before 3.5.2 allows remote attackers to cause a denial of service (NULL pointer dereference and process crash) via a Negotiate Protocol request with a certain 0x0003 field value followed by a Session Setup AndX request with a certain 0x8003 field value.
	</description>
 </metadata>
<!-- a35d137f63812ef26e72ebf6bc667db4 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009062261" comment="cifs-mount less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062263" comment="libsmbclient0-32bit less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062265" comment="libsmbclient0 less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062266" comment="libtalloc1-32bit less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062268" comment="libtalloc1 less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062269" comment="libtdb1-32bit less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062271" comment="libtdb1 less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062272" comment="libwbclient0-32bit less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062274" comment="libwbclient0 less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062275" comment="samba-32bit less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062276" comment="samba-client-32bit less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062278" comment="samba-client less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062279" comment="samba-doc less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062280" comment="samba-krb-printing less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062281" comment="samba-winbind-32bit less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062283" comment="samba-winbind less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062285" comment="samba less than 3.4.3-1.18.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101639" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1639</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1639" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1639" source="CVE"/>
	<description>
	The cli_pdf function in libclamav/pdf.c in ClamAV before 0.96.1 allows remote attackers to cause a denial of service (crash) via a malformed PDF file, related to an inconsistency in the calculated stream length and the real stream length.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 20f5aca22421a30b30c0800846b2cee7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061754" comment="clamav less than 0.96.1-0.1.1"/>
	</criteria>
	<!-- 37527c910209c36cd43ddbbcbba1c5e1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061754" comment="clamav less than 0.96.1-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101640" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1640</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1640" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1640" source="CVE"/>
	<description>
	Off-by-one error in the parseicon function in libclamav/pe_icons.c in ClamAV 0.96 allows remote attackers to cause a denial of service (crash) via a crafted PE icon that triggers an out-of-bounds read, related to improper rounding during scaling.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 20f5aca22421a30b30c0800846b2cee7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061754" comment="clamav less than 0.96.1-0.1.1"/>
	</criteria>
	<!-- 37527c910209c36cd43ddbbcbba1c5e1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061754" comment="clamav less than 0.96.1-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101641" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1641</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1641" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1641" source="CVE"/>
	<description>
	The do_gfs2_set_flags function in fs/gfs2/file.c in the Linux kernel before 2.6.34-git10 does not verify the ownership of a file, which allows local users to bypass intended access restrictions via a SETFLAGS ioctl request.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 01f44594f9d8615a4c725ad4472abb2b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061868" comment="btrfs-kmp-default less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061869" comment="btrfs-kmp-xen less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061872" comment="hyper-v-kmp-default less than 0_2.6.32.13_0.5-0.7.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061873" comment="kernel-default-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061874" comment="kernel-default-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061945" comment="kernel-default-extra less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061875" comment="kernel-default less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061946" comment="kernel-desktop-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061876" comment="kernel-source less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061877" comment="kernel-syms less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061881" comment="kernel-xen-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061882" comment="kernel-xen-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061947" comment="kernel-xen-extra less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061883" comment="kernel-xen less than 2.6.32.13-0.5.1"/>
		</criteria>
	</criteria>
	<!-- 66504af0afe753b5175112b44bc8827d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061675" comment="kernel-default-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061679" comment="kernel-pae-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061680" comment="kernel-pae-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061681" comment="kernel-pae less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061693" comment="kernel-xen-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- c8a29eec659b0b2b3e85c610b67beacd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061675" comment="kernel-default-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061693" comment="kernel-xen-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- caf966715fc66f993dd8892aa75742ad -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061868" comment="btrfs-kmp-default less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061889" comment="btrfs-kmp-pae less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061869" comment="btrfs-kmp-xen less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061872" comment="hyper-v-kmp-default less than 0_2.6.32.13_0.5-0.7.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061891" comment="hyper-v-kmp-pae less than 0_2.6.32.13_0.5-0.7.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061873" comment="kernel-default-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061874" comment="kernel-default-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061945" comment="kernel-default-extra less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061875" comment="kernel-default less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061946" comment="kernel-desktop-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061892" comment="kernel-pae-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061893" comment="kernel-pae-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061948" comment="kernel-pae-extra less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061894" comment="kernel-pae less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061876" comment="kernel-source less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061877" comment="kernel-syms less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061881" comment="kernel-xen-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061882" comment="kernel-xen-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061947" comment="kernel-xen-extra less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061883" comment="kernel-xen less than 2.6.32.13-0.5.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101643" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1643</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-1643" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1643" source="CVE"/>
	<description>
	mm/shmem.c in the Linux kernel before 2.6.28-rc3, when strict overcommit is enabled, does not properly handle the export of shmemfs objects by knfsd, which allows attackers to cause a denial of service (NULL pointer dereference and knfsd crash) or possibly have unspecified other impact via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 66504af0afe753b5175112b44bc8827d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061675" comment="kernel-default-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061679" comment="kernel-pae-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061680" comment="kernel-pae-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061681" comment="kernel-pae less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061693" comment="kernel-xen-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- c8a29eec659b0b2b3e85c610b67beacd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061675" comment="kernel-default-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061693" comment="kernel-xen-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101748" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1748</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1748" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1748" source="CVE"/>
	<description>
	The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request, as demonstated by the (1) /admin?OP=redirect&amp;URL=% and (2) /admin?URL=/admin/&amp;OP=% URIs.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- d603aeff8a309d9d04651d4469e31973 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064776" comment="cups-client less than 1.3.9-8.37.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064777" comment="cups-libs-32bit less than 1.3.9-8.37.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064779" comment="cups-libs less than 1.3.9-8.37.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064780" comment="cups less than 1.3.9-8.37.1"/>
		</criteria>
	</criteria>
	<!-- e290f3059978b800480c09727b4b714a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064776" comment="cups-client less than 1.3.9-8.37.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064777" comment="cups-libs-32bit less than 1.3.9-8.37.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064779" comment="cups-libs less than 1.3.9-8.37.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064780" comment="cups less than 1.3.9-8.37.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101797" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1797</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1797" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1797" source="CVE"/>
	<description>
	Multiple stack-based buffer overflows in the cff_decoder_parse_charstrings function in the CFF Type2 CharStrings interpreter in cff/cffgload.c in FreeType before 2.4.2, as used in Apple iOS before 4.0.2 on the iPhone and iPod touch and before 3.2.2 on the iPad, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted CFF opcodes in embedded fonts in a PDF document, as demonstrated by JailbreakMe. NOTE: some of these details are obtained from third party information.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 7bcc9a1fade88c7620df728424de42c5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062111" comment="freetype2-devel less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
	<!-- f28613bd3eb0b0f8e83bbf97c432760b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062111" comment="freetype2-devel less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101848" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1848</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1848" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1848" source="CVE"/>
	<description>
	Directory traversal vulnerability in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to bypass intended table grants to read field definitions of arbitrary tables, and on 5.1 to read or delete content of arbitrary tables, via a .. (dot dot) in a table name.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1873ab41de744ae673270530913eb01c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063483" comment="libmysqlclient15-32bit less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063485" comment="libmysqlclient15 less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063557" comment="libmysqlclient_r15-32bit less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063486" comment="libmysqlclient_r15 less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063488" comment="mysql-client less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063489" comment="mysql less than 5.0.67-13.26.1"/>
		</criteria>
	</criteria>
	<!-- 471c09c97921274cec802d6f971c4d92 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063483" comment="libmysqlclient15-32bit less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063485" comment="libmysqlclient15 less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063557" comment="libmysqlclient_r15-32bit less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063486" comment="libmysqlclient_r15 less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063488" comment="mysql-client less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063489" comment="mysql less than 5.0.67-13.26.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101849" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1849</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1849" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1849" source="CVE"/>
	<description>
	The my_net_skip_rest function in sql/net_serv.cc in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by sending a large number of packets that exceed the maximum length.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1873ab41de744ae673270530913eb01c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063483" comment="libmysqlclient15-32bit less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063485" comment="libmysqlclient15 less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063557" comment="libmysqlclient_r15-32bit less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063486" comment="libmysqlclient_r15 less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063488" comment="mysql-client less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063489" comment="mysql less than 5.0.67-13.26.1"/>
		</criteria>
	</criteria>
	<!-- 471c09c97921274cec802d6f971c4d92 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063483" comment="libmysqlclient15-32bit less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063485" comment="libmysqlclient15 less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063557" comment="libmysqlclient_r15-32bit less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063486" comment="libmysqlclient_r15 less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063488" comment="mysql-client less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063489" comment="mysql less than 5.0.67-13.26.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101850" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1850</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1850" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1850" source="CVE"/>
	<description>
	Buffer overflow in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to execute arbitrary code via a COM_FIELD_LIST command with a long table name.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1873ab41de744ae673270530913eb01c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063483" comment="libmysqlclient15-32bit less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063485" comment="libmysqlclient15 less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063557" comment="libmysqlclient_r15-32bit less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063486" comment="libmysqlclient_r15 less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063488" comment="mysql-client less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063489" comment="mysql less than 5.0.67-13.26.1"/>
		</criteria>
	</criteria>
	<!-- 471c09c97921274cec802d6f971c4d92 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063483" comment="libmysqlclient15-32bit less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063485" comment="libmysqlclient15 less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063557" comment="libmysqlclient_r15-32bit less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063486" comment="libmysqlclient_r15 less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063488" comment="mysql-client less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063489" comment="mysql less than 5.0.67-13.26.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101869" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1869</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1869" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1869" source="CVE"/>
	<description>
	Stack-based buffer overflow in the parser function in GhostScript 8.70 and 8.64 allows context-dependent attackers to execute arbitrary code via a crafted PostScript file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 050a560119b003b7f093735ee4ea36d0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061853" comment="ghostscript-fonts-other less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061854" comment="ghostscript-fonts-rus less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061855" comment="ghostscript-fonts-std less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061856" comment="ghostscript-library less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061857" comment="ghostscript-omni less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061858" comment="ghostscript-x11 less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061859" comment="libgimpprint less than 4.2.7-32.28.1"/>
		</criteria>
	</criteria>
	<!-- 8ea47e7a8ca134ad54f518d9ea69e5c0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061860" comment="ghostscript-fonts-other less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061861" comment="ghostscript-fonts-rus less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061862" comment="ghostscript-fonts-std less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061863" comment="ghostscript-library less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061864" comment="ghostscript-omni less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061865" comment="ghostscript-x11 less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061866" comment="libgimpprint less than 4.2.7-32.27.26.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101975" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1975</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1975" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1975" source="CVE"/>
	<description>
	PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, and 8.4 before 8.4.4 does not properly check privileges during certain RESET ALL operations, which allows remote authenticated users to remove arbitrary parameter settings via a (1) ALTER USER or (2) ALTER DATABASE statement.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1623a9038b26e4b2fb345e388ebf6ca9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061273" comment="postgresql-libs-32bit less than 8.3.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061275" comment="postgresql-libs less than 8.3.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061277" comment="postgresql less than 8.3.11-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 3583616cbc2a604051aee34d4ba07c2c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061277" comment="postgresql less than 8.3.11-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102055" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2055</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2055" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2055" source="CVE"/>
	<description>
	Ghostscript 8.71 and earlier reads initialization files from the current working directory, which allows local users to execute arbitrary PostScript commands via a Trojan horse file, related to improper support for the -P- option to the gs program.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 050a560119b003b7f093735ee4ea36d0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061853" comment="ghostscript-fonts-other less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061854" comment="ghostscript-fonts-rus less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061855" comment="ghostscript-fonts-std less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061856" comment="ghostscript-library less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061857" comment="ghostscript-omni less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061858" comment="ghostscript-x11 less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061859" comment="libgimpprint less than 4.2.7-32.28.1"/>
		</criteria>
	</criteria>
	<!-- 8ea47e7a8ca134ad54f518d9ea69e5c0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061860" comment="ghostscript-fonts-other less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061861" comment="ghostscript-fonts-rus less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061862" comment="ghostscript-fonts-std less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061863" comment="ghostscript-library less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061864" comment="ghostscript-omni less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061865" comment="ghostscript-x11 less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061866" comment="libgimpprint less than 4.2.7-32.27.26.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102059" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2059</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2059" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2059" source="CVE"/>
	<description>
	lib/fsm.c in RPM 4.8.0 and unspecified 4.7.x and 4.6.x versions, and RPM before 4.4.3, does not properly reset the metadata of an executable file during replacement of the file in an RPM package upgrade, which might allow local users to gain privileges by creating a hard link to a vulnerable (1) setuid or (2) setgid file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 32f4960f9da43da922885fefb185f7d9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062630" comment="popt-32bit less than 1.7-37.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062632" comment="popt less than 1.7-37.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062633" comment="rpm-32bit less than 4.4.2.3-37.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062635" comment="rpm less than 4.4.2.3-37.18.1"/>
		</criteria>
	</criteria>
	<!-- 63795266ceb69301f2e2befb061ad04f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062630" comment="popt-32bit less than 1.7-37.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062632" comment="popt less than 1.7-37.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062633" comment="rpm-32bit less than 4.4.2.3-37.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062635" comment="rpm less than 4.4.2.3-37.18.1"/>
		</criteria>
	</criteria>
	<!-- a609488caffd89cdc3149aaed0a4cf7c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064944" comment="popt-32bit less than 1.7-37.25.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064946" comment="popt less than 1.7-37.25.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064947" comment="rpm-32bit less than 4.4.2.3-37.25.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064949" comment="rpm less than 4.4.2.3-37.25.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102063" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2063</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-2063" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2063" source="CVE"/>
	<description>
	Buffer overflow in the SMB1 packet chaining implementation in the chain_reply function in process.c in smbd in Samba 3.0.x before 3.3.13 allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a crafted field in a packet.
	</description>
 </metadata>
<!-- 38b274074b3d5ef4abafff31fa80e561 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060901" comment="cifs-mount less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060903" comment="libsmbclient0-32bit less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060905" comment="libsmbclient0 less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060906" comment="libtalloc1-32bit less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060908" comment="libtalloc1 less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060909" comment="libtdb1-32bit less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060911" comment="libtdb1 less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060912" comment="libwbclient0-32bit less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060914" comment="libwbclient0 less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060915" comment="samba-32bit less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060916" comment="samba-client-32bit less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060918" comment="samba-client less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060919" comment="samba-krb-printing less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060997" comment="samba-vscan less than 0.3.6b-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060920" comment="samba-winbind-32bit less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060922" comment="samba-winbind less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060924" comment="samba less than 3.2.7-11.20.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102066" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2066</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2066" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2066" source="CVE"/>
	<description>
	The mext_check_arguments function in fs/ext4/move_extent.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a MOVE_EXT ioctl call that specifies this file as a donor.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 01f44594f9d8615a4c725ad4472abb2b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061868" comment="btrfs-kmp-default less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061869" comment="btrfs-kmp-xen less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061872" comment="hyper-v-kmp-default less than 0_2.6.32.13_0.5-0.7.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061873" comment="kernel-default-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061874" comment="kernel-default-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061945" comment="kernel-default-extra less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061875" comment="kernel-default less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061946" comment="kernel-desktop-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061876" comment="kernel-source less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061877" comment="kernel-syms less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061881" comment="kernel-xen-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061882" comment="kernel-xen-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061947" comment="kernel-xen-extra less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061883" comment="kernel-xen less than 2.6.32.13-0.5.1"/>
		</criteria>
	</criteria>
	<!-- caf966715fc66f993dd8892aa75742ad -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061868" comment="btrfs-kmp-default less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061889" comment="btrfs-kmp-pae less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061869" comment="btrfs-kmp-xen less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061872" comment="hyper-v-kmp-default less than 0_2.6.32.13_0.5-0.7.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061891" comment="hyper-v-kmp-pae less than 0_2.6.32.13_0.5-0.7.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061873" comment="kernel-default-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061874" comment="kernel-default-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061945" comment="kernel-default-extra less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061875" comment="kernel-default less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061946" comment="kernel-desktop-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061892" comment="kernel-pae-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061893" comment="kernel-pae-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061948" comment="kernel-pae-extra less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061894" comment="kernel-pae less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061876" comment="kernel-source less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061877" comment="kernel-syms less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061881" comment="kernel-xen-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061882" comment="kernel-xen-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061947" comment="kernel-xen-extra less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061883" comment="kernel-xen less than 2.6.32.13-0.5.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102074" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2074</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2074" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2074" source="CVE"/>
	<description>
	istream.c in w3m 0.5.2 and possibly other versions, when ssl_verify_server is enabled, does not properly handle a '\0' character in a domain name in the (1) subject's Common Name or (2) Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- e1f25a08a12598e8317948de7f9884c3 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061665" comment="w3m less than 0.5.2-128.18.1"/>
	</criteria>
	<!-- ebf1dbef4636e519d87ba8de9c445943 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061666" comment="w3m less than 0.5.2-132.2.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102077" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2077</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2077" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2077" source="CVE"/>
	<description>
	** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2010-1640.  Reason: This candidate is a duplicate of CVE-2010-1640.  Notes: All CVE users should reference CVE-2010-1640 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 20f5aca22421a30b30c0800846b2cee7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061754" comment="clamav less than 0.96.1-0.1.1"/>
	</criteria>
	<!-- 37527c910209c36cd43ddbbcbba1c5e1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061754" comment="clamav less than 0.96.1-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102089" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2089</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2089" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2089" source="CVE"/>
	<description>
	The audioop module in Python 2.7 and 3.2 does not verify the relationships between size arguments and byte string lengths, which allows context-dependent attackers to cause a denial of service (memory corruption and application crash) via crafted arguments, as demonstrated by a call to audioop.reverse with a one-byte string, a different vulnerability than CVE-2010-1634.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2aff67bb465d1d97e63189fa1499680b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064997" comment="libpython2_6-1_0-32bit less than 2.6.0-8.8.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064999" comment="libpython2_6-1_0 less than 2.6.0-8.8.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065001" comment="python-base-32bit less than 2.6.0-8.8.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065003" comment="python-base less than 2.6.0-8.8.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065004" comment="python-curses less than 2.6.0-8.9.6.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065053" comment="python-devel less than 2.6.0-8.8.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065010" comment="python-xml less than 2.6.0-8.8.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065011" comment="python less than 2.6.0-8.9.6.2"/>
		</criteria>
	</criteria>
	<!-- bf45eab61dc9da04aa81b9581e8eab85 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009065012" comment="libpython2_6-1_0-32bit less than 2.6.0-8.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065014" comment="libpython2_6-1_0 less than 2.6.0-8.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065016" comment="python-base-32bit less than 2.6.0-8.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065018" comment="python-base less than 2.6.0-8.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065019" comment="python-curses less than 2.6.0-8.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065054" comment="python-devel less than 2.6.0-8.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065023" comment="python-tk less than 2.6.0-8.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065025" comment="python-xml less than 2.6.0-8.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065026" comment="python less than 2.6.0-8.10.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102160" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2160</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2160" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2160" source="CVE"/>
	<description>
	Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via an invalid offset in an unspecified undocumented opcode in ActionScript Virtual Machine 2, related to getouterscope, a different vulnerability than CVE-2010-2165, CVE-2010-2166, CVE-2010-2171, CVE-2010-2175, CVE-2010-2176, CVE-2010-2177, CVE-2010-2178, CVE-2010-2180, CVE-2010-2182, CVE-2010-2184, CVE-2010-2187, and CVE-2010-2188.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 9fed1ac7d6ac263f8b42cb8e24927e67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
	<!-- dc5e2e29ebe98d9444b78ef5643bf4f1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102161" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2161</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2161" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2161" source="CVE"/>
	<description>
	Array index error in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers to execute arbitrary code via unspecified "types of Adobe Flash code."
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 9fed1ac7d6ac263f8b42cb8e24927e67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
	<!-- dc5e2e29ebe98d9444b78ef5643bf4f1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102162" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2162</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2162" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2162" source="CVE"/>
	<description>
	Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (heap memory corruption) or possibly execute arbitrary code via vectors related to improper length calculation and the (1) STSC, (2) STSZ, and (3) STCO atoms.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 9fed1ac7d6ac263f8b42cb8e24927e67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
	<!-- dc5e2e29ebe98d9444b78ef5643bf4f1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102163" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2163</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2163" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2163" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers to execute arbitrary code via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 9fed1ac7d6ac263f8b42cb8e24927e67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
	<!-- dc5e2e29ebe98d9444b78ef5643bf4f1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102164" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2164</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2164" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2164" source="CVE"/>
	<description>
	Use-after-free vulnerability in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers to execute arbitrary code via unspecified vectors related to an unspecified "image type within a certain function."
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 9fed1ac7d6ac263f8b42cb8e24927e67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
	<!-- dc5e2e29ebe98d9444b78ef5643bf4f1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102165" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2165</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2165" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2165" source="CVE"/>
	<description>
	Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-2160, CVE-2010-2166, CVE-2010-2171, CVE-2010-2175, CVE-2010-2176, CVE-2010-2177, CVE-2010-2178, CVE-2010-2180, CVE-2010-2182, CVE-2010-2184, CVE-2010-2187, and CVE-2010-2188.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 9fed1ac7d6ac263f8b42cb8e24927e67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
	<!-- dc5e2e29ebe98d9444b78ef5643bf4f1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102166" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2166</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2166" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2166" source="CVE"/>
	<description>
	Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-2160, CVE-2010-2165, CVE-2010-2171, CVE-2010-2175, CVE-2010-2176, CVE-2010-2177, CVE-2010-2178, CVE-2010-2180, CVE-2010-2182, CVE-2010-2184, CVE-2010-2187, and CVE-2010-2188.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 9fed1ac7d6ac263f8b42cb8e24927e67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
	<!-- dc5e2e29ebe98d9444b78ef5643bf4f1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102167" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2167</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2167" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2167" source="CVE"/>
	<description>
	Multiple heap-based buffer overflows in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers to execute arbitrary code via unspecified vectors related to malformed (1) GIF or (2) JPEG data.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 9fed1ac7d6ac263f8b42cb8e24927e67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
	<!-- dc5e2e29ebe98d9444b78ef5643bf4f1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102168" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2168</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2168" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2168" source="CVE"/>
	<description>
	Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code via a PDF file with crafted Flash content, involving the newfunction (0x44) operator and an "invalid pointer vulnerability" that triggers memory corruption, a different vulnerability than CVE-2010-1285 and CVE-2010-2201.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 33cfd1f00fc11a44db9cae1331100365 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061127" comment="acroread-cmaps less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061128" comment="acroread-fonts-ja less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061129" comment="acroread-fonts-ko less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061130" comment="acroread-fonts-zh_CN less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061131" comment="acroread-fonts-zh_TW less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061132" comment="acroread less than 9.3.3-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 738a9bfc615adca49b1c8c24702d69ab -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061133" comment="acroread_ja less than 9.3.3-0.1.1"/>
	</criteria>
	<!-- af3e139e036f69030f0263d2bf39de4b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061127" comment="acroread-cmaps less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061128" comment="acroread-fonts-ja less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061129" comment="acroread-fonts-ko less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061130" comment="acroread-fonts-zh_CN less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061131" comment="acroread-fonts-zh_TW less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061132" comment="acroread less than 9.3.3-0.1.1"/>
		</criteria>
	</criteria>
	<!-- faf9c7e8401c2a5fc98e2cd4840b594b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061133" comment="acroread_ja less than 9.3.3-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102169" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2169</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2169" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2169" source="CVE"/>
	<description>
	Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allow attackers to cause a denial of service (pointer memory corruption) or possibly execute arbitrary code via unspecified vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 9fed1ac7d6ac263f8b42cb8e24927e67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
	<!-- dc5e2e29ebe98d9444b78ef5643bf4f1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102170" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2170</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2170" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2170" source="CVE"/>
	<description>
	Integer overflow in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-2181 and CVE-2010-2183.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 9fed1ac7d6ac263f8b42cb8e24927e67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
	<!-- dc5e2e29ebe98d9444b78ef5643bf4f1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102171" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2171</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2171" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2171" source="CVE"/>
	<description>
	Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via vectors related to SWF files, decompression of embedded JPEG image data, and the DefineBits and other unspecified tags, a different vulnerability than CVE-2010-2160, CVE-2010-2165, CVE-2010-2166, CVE-2010-2175, CVE-2010-2176, CVE-2010-2177, CVE-2010-2178, CVE-2010-2180, CVE-2010-2182, CVE-2010-2184, CVE-2010-2187, and CVE-2010-2188.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 9fed1ac7d6ac263f8b42cb8e24927e67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
	<!-- dc5e2e29ebe98d9444b78ef5643bf4f1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102172" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2172</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2172" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2172" source="CVE"/>
	<description>
	Adobe Flash Player 9 before 9.0.277.0 on unspecified UNIX platforms allows attackers to cause a denial of service via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 9fed1ac7d6ac263f8b42cb8e24927e67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
	<!-- dc5e2e29ebe98d9444b78ef5643bf4f1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102173" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2173</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2173" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2173" source="CVE"/>
	<description>
	Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers to execute arbitrary code via unspecified vectors, related to an "invalid pointer vulnerability" and the newclass (0x58) operator, a different vulnerability than CVE-2010-2174.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 9fed1ac7d6ac263f8b42cb8e24927e67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
	<!-- dc5e2e29ebe98d9444b78ef5643bf4f1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102174" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2174</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2174" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2174" source="CVE"/>
	<description>
	Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers to execute arbitrary code via unspecified vectors, related to an "invalid pointer vulnerability" and the newfunction (0x44) operator, a different vulnerability than CVE-2010-2173.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 9fed1ac7d6ac263f8b42cb8e24927e67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
	<!-- dc5e2e29ebe98d9444b78ef5643bf4f1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102175" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2175</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2175" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2175" source="CVE"/>
	<description>
	Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-2160, CVE-2010-2165, CVE-2010-2166, CVE-2010-2171, CVE-2010-2176, CVE-2010-2177, CVE-2010-2178, CVE-2010-2180, CVE-2010-2182, CVE-2010-2184, CVE-2010-2187, and CVE-2010-2188.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 9fed1ac7d6ac263f8b42cb8e24927e67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
	<!-- dc5e2e29ebe98d9444b78ef5643bf4f1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102176" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2176</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2176" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2176" source="CVE"/>
	<description>
	Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-2160, CVE-2010-2165, CVE-2010-2166, CVE-2010-2171, CVE-2010-2175, CVE-2010-2177, CVE-2010-2178, CVE-2010-2180, CVE-2010-2182, CVE-2010-2184, CVE-2010-2187, and CVE-2010-2188.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 9fed1ac7d6ac263f8b42cb8e24927e67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
	<!-- dc5e2e29ebe98d9444b78ef5643bf4f1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102177" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2177</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2177" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2177" source="CVE"/>
	<description>
	Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-2160, CVE-2010-2165, CVE-2010-2166, CVE-2010-2171, CVE-2010-2175, CVE-2010-2176, CVE-2010-2178, CVE-2010-2180, CVE-2010-2182, CVE-2010-2184, CVE-2010-2187, and CVE-2010-2188.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 9fed1ac7d6ac263f8b42cb8e24927e67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
	<!-- dc5e2e29ebe98d9444b78ef5643bf4f1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102178" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2178</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2178" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2178" source="CVE"/>
	<description>
	Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-2160, CVE-2010-2165, CVE-2010-2166, CVE-2010-2171, CVE-2010-2175, CVE-2010-2176, CVE-2010-2177, CVE-2010-2180, CVE-2010-2182, CVE-2010-2184, CVE-2010-2187, and CVE-2010-2188.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 9fed1ac7d6ac263f8b42cb8e24927e67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
	<!-- dc5e2e29ebe98d9444b78ef5643bf4f1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102179" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2179</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2179" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2179" source="CVE"/>
	<description>
	Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, when Firefox or Chrome is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to URL parsing.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 9fed1ac7d6ac263f8b42cb8e24927e67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
	<!-- dc5e2e29ebe98d9444b78ef5643bf4f1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102180" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2180</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2180" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2180" source="CVE"/>
	<description>
	Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-2160, CVE-2010-2165, CVE-2010-2166, CVE-2010-2171, CVE-2010-2175, CVE-2010-2176, CVE-2010-2177, CVE-2010-2178, CVE-2010-2182, CVE-2010-2184, CVE-2010-2187, and CVE-2010-2188.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 9fed1ac7d6ac263f8b42cb8e24927e67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
	<!-- dc5e2e29ebe98d9444b78ef5643bf4f1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102181" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2181</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2181" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2181" source="CVE"/>
	<description>
	Integer overflow in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-2170 and CVE-2010-2183.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 9fed1ac7d6ac263f8b42cb8e24927e67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
	<!-- dc5e2e29ebe98d9444b78ef5643bf4f1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102182" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2182</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2182" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2182" source="CVE"/>
	<description>
	Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-2160, CVE-2010-2165, CVE-2010-2166, CVE-2010-2171, CVE-2010-2175, CVE-2010-2176, CVE-2010-2177, CVE-2010-2178, CVE-2010-2180, CVE-2010-2184, CVE-2010-2187, and CVE-2010-2188.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 9fed1ac7d6ac263f8b42cb8e24927e67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
	<!-- dc5e2e29ebe98d9444b78ef5643bf4f1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102183" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2183</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2183" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2183" source="CVE"/>
	<description>
	Integer overflow in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-2170 and CVE-2010-2181.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 9fed1ac7d6ac263f8b42cb8e24927e67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
	<!-- dc5e2e29ebe98d9444b78ef5643bf4f1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102184" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2184</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2184" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2184" source="CVE"/>
	<description>
	Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-2160, CVE-2010-2165, CVE-2010-2166, CVE-2010-2171, CVE-2010-2175, CVE-2010-2176, CVE-2010-2177, CVE-2010-2178, CVE-2010-2180, CVE-2010-2182, CVE-2010-2187, and CVE-2010-2188.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 9fed1ac7d6ac263f8b42cb8e24927e67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
	<!-- dc5e2e29ebe98d9444b78ef5643bf4f1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102185" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2185</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2185" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2185" source="CVE"/>
	<description>
	Buffer overflow in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers to execute arbitrary code via unspecified vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 9fed1ac7d6ac263f8b42cb8e24927e67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
	<!-- dc5e2e29ebe98d9444b78ef5643bf4f1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102186" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2186</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2186" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2186" source="CVE"/>
	<description>
	Unspecified vulnerability in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 9fed1ac7d6ac263f8b42cb8e24927e67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
	<!-- dc5e2e29ebe98d9444b78ef5643bf4f1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102187" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2187</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2187" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2187" source="CVE"/>
	<description>
	Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-2160, CVE-2010-2165, CVE-2010-2166, CVE-2010-2171, CVE-2010-2175, CVE-2010-2176, CVE-2010-2177, CVE-2010-2178, CVE-2010-2180, CVE-2010-2182, CVE-2010-2184, and CVE-2010-2188.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 9fed1ac7d6ac263f8b42cb8e24927e67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
	<!-- dc5e2e29ebe98d9444b78ef5643bf4f1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102188" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2188</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2188" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2188" source="CVE"/>
	<description>
	Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code by calling the ActionScript native object 2200 connect method multiple times with different arguments, a different vulnerability than CVE-2010-2160, CVE-2010-2165, CVE-2010-2166, CVE-2010-2171, CVE-2010-2175, CVE-2010-2176, CVE-2010-2177, CVE-2010-2178, CVE-2010-2180, CVE-2010-2182, CVE-2010-2184, and CVE-2010-2187.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 095cf91c7a73fc7f8adfcb7b68dd1ea9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062194" comment="acroread_ja less than 9.3.4-0.1.1"/>
	</criteria>
	<!-- 36a9cbb312d6ad766eed81d158f1dc01 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062194" comment="acroread_ja less than 9.3.4-0.1.1"/>
	</criteria>
	<!-- 85ef4e12e2a5ef29d8861660c8ba0fec -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061978" comment="flash-player less than 10.1.82.76-0.1.1"/>
	</criteria>
	<!-- 9fed1ac7d6ac263f8b42cb8e24927e67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
	<!-- acc35314c2f71240e3fdc5d3f7877332 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061978" comment="flash-player less than 10.1.82.76-0.1.1"/>
	</criteria>
	<!-- dc5e2e29ebe98d9444b78ef5643bf4f1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
	<!-- df4199604d1ebfce8b612958957eb533 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062202" comment="acroread-cmaps less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062203" comment="acroread-fonts-ja less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062204" comment="acroread-fonts-ko less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062205" comment="acroread-fonts-zh_CN less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062206" comment="acroread-fonts-zh_TW less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062207" comment="acroread less than 9.3.4-0.6.1"/>
		</criteria>
	</criteria>
	<!-- f1ea8f5a6e6b82355c9b5987cea86fa1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062202" comment="acroread-cmaps less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062203" comment="acroread-fonts-ja less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062204" comment="acroread-fonts-ko less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062205" comment="acroread-fonts-zh_CN less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062206" comment="acroread-fonts-zh_TW less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062207" comment="acroread less than 9.3.4-0.6.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102189" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2189</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2189" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2189" source="CVE"/>
	<description>
	Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, when used in conjunction with VMWare Tools on a VMWare platform, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 9fed1ac7d6ac263f8b42cb8e24927e67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
	<!-- dc5e2e29ebe98d9444b78ef5643bf4f1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060833" comment="flash-player less than 10.1.53.64-1.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102201" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2201</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2201" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2201" source="CVE"/>
	<description>
	Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code via a PDF file with crafted Flash content involving the (1) pushstring (0x2C) operator, (2) debugfile (0xF1) operator, and an "invalid pointer vulnerability" that triggers memory corruption, a different vulnerability than CVE-2010-1285 and CVE-2010-2168.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 33cfd1f00fc11a44db9cae1331100365 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061127" comment="acroread-cmaps less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061128" comment="acroread-fonts-ja less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061129" comment="acroread-fonts-ko less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061130" comment="acroread-fonts-zh_CN less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061131" comment="acroread-fonts-zh_TW less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061132" comment="acroread less than 9.3.3-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 738a9bfc615adca49b1c8c24702d69ab -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061133" comment="acroread_ja less than 9.3.3-0.1.1"/>
	</criteria>
	<!-- af3e139e036f69030f0263d2bf39de4b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061127" comment="acroread-cmaps less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061128" comment="acroread-fonts-ja less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061129" comment="acroread-fonts-ko less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061130" comment="acroread-fonts-zh_CN less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061131" comment="acroread-fonts-zh_TW less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061132" comment="acroread less than 9.3.3-0.1.1"/>
		</criteria>
	</criteria>
	<!-- faf9c7e8401c2a5fc98e2cd4840b594b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061133" comment="acroread_ja less than 9.3.3-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102202" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2202</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2202" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2202" source="CVE"/>
	<description>
	Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-1295, CVE-2010-2207, CVE-2010-2209, CVE-2010-2210, CVE-2010-2211, and CVE-2010-2212.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 33cfd1f00fc11a44db9cae1331100365 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061127" comment="acroread-cmaps less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061128" comment="acroread-fonts-ja less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061129" comment="acroread-fonts-ko less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061130" comment="acroread-fonts-zh_CN less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061131" comment="acroread-fonts-zh_TW less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061132" comment="acroread less than 9.3.3-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 738a9bfc615adca49b1c8c24702d69ab -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061133" comment="acroread_ja less than 9.3.3-0.1.1"/>
	</criteria>
	<!-- af3e139e036f69030f0263d2bf39de4b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061127" comment="acroread-cmaps less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061128" comment="acroread-fonts-ja less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061129" comment="acroread-fonts-ko less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061130" comment="acroread-fonts-zh_CN less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061131" comment="acroread-fonts-zh_TW less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061132" comment="acroread less than 9.3.3-0.1.1"/>
		</criteria>
	</criteria>
	<!-- faf9c7e8401c2a5fc98e2cd4840b594b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061133" comment="acroread_ja less than 9.3.3-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102203" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2203</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2203" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2203" source="CVE"/>
	<description>
	Adobe Reader and Acrobat 9.x before 9.3.3 on UNIX allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 33cfd1f00fc11a44db9cae1331100365 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061127" comment="acroread-cmaps less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061128" comment="acroread-fonts-ja less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061129" comment="acroread-fonts-ko less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061130" comment="acroread-fonts-zh_CN less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061131" comment="acroread-fonts-zh_TW less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061132" comment="acroread less than 9.3.3-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 738a9bfc615adca49b1c8c24702d69ab -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061133" comment="acroread_ja less than 9.3.3-0.1.1"/>
	</criteria>
	<!-- af3e139e036f69030f0263d2bf39de4b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061127" comment="acroread-cmaps less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061128" comment="acroread-fonts-ja less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061129" comment="acroread-fonts-ko less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061130" comment="acroread-fonts-zh_CN less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061131" comment="acroread-fonts-zh_TW less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061132" comment="acroread less than 9.3.3-0.1.1"/>
		</criteria>
	</criteria>
	<!-- faf9c7e8401c2a5fc98e2cd4840b594b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061133" comment="acroread_ja less than 9.3.3-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102204" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2204</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2204" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2204" source="CVE"/>
	<description>
	Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 33cfd1f00fc11a44db9cae1331100365 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061127" comment="acroread-cmaps less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061128" comment="acroread-fonts-ja less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061129" comment="acroread-fonts-ko less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061130" comment="acroread-fonts-zh_CN less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061131" comment="acroread-fonts-zh_TW less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061132" comment="acroread less than 9.3.3-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 738a9bfc615adca49b1c8c24702d69ab -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061133" comment="acroread_ja less than 9.3.3-0.1.1"/>
	</criteria>
	<!-- af3e139e036f69030f0263d2bf39de4b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061127" comment="acroread-cmaps less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061128" comment="acroread-fonts-ja less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061129" comment="acroread-fonts-ko less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061130" comment="acroread-fonts-zh_CN less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061131" comment="acroread-fonts-zh_TW less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061132" comment="acroread less than 9.3.3-0.1.1"/>
		</criteria>
	</criteria>
	<!-- faf9c7e8401c2a5fc98e2cd4840b594b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061133" comment="acroread_ja less than 9.3.3-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102205" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2205</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2205" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2205" source="CVE"/>
	<description>
	Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, access uninitialized memory, which allows attackers to execute arbitrary code via unspecified vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 33cfd1f00fc11a44db9cae1331100365 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061127" comment="acroread-cmaps less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061128" comment="acroread-fonts-ja less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061129" comment="acroread-fonts-ko less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061130" comment="acroread-fonts-zh_CN less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061131" comment="acroread-fonts-zh_TW less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061132" comment="acroread less than 9.3.3-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 738a9bfc615adca49b1c8c24702d69ab -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061133" comment="acroread_ja less than 9.3.3-0.1.1"/>
	</criteria>
	<!-- af3e139e036f69030f0263d2bf39de4b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061127" comment="acroread-cmaps less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061128" comment="acroread-fonts-ja less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061129" comment="acroread-fonts-ko less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061130" comment="acroread-fonts-zh_CN less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061131" comment="acroread-fonts-zh_TW less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061132" comment="acroread less than 9.3.3-0.1.1"/>
		</criteria>
	</criteria>
	<!-- faf9c7e8401c2a5fc98e2cd4840b594b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061133" comment="acroread_ja less than 9.3.3-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102206" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2206</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2206" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2206" source="CVE"/>
	<description>
	Array index error in AcroForm.api in Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted GIF image in a PDF file, which bypasses a size check and triggers a heap-based buffer overflow.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 33cfd1f00fc11a44db9cae1331100365 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061127" comment="acroread-cmaps less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061128" comment="acroread-fonts-ja less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061129" comment="acroread-fonts-ko less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061130" comment="acroread-fonts-zh_CN less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061131" comment="acroread-fonts-zh_TW less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061132" comment="acroread less than 9.3.3-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 738a9bfc615adca49b1c8c24702d69ab -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061133" comment="acroread_ja less than 9.3.3-0.1.1"/>
	</criteria>
	<!-- af3e139e036f69030f0263d2bf39de4b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061127" comment="acroread-cmaps less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061128" comment="acroread-fonts-ja less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061129" comment="acroread-fonts-ko less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061130" comment="acroread-fonts-zh_CN less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061131" comment="acroread-fonts-zh_TW less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061132" comment="acroread less than 9.3.3-0.1.1"/>
		</criteria>
	</criteria>
	<!-- faf9c7e8401c2a5fc98e2cd4840b594b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061133" comment="acroread_ja less than 9.3.3-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102207" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2207</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2207" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2207" source="CVE"/>
	<description>
	Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-1295, CVE-2010-2202, CVE-2010-2209, CVE-2010-2210, CVE-2010-2211, and CVE-2010-2212.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 33cfd1f00fc11a44db9cae1331100365 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061127" comment="acroread-cmaps less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061128" comment="acroread-fonts-ja less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061129" comment="acroread-fonts-ko less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061130" comment="acroread-fonts-zh_CN less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061131" comment="acroread-fonts-zh_TW less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061132" comment="acroread less than 9.3.3-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 738a9bfc615adca49b1c8c24702d69ab -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061133" comment="acroread_ja less than 9.3.3-0.1.1"/>
	</criteria>
	<!-- af3e139e036f69030f0263d2bf39de4b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061127" comment="acroread-cmaps less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061128" comment="acroread-fonts-ja less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061129" comment="acroread-fonts-ko less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061130" comment="acroread-fonts-zh_CN less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061131" comment="acroread-fonts-zh_TW less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061132" comment="acroread less than 9.3.3-0.1.1"/>
		</criteria>
	</criteria>
	<!-- faf9c7e8401c2a5fc98e2cd4840b594b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061133" comment="acroread_ja less than 9.3.3-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102208" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2208</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2208" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2208" source="CVE"/>
	<description>
	Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, dereference a heap object after this object's deletion, which allows attackers to execute arbitrary code via unspecified vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 33cfd1f00fc11a44db9cae1331100365 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061127" comment="acroread-cmaps less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061128" comment="acroread-fonts-ja less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061129" comment="acroread-fonts-ko less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061130" comment="acroread-fonts-zh_CN less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061131" comment="acroread-fonts-zh_TW less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061132" comment="acroread less than 9.3.3-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 738a9bfc615adca49b1c8c24702d69ab -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061133" comment="acroread_ja less than 9.3.3-0.1.1"/>
	</criteria>
	<!-- af3e139e036f69030f0263d2bf39de4b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061127" comment="acroread-cmaps less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061128" comment="acroread-fonts-ja less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061129" comment="acroread-fonts-ko less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061130" comment="acroread-fonts-zh_CN less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061131" comment="acroread-fonts-zh_TW less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061132" comment="acroread less than 9.3.3-0.1.1"/>
		</criteria>
	</criteria>
	<!-- faf9c7e8401c2a5fc98e2cd4840b594b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061133" comment="acroread_ja less than 9.3.3-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102209" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2209</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2209" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2209" source="CVE"/>
	<description>
	Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-1295, CVE-2010-2202, CVE-2010-2207, CVE-2010-2210, CVE-2010-2211, and CVE-2010-2212.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 33cfd1f00fc11a44db9cae1331100365 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061127" comment="acroread-cmaps less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061128" comment="acroread-fonts-ja less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061129" comment="acroread-fonts-ko less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061130" comment="acroread-fonts-zh_CN less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061131" comment="acroread-fonts-zh_TW less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061132" comment="acroread less than 9.3.3-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 738a9bfc615adca49b1c8c24702d69ab -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061133" comment="acroread_ja less than 9.3.3-0.1.1"/>
	</criteria>
	<!-- af3e139e036f69030f0263d2bf39de4b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061127" comment="acroread-cmaps less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061128" comment="acroread-fonts-ja less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061129" comment="acroread-fonts-ko less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061130" comment="acroread-fonts-zh_CN less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061131" comment="acroread-fonts-zh_TW less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061132" comment="acroread less than 9.3.3-0.1.1"/>
		</criteria>
	</criteria>
	<!-- faf9c7e8401c2a5fc98e2cd4840b594b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061133" comment="acroread_ja less than 9.3.3-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102210" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2210</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2210" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2210" source="CVE"/>
	<description>
	Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-1295, CVE-2010-2202, CVE-2010-2207, CVE-2010-2209, CVE-2010-2211, and CVE-2010-2212.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 33cfd1f00fc11a44db9cae1331100365 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061127" comment="acroread-cmaps less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061128" comment="acroread-fonts-ja less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061129" comment="acroread-fonts-ko less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061130" comment="acroread-fonts-zh_CN less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061131" comment="acroread-fonts-zh_TW less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061132" comment="acroread less than 9.3.3-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 738a9bfc615adca49b1c8c24702d69ab -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061133" comment="acroread_ja less than 9.3.3-0.1.1"/>
	</criteria>
	<!-- af3e139e036f69030f0263d2bf39de4b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061127" comment="acroread-cmaps less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061128" comment="acroread-fonts-ja less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061129" comment="acroread-fonts-ko less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061130" comment="acroread-fonts-zh_CN less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061131" comment="acroread-fonts-zh_TW less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061132" comment="acroread less than 9.3.3-0.1.1"/>
		</criteria>
	</criteria>
	<!-- faf9c7e8401c2a5fc98e2cd4840b594b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061133" comment="acroread_ja less than 9.3.3-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102211" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2211</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2211" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2211" source="CVE"/>
	<description>
	Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-1295, CVE-2010-2202, CVE-2010-2207, CVE-2010-2209, CVE-2010-2210, and CVE-2010-2212.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 33cfd1f00fc11a44db9cae1331100365 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061127" comment="acroread-cmaps less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061128" comment="acroread-fonts-ja less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061129" comment="acroread-fonts-ko less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061130" comment="acroread-fonts-zh_CN less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061131" comment="acroread-fonts-zh_TW less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061132" comment="acroread less than 9.3.3-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 738a9bfc615adca49b1c8c24702d69ab -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061133" comment="acroread_ja less than 9.3.3-0.1.1"/>
	</criteria>
	<!-- af3e139e036f69030f0263d2bf39de4b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061127" comment="acroread-cmaps less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061128" comment="acroread-fonts-ja less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061129" comment="acroread-fonts-ko less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061130" comment="acroread-fonts-zh_CN less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061131" comment="acroread-fonts-zh_TW less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061132" comment="acroread less than 9.3.3-0.1.1"/>
		</criteria>
	</criteria>
	<!-- faf9c7e8401c2a5fc98e2cd4840b594b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061133" comment="acroread_ja less than 9.3.3-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102212" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2212</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2212" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2212" source="CVE"/>
	<description>
	Buffer overflow in Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a PDF file containing Flash content with a crafted #1023 (3FFh) tag, a different vulnerability than CVE-2010-1295, CVE-2010-2202, CVE-2010-2207, CVE-2010-2209, CVE-2010-2210, and CVE-2010-2211.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 33cfd1f00fc11a44db9cae1331100365 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061127" comment="acroread-cmaps less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061128" comment="acroread-fonts-ja less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061129" comment="acroread-fonts-ko less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061130" comment="acroread-fonts-zh_CN less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061131" comment="acroread-fonts-zh_TW less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061132" comment="acroread less than 9.3.3-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 738a9bfc615adca49b1c8c24702d69ab -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061133" comment="acroread_ja less than 9.3.3-0.1.1"/>
	</criteria>
	<!-- af3e139e036f69030f0263d2bf39de4b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061127" comment="acroread-cmaps less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061128" comment="acroread-fonts-ja less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061129" comment="acroread-fonts-ko less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061130" comment="acroread-fonts-zh_CN less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061131" comment="acroread-fonts-zh_TW less than 9.3.3-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061132" comment="acroread less than 9.3.3-0.1.1"/>
		</criteria>
	</criteria>
	<!-- faf9c7e8401c2a5fc98e2cd4840b594b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061133" comment="acroread_ja less than 9.3.3-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102213" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2213</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2213" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2213" source="CVE"/>
	<description>
	Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-0209, CVE-2010-2214, and CVE-2010-2216.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 095cf91c7a73fc7f8adfcb7b68dd1ea9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062194" comment="acroread_ja less than 9.3.4-0.1.1"/>
	</criteria>
	<!-- 36a9cbb312d6ad766eed81d158f1dc01 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062194" comment="acroread_ja less than 9.3.4-0.1.1"/>
	</criteria>
	<!-- 85ef4e12e2a5ef29d8861660c8ba0fec -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061978" comment="flash-player less than 10.1.82.76-0.1.1"/>
	</criteria>
	<!-- acc35314c2f71240e3fdc5d3f7877332 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061978" comment="flash-player less than 10.1.82.76-0.1.1"/>
	</criteria>
	<!-- df4199604d1ebfce8b612958957eb533 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062202" comment="acroread-cmaps less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062203" comment="acroread-fonts-ja less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062204" comment="acroread-fonts-ko less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062205" comment="acroread-fonts-zh_CN less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062206" comment="acroread-fonts-zh_TW less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062207" comment="acroread less than 9.3.4-0.6.1"/>
		</criteria>
	</criteria>
	<!-- f1ea8f5a6e6b82355c9b5987cea86fa1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062202" comment="acroread-cmaps less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062203" comment="acroread-fonts-ja less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062204" comment="acroread-fonts-ko less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062205" comment="acroread-fonts-zh_CN less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062206" comment="acroread-fonts-zh_TW less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062207" comment="acroread less than 9.3.4-0.6.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102214" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2214</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2214" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2214" source="CVE"/>
	<description>
	Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-0209, CVE-2010-2213, and CVE-2010-2216.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 095cf91c7a73fc7f8adfcb7b68dd1ea9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062194" comment="acroread_ja less than 9.3.4-0.1.1"/>
	</criteria>
	<!-- 36a9cbb312d6ad766eed81d158f1dc01 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062194" comment="acroread_ja less than 9.3.4-0.1.1"/>
	</criteria>
	<!-- 85ef4e12e2a5ef29d8861660c8ba0fec -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061978" comment="flash-player less than 10.1.82.76-0.1.1"/>
	</criteria>
	<!-- acc35314c2f71240e3fdc5d3f7877332 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061978" comment="flash-player less than 10.1.82.76-0.1.1"/>
	</criteria>
	<!-- df4199604d1ebfce8b612958957eb533 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062202" comment="acroread-cmaps less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062203" comment="acroread-fonts-ja less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062204" comment="acroread-fonts-ko less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062205" comment="acroread-fonts-zh_CN less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062206" comment="acroread-fonts-zh_TW less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062207" comment="acroread less than 9.3.4-0.6.1"/>
		</criteria>
	</criteria>
	<!-- f1ea8f5a6e6b82355c9b5987cea86fa1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062202" comment="acroread-cmaps less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062203" comment="acroread-fonts-ja less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062204" comment="acroread-fonts-ko less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062205" comment="acroread-fonts-zh_CN less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062206" comment="acroread-fonts-zh_TW less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062207" comment="acroread less than 9.3.4-0.6.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102215" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2215</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2215" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2215" source="CVE"/>
	<description>
	Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to trick a user into (1) selecting a link or (2) completing a dialog, related to a "click-jacking" issue.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 095cf91c7a73fc7f8adfcb7b68dd1ea9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062194" comment="acroread_ja less than 9.3.4-0.1.1"/>
	</criteria>
	<!-- 36a9cbb312d6ad766eed81d158f1dc01 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062194" comment="acroread_ja less than 9.3.4-0.1.1"/>
	</criteria>
	<!-- 85ef4e12e2a5ef29d8861660c8ba0fec -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061978" comment="flash-player less than 10.1.82.76-0.1.1"/>
	</criteria>
	<!-- acc35314c2f71240e3fdc5d3f7877332 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061978" comment="flash-player less than 10.1.82.76-0.1.1"/>
	</criteria>
	<!-- df4199604d1ebfce8b612958957eb533 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062202" comment="acroread-cmaps less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062203" comment="acroread-fonts-ja less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062204" comment="acroread-fonts-ko less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062205" comment="acroread-fonts-zh_CN less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062206" comment="acroread-fonts-zh_TW less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062207" comment="acroread less than 9.3.4-0.6.1"/>
		</criteria>
	</criteria>
	<!-- f1ea8f5a6e6b82355c9b5987cea86fa1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062202" comment="acroread-cmaps less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062203" comment="acroread-fonts-ja less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062204" comment="acroread-fonts-ko less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062205" comment="acroread-fonts-zh_CN less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062206" comment="acroread-fonts-zh_TW less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062207" comment="acroread less than 9.3.4-0.6.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102216" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2216</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2216" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2216" source="CVE"/>
	<description>
	Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-0209, CVE-2010-2213, and CVE-2010-2214.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 095cf91c7a73fc7f8adfcb7b68dd1ea9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062194" comment="acroread_ja less than 9.3.4-0.1.1"/>
	</criteria>
	<!-- 36a9cbb312d6ad766eed81d158f1dc01 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062194" comment="acroread_ja less than 9.3.4-0.1.1"/>
	</criteria>
	<!-- 85ef4e12e2a5ef29d8861660c8ba0fec -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061978" comment="flash-player less than 10.1.82.76-0.1.1"/>
	</criteria>
	<!-- acc35314c2f71240e3fdc5d3f7877332 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061978" comment="flash-player less than 10.1.82.76-0.1.1"/>
	</criteria>
	<!-- df4199604d1ebfce8b612958957eb533 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062202" comment="acroread-cmaps less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062203" comment="acroread-fonts-ja less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062204" comment="acroread-fonts-ko less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062205" comment="acroread-fonts-zh_CN less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062206" comment="acroread-fonts-zh_TW less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062207" comment="acroread less than 9.3.4-0.6.1"/>
		</criteria>
	</criteria>
	<!-- f1ea8f5a6e6b82355c9b5987cea86fa1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062202" comment="acroread-cmaps less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062203" comment="acroread-fonts-ja less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062204" comment="acroread-fonts-ko less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062205" comment="acroread-fonts-zh_CN less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062206" comment="acroread-fonts-zh_TW less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062207" comment="acroread less than 9.3.4-0.6.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102221" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2221</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2221" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2221" source="CVE"/>
	<description>
	Multiple buffer overflows in the iSNS implementation in isns.c in (1) Linux SCSI target framework (aka tgt or scsi-target-utils) before 1.0.6, (2) iSCSI Enterprise Target (aka iscsitarget or IET) 1.4.20.1 and earlier, and (3) Generic SCSI Target Subsystem for Linux (aka SCST or iscsi-scst) 1.0.1.1 and earlier allow remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via (a) a long iSCSI Name string in an SCN message or (b) an invalid PDU.
	</description>
 </metadata>
<!-- b2720d1cb13b664616006efc437aaeb0 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009062383" comment="iscsitarget-kmp-default less than 1.4.19_2.6.32.13_0.5-0.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062386" comment="iscsitarget-kmp-xen less than 1.4.19_2.6.32.13_0.5-0.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062387" comment="iscsitarget less than 1.4.19-0.7.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102237" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2237</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2237" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2237" source="CVE"/>
	<description>
	Red Hat libvirt, possibly 0.6.1 through 0.8.2, looks up disk backing stores without referring to the user-defined main disk format, which might allow guest OS users to read arbitrary files on the host OS, and possibly have unspecified other impact, via unknown vectors.
	</description>
 </metadata>
<!-- a8fd679955cb064e6e90b799c4557591 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009062636" comment="libvirt-doc less than 0.7.6-1.12.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062637" comment="libvirt-python less than 0.7.6-1.12.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062638" comment="libvirt less than 0.7.6-1.12.2"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102238" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2238</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2238" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2238" source="CVE"/>
	<description>
	Red Hat libvirt, possibly 0.7.2 through 0.8.2, recurses into disk-image backing stores without extracting the defined disk backing-store format, which might allow guest OS users to read arbitrary files on the host OS, and possibly have unspecified other impact, via unknown vectors.
	</description>
 </metadata>
<!-- a8fd679955cb064e6e90b799c4557591 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009062636" comment="libvirt-doc less than 0.7.6-1.12.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062637" comment="libvirt-python less than 0.7.6-1.12.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062638" comment="libvirt less than 0.7.6-1.12.2"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102239" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2239</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2239" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2239" source="CVE"/>
	<description>
	Red Hat libvirt, possibly 0.6.0 through 0.8.2, creates new images without setting the user-defined backing-store format, which allows guest OS users to read arbitrary files on the host OS via unspecified vectors.
	</description>
 </metadata>
<!-- a8fd679955cb064e6e90b799c4557591 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009062636" comment="libvirt-doc less than 0.7.6-1.12.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062637" comment="libvirt-python less than 0.7.6-1.12.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062638" comment="libvirt less than 0.7.6-1.12.2"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102240" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2240</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2240" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2240" source="CVE"/>
	<description>
	The do_anonymous_page function in mm/memory.c in the Linux kernel before 2.6.27.52, 2.6.32.x before 2.6.32.19, 2.6.34.x before 2.6.34.4, and 2.6.35.x before 2.6.35.2 does not properly separate the stack and the heap, which allows context-dependent attackers to execute arbitrary code by writing to the bottom page of a shared memory segment, as demonstrated by a memory-exhaustion attack against the X.Org X server.
	</description>
 </metadata>
<!-- 0174468eca4a0d10570a92e001f081dd -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009063235" comment="xorg-x11-Xvnc less than 7.4-27.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009063236" comment="xorg-x11-server-extra less than 7.4-27.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009063237" comment="xorg-x11-server less than 7.4-27.24.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102242" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2242</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2242" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2242" source="CVE"/>
	<description>
	Red Hat libvirt 0.2.0 through 0.8.2 creates iptables rules with improper mappings of privileged source ports, which allows guest OS users to bypass intended access restrictions by leveraging IP address and source-port values, as demonstrated by copying and deleting an NFS directory tree.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 4e3e6cd81221a6afd2bfbca8567ebb2c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062640" comment="libvirt-python less than 0.4.6-14.63.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062641" comment="libvirt less than 0.4.6-14.63.1"/>
		</criteria>
	</criteria>
	<!-- a8fd679955cb064e6e90b799c4557591 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062636" comment="libvirt-doc less than 0.7.6-1.12.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062637" comment="libvirt-python less than 0.7.6-1.12.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062638" comment="libvirt less than 0.7.6-1.12.2"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102249" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2249</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2249" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2249" source="CVE"/>
	<description>
	Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunks.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 05599e35a510ca089ac92c0708d24d96 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062299" comment="libpng-devel less than 1.2.31-5.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062258" comment="libpng12-0-32bit less than 1.2.31-5.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062260" comment="libpng12-0 less than 1.2.31-5.18.1"/>
		</criteria>
	</criteria>
	<!-- 1827d5255702922bfdc18e59d59e6a20 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062299" comment="libpng-devel less than 1.2.31-5.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062258" comment="libpng12-0-32bit less than 1.2.31-5.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062260" comment="libpng12-0 less than 1.2.31-5.18.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102283" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2283</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2283" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2283" source="CVE"/>
	<description>
	The SMB dissector in Wireshark 0.99.6 through 1.0.13, and 1.2.0 through 1.2.8 allows remote attackers to cause a denial of service (NULL pointer dereference) via unknown vectors.
	</description>
 </metadata>
<!-- 6e5fc6e202651e8b93c830786b3ea82f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066948" comment="wireshark less than 1.4.4-0.2.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102284" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2284</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2284" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2284" source="CVE"/>
	<description>
	Buffer overflow in the ASN.1 BER dissector in Wireshark 0.10.13 through 1.0.13 and 1.2.0 through 1.2.8 has unknown impact and remote attack vectors.
	</description>
 </metadata>
<!-- 6e5fc6e202651e8b93c830786b3ea82f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066948" comment="wireshark less than 1.4.4-0.2.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102285" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2285</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2285" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2285" source="CVE"/>
	<description>
	The SMB PIPE dissector in Wireshark 0.8.20 through 1.0.13 and 1.2.0 through 1.2.8 allows remote attackers to cause a denial of service (NULL pointer dereference) via unknown vectors.
	</description>
 </metadata>
<!-- 6e5fc6e202651e8b93c830786b3ea82f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066948" comment="wireshark less than 1.4.4-0.2.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102286" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2286</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2286" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2286" source="CVE"/>
	<description>
	The SigComp Universal Decompressor Virtual Machine dissector in Wireshark 0.10.7 through 1.0.13 and 1.2.0 through 1.2.8 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.
	</description>
 </metadata>
<!-- 6e5fc6e202651e8b93c830786b3ea82f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066948" comment="wireshark less than 1.4.4-0.2.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102287" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2287</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2287" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2287" source="CVE"/>
	<description>
	Buffer overflow in the SigComp Universal Decompressor Virtual Machine dissector in Wireshark 0.10.8 through 1.0.13 and 1.2.0 through 1.2.8 has unknown impact and remote attack vectors.
	</description>
 </metadata>
<!-- 6e5fc6e202651e8b93c830786b3ea82f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066948" comment="wireshark less than 1.4.4-0.2.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102431" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2431</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2431" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2431" source="CVE"/>
	<description>
	The cupsFileOpen function in CUPS before 1.4.4 allows local users, with lp group membership, to overwrite arbitrary files via a symlink attack on the (1) /var/cache/cups/remote.cache or (2) /var/cache/cups/job.cache file.
	</description>
 </metadata>
<!-- e50c58ccd03dea996e547017df4bffff -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009070956" comment="cups-client less than 1.3.9-8.44.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070957" comment="cups-libs-32bit less than 1.3.9-8.44.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070959" comment="cups-libs less than 1.3.9-8.44.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070960" comment="cups less than 1.3.9-8.44.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102432" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2432</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2432" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2432" source="CVE"/>
	<description>
	The cupsDoAuthentication function in auth.c in the client in CUPS before 1.4.4, when HAVE_GSSAPI is omitted, does not properly handle a demand for authorization, which allows remote CUPS servers to cause a denial of service (infinite loop) via HTTP_UNAUTHORIZED responses.
	</description>
 </metadata>
<!-- e50c58ccd03dea996e547017df4bffff -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009070956" comment="cups-client less than 1.3.9-8.44.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070957" comment="cups-libs-32bit less than 1.3.9-8.44.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070959" comment="cups-libs less than 1.3.9-8.44.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070960" comment="cups less than 1.3.9-8.44.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102441" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2441</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2441" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2441" source="CVE"/>
	<description>
	WebKit does not properly restrict focus changes, which allows remote attackers to read keystrokes via "cross-domain IFRAME gadgets," a different vulnerability than CVE-2010-1126, CVE-2010-1422, and CVE-2010-2295.
	</description>
 </metadata>
<!-- f57e4769dd3aca778aead0ead7cd3c6f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009069232" comment="libwebkit-1_0-2 less than 1.2.7-0.11.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009069234" comment="libwebkit-lang less than 1.2.7-0.11.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009069235" comment="webkit-sharp less than 0.2-2.45.3"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102478" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2478</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2478" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2478" source="CVE"/>
	<description>
	Integer overflow in the ethtool_get_rxnfc function in net/core/ethtool.c in the Linux kernel before 2.6.33.7 on 32-bit platforms allows local users to cause a denial of service or possibly have unspecified other impact via an ETHTOOL_GRXCLSRLALL ethtool command with a large info.rule_cnt value that triggers a buffer overflow, a different vulnerability than CVE-2010-3084.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 70608756570f270952a30400f0f97a67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062623" comment="kernel-default-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062624" comment="kernel-desktop-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062625" comment="kernel-xen-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
	<!-- e2f6c6cc02f7dc05554cab87c9f88650 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062408" comment="btrfs-kmp-pae less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062410" comment="hyper-v-kmp-pae less than 0_2.6.32.19_0.2-0.7.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062623" comment="kernel-default-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062624" comment="kernel-desktop-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062411" comment="kernel-pae-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062412" comment="kernel-pae-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062626" comment="kernel-pae-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062413" comment="kernel-pae less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062625" comment="kernel-xen-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102494" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2494</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2494" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2494" source="CVE"/>
	<description>
	Multiple buffer underflows in the base64 decoder in base64.c in (1) bogofilter and (2) bogolexer in bogofilter before 1.2.2 allow remote attackers to cause a denial of service (heap memory corruption and application crash) via an e-mail message with invalid base64 data that begins with an = (equals) character.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 02a74cb2567850bb3f8403f523fb4ebb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061806" comment="bogofilter less than 1.1.1-174.20.1"/>
	</criteria>
	<!-- d0601e3b0d5cd04371c57e504a1da276 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061806" comment="bogofilter less than 1.1.1-174.20.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102495" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2495</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2495" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2495" source="CVE"/>
	<description>
	The pppol2tp_xmit function in drivers/net/pppol2tp.c in the L2TP implementation in the Linux kernel before 2.6.34 does not properly validate certain values associated with an interface, which allows attackers to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via vectors related to a routing change.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 01f44594f9d8615a4c725ad4472abb2b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061868" comment="btrfs-kmp-default less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061869" comment="btrfs-kmp-xen less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061872" comment="hyper-v-kmp-default less than 0_2.6.32.13_0.5-0.7.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061873" comment="kernel-default-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061874" comment="kernel-default-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061945" comment="kernel-default-extra less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061875" comment="kernel-default less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061946" comment="kernel-desktop-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061876" comment="kernel-source less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061877" comment="kernel-syms less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061881" comment="kernel-xen-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061882" comment="kernel-xen-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061947" comment="kernel-xen-extra less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061883" comment="kernel-xen less than 2.6.32.13-0.5.1"/>
		</criteria>
	</criteria>
	<!-- caf966715fc66f993dd8892aa75742ad -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061868" comment="btrfs-kmp-default less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061889" comment="btrfs-kmp-pae less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061869" comment="btrfs-kmp-xen less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061872" comment="hyper-v-kmp-default less than 0_2.6.32.13_0.5-0.7.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061891" comment="hyper-v-kmp-pae less than 0_2.6.32.13_0.5-0.7.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061873" comment="kernel-default-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061874" comment="kernel-default-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061945" comment="kernel-default-extra less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061875" comment="kernel-default less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061946" comment="kernel-desktop-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061892" comment="kernel-pae-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061893" comment="kernel-pae-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061948" comment="kernel-pae-extra less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061894" comment="kernel-pae less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061876" comment="kernel-source less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061877" comment="kernel-syms less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061881" comment="kernel-xen-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061882" comment="kernel-xen-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061947" comment="kernel-xen-extra less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061883" comment="kernel-xen less than 2.6.32.13-0.5.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102497" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2497</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2497" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2497" source="CVE"/>
	<description>
	Integer underflow in glyph handling in FreeType before 2.4.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 7bcc9a1fade88c7620df728424de42c5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062111" comment="freetype2-devel less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
	<!-- f28613bd3eb0b0f8e83bbf97c432760b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062111" comment="freetype2-devel less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102498" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2498</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2498" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2498" source="CVE"/>
	<description>
	The psh_glyph_find_strong_points function in pshinter/pshalgo.c in FreeType before 2.4.0 does not properly implement hinting masks, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a crafted font file that triggers an invalid free operation.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 7bcc9a1fade88c7620df728424de42c5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062111" comment="freetype2-devel less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
	<!-- f28613bd3eb0b0f8e83bbf97c432760b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062111" comment="freetype2-devel less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102499" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2499</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2499" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2499" source="CVE"/>
	<description>
	Buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted LaserWriter PS font file with an embedded PFB fragment.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 7bcc9a1fade88c7620df728424de42c5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062111" comment="freetype2-devel less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
	<!-- f28613bd3eb0b0f8e83bbf97c432760b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062111" comment="freetype2-devel less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102500" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2500</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2500" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2500" source="CVE"/>
	<description>
	Integer overflow in the gray_render_span function in smooth/ftgrays.c in FreeType before 2.4.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 7bcc9a1fade88c7620df728424de42c5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062111" comment="freetype2-devel less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
	<!-- f28613bd3eb0b0f8e83bbf97c432760b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062111" comment="freetype2-devel less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102519" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2519</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2519" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2519" source="CVE"/>
	<description>
	Heap-based buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted length value in a POST fragment header in a font file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 7bcc9a1fade88c7620df728424de42c5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062111" comment="freetype2-devel less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
	<!-- f28613bd3eb0b0f8e83bbf97c432760b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062111" comment="freetype2-devel less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102520" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2520</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2520" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2520" source="CVE"/>
	<description>
	Heap-based buffer overflow in the Ins_IUP function in truetype/ttinterp.c in FreeType before 2.4.0, when TrueType bytecode support is enabled, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 7bcc9a1fade88c7620df728424de42c5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062111" comment="freetype2-devel less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
	<!-- f28613bd3eb0b0f8e83bbf97c432760b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062111" comment="freetype2-devel less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102521" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2521</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2521" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2521" source="CVE"/>
	<description>
	Multiple buffer overflows in fs/nfsd/nfs4xdr.c in the XDR implementation in the NFS server in the Linux kernel before 2.6.34-rc6 allow remote attackers to cause a denial of service (panic) or possibly execute arbitrary code via a crafted NFSv4 compound WRITE request, related to the read_buf and nfsd4_decode_compound functions.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 66504af0afe753b5175112b44bc8827d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061675" comment="kernel-default-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061679" comment="kernel-pae-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061680" comment="kernel-pae-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061681" comment="kernel-pae less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061693" comment="kernel-xen-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 70608756570f270952a30400f0f97a67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062623" comment="kernel-default-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062624" comment="kernel-desktop-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062625" comment="kernel-xen-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
	<!-- c8a29eec659b0b2b3e85c610b67beacd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061675" comment="kernel-default-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061693" comment="kernel-xen-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e2f6c6cc02f7dc05554cab87c9f88650 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062408" comment="btrfs-kmp-pae less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062410" comment="hyper-v-kmp-pae less than 0_2.6.32.19_0.2-0.7.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062623" comment="kernel-default-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062624" comment="kernel-desktop-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062411" comment="kernel-pae-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062412" comment="kernel-pae-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062626" comment="kernel-pae-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062413" comment="kernel-pae less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062625" comment="kernel-xen-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102522" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2522</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2522" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2522" source="CVE"/>
	<description>
	The mipv6 daemon in UMIP 0.4 does not verify that netlink messages originated in the kernel, which allows local users to spoof netlink socket communication via a crafted unicast message.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 448eb6fbdb13a064282bf6f2a91d1a9f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063774" comment="mipv6d less than 2.0.2-2.15.1"/>
	</criteria>
	<!-- d682c26a46cd978068d8c8bc5311a1cd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063774" comment="mipv6d less than 2.0.2-2.15.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102523" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2523</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2523" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2523" source="CVE"/>
	<description>
	Multiple buffer overflows in ha.c in the mipv6 daemon in UMIP 0.4 allow remote attackers to have an unspecified impact via a crafted (1) ND_OPT_PREFIX_INFORMATION or (2) ND_OPT_HOME_AGENT_INFO packet.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 448eb6fbdb13a064282bf6f2a91d1a9f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063774" comment="mipv6d less than 2.0.2-2.15.1"/>
	</criteria>
	<!-- d682c26a46cd978068d8c8bc5311a1cd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063774" comment="mipv6d less than 2.0.2-2.15.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102524" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2524</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2524" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2524" source="CVE"/>
	<description>
	The DNS resolution functionality in the CIFS implementation in the Linux kernel before 2.6.35, when CONFIG_CIFS_DFS_UPCALL is enabled, relies on a user's keyring for the dns_resolver upcall in the cifs.upcall userspace helper, which allows local users to spoof the results of DNS queries and perform arbitrary CIFS mounts via vectors involving an add_key call, related to a "cache stuffing" issue and MS-DFS referrals.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 70608756570f270952a30400f0f97a67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062623" comment="kernel-default-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062624" comment="kernel-desktop-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062625" comment="kernel-xen-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
	<!-- e2f6c6cc02f7dc05554cab87c9f88650 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062408" comment="btrfs-kmp-pae less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062410" comment="hyper-v-kmp-pae less than 0_2.6.32.19_0.2-0.7.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062623" comment="kernel-default-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062624" comment="kernel-desktop-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062411" comment="kernel-pae-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062412" comment="kernel-pae-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062626" comment="kernel-pae-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062413" comment="kernel-pae less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062625" comment="kernel-xen-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102526" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2526</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2526" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2526" source="CVE"/>
	<description>
	The cluster logical volume manager daemon (clvmd) in lvm2-cluster in LVM2 before 2.02.72, as used in Red Hat Global File System (GFS) and other products, does not verify client credentials upon a socket connection, which allows local users to cause a denial of service (daemon exit or logical-volume change) or possibly have unspecified other impact via crafted control commands.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5d5a4e6a66842e208571ff8227921547 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062642" comment="lvm2 less than 2.02.39-18.26.3"/>
	</criteria>
	<!-- 8a73ebc90cadef3ab692d6db3b81626d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062643" comment="lvm2 less than 2.02.39-18.31.2"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102527" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2527</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2527" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2527" source="CVE"/>
	<description>
	Multiple buffer overflows in demo programs in FreeType before 2.4.0 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 7bcc9a1fade88c7620df728424de42c5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062111" comment="freetype2-devel less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
	<!-- f28613bd3eb0b0f8e83bbf97c432760b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062111" comment="freetype2-devel less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102537" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2537</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2537" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2537" source="CVE"/>
	<description>
	The btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a (1) BTRFS_IOC_CLONE or (2) BTRFS_IOC_CLONE_RANGE ioctl call that specifies this file as a donor.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 70608756570f270952a30400f0f97a67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062623" comment="kernel-default-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062624" comment="kernel-desktop-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062625" comment="kernel-xen-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
	<!-- e2f6c6cc02f7dc05554cab87c9f88650 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062408" comment="btrfs-kmp-pae less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062410" comment="hyper-v-kmp-pae less than 0_2.6.32.19_0.2-0.7.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062623" comment="kernel-default-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062624" comment="kernel-desktop-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062411" comment="kernel-pae-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062412" comment="kernel-pae-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062626" comment="kernel-pae-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062413" comment="kernel-pae less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062625" comment="kernel-xen-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102538" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2538</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2538" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2538" source="CVE"/>
	<description>
	Integer overflow in the btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2.6.35 might allow local users to obtain sensitive information via a BTRFS_IOC_CLONE_RANGE ioctl call.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 70608756570f270952a30400f0f97a67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062623" comment="kernel-default-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062624" comment="kernel-desktop-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062625" comment="kernel-xen-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
	<!-- e2f6c6cc02f7dc05554cab87c9f88650 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062408" comment="btrfs-kmp-pae less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062410" comment="hyper-v-kmp-pae less than 0_2.6.32.19_0.2-0.7.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062623" comment="kernel-default-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062624" comment="kernel-desktop-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062411" comment="kernel-pae-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062412" comment="kernel-pae-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062626" comment="kernel-pae-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062413" comment="kernel-pae less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062625" comment="kernel-xen-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102541" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2541</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2541" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2541" source="CVE"/>
	<description>
	Buffer overflow in ftmulti.c in the ftmulti demo program in FreeType before 2.4.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 7bcc9a1fade88c7620df728424de42c5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062111" comment="freetype2-devel less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
	<!-- f28613bd3eb0b0f8e83bbf97c432760b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062111" comment="freetype2-devel less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102547" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2547</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2547" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2547" source="CVE"/>
	<description>
	Use-after-free vulnerability in kbx/keybox-blob.c in GPGSM in GnuPG 2.x through 2.0.16 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a certificate with a large number of Subject Alternate Names, which is not properly handled in a realloc operation when importing the certificate or verifying its signature.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- ab5fff9f4b3475bf58d306cbb6b25aef -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061951" comment="gpg2-lang less than 2.0.9-25.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061952" comment="gpg2 less than 2.0.9-25.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061953" comment="libgcrypt11-32bit less than 1.4.1-6.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061955" comment="libgcrypt11 less than 1.4.1-6.7"/>
		</criteria>
	</criteria>
	<!-- d0a463a21a2a3eaac40630a601b657a3 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061951" comment="gpg2-lang less than 2.0.9-25.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061952" comment="gpg2 less than 2.0.9-25.26.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102575" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2575</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2575" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2575" source="CVE"/>
	<description>
	Heap-based buffer overflow in the RLE decompression functionality in the TranscribePalmImageToJPEG function in generators/plucker/inplug/image.cpp in Okular in KDE SC 4.3.0 through 4.5.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted image in a PDB file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5f5356890325fbbde04920c42296ed96 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063238" comment="kde4-gwenview less than 4.1.3-7.17.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063239" comment="kde4-kcolorchooser less than 4.1.3-7.17.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063317" comment="kde4-kgamma less than 4.1.3-7.17.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063318" comment="kde4-kio_kamera less than 4.1.3-7.17.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063240" comment="kde4-kruler less than 4.1.3-7.17.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063241" comment="kde4-ksnapshot less than 4.1.3-7.17.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063242" comment="kde4-okular less than 4.1.3-7.17.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063243" comment="libkipi5 less than 4.1.3-7.17.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063316" comment="libksane0 less than 4.1.3-7.17.1"/>
		</criteria>
	</criteria>
	<!-- ab2f556bf2a34c6440fc935aabb8b6df -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063244" comment="gwenview less than 4.3.5-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063245" comment="kcolorchooser less than 4.3.5-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063319" comment="kdegraphics4 less than 4.3.5-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063325" comment="kgamma less than 4.3.5-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063326" comment="kio_kamera less than 4.3.5-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063246" comment="kruler less than 4.3.5-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063247" comment="ksnapshot less than 4.3.5-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063320" comment="libkdcraw7 less than 4.3.5-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063248" comment="libkexiv2-7 less than 4.3.5-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063249" comment="libkipi6 less than 4.3.5-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063323" comment="libksane0 less than 4.3.5-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063250" comment="okular less than 4.3.5-0.2.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102621" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2621</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2621" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2621" source="CVE"/>
	<description>
	The QSslSocketBackendPrivate::transmit function in src_network_ssl_qsslsocket_openssl.cpp in Qt 4.6.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a malformed request.
	</description>
 </metadata>
<!-- 34afda31849d3183ccf4b0c1ae44eb26 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009070875" comment="libQtWebKit4-32bit less than 4.6.3-5.10.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070877" comment="libQtWebKit4 less than 4.6.3-5.10.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070878" comment="libqt4-32bit less than 4.6.3-5.10.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070879" comment="libqt4-qt3support-32bit less than 4.6.3-5.10.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070881" comment="libqt4-qt3support less than 4.6.3-5.10.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070882" comment="libqt4-sql-32bit less than 4.6.3-5.10.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070897" comment="libqt4-sql-mysql-32bit less than 4.6.3-5.10.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070883" comment="libqt4-sql-mysql less than 4.6.3-5.10.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070899" comment="libqt4-sql-postgresql-32bit less than 4.6.3-5.10.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070901" comment="libqt4-sql-postgresql less than 4.6.3-5.10.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070902" comment="libqt4-sql-sqlite-32bit less than 4.6.3-5.10.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070884" comment="libqt4-sql-sqlite less than 4.6.3-5.10.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070904" comment="libqt4-sql-unixODBC-32bit less than 4.6.3-5.10.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070906" comment="libqt4-sql-unixODBC less than 4.6.3-5.10.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070886" comment="libqt4-sql less than 4.6.3-5.10.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070887" comment="libqt4-x11-32bit less than 4.6.3-5.10.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070889" comment="libqt4-x11 less than 4.6.3-5.10.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070891" comment="libqt4 less than 4.6.3-5.10.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102628" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2628</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2628" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2628" source="CVE"/>
	<description>
	The IKE daemon in strongSwan 4.3.x before 4.3.7 and 4.4.x before 4.4.1 does not properly check the return values of snprintf calls, which allows remote attackers to execute arbitrary code via crafted (1) certificate or (2) identity data that triggers buffer overflows.
	</description>
 </metadata>
<!-- 0fcdb75b2f24c2cf4d05018279a4e2b9 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009061963" comment="strongswan-doc less than 4.3.4-3.4.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061964" comment="strongswan less than 4.3.4-3.4.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102640" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2640</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2640" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2640" source="CVE"/>
	<description>
	Array index error in the PK font parser in the dvi-backend component in Evince 2.32 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer.
	</description>
 </metadata>
<!-- 625b56e690b7e91964f2b45637eb0b04 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009065542" comment="evince-lang less than 2.28.2-0.3.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009065543" comment="evince less than 2.28.2-0.3.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102641" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2641</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2641" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2641" source="CVE"/>
	<description>
	Array index error in the VF font parser in the dvi-backend component in Evince 2.32 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer.
	</description>
 </metadata>
<!-- 625b56e690b7e91964f2b45637eb0b04 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009065542" comment="evince-lang less than 2.28.2-0.3.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009065543" comment="evince less than 2.28.2-0.3.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102642" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2642</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2642" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2642" source="CVE"/>
	<description>
	Heap-based buffer overflow in the AFM font parser in the dvi-backend component in Evince 2.32 and earlier, teTeX 3.0, t1lib 5.1.2, and possibly other products allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 625b56e690b7e91964f2b45637eb0b04 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009065542" comment="evince-lang less than 2.28.2-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065543" comment="evince less than 2.28.2-0.3.1"/>
		</criteria>
	</criteria>
	<!-- 9d8611fed55623b964f5455e5c86abd4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065858" comment="t1lib less than 5.1.1-100.19.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102643" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2643</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2643" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2643" source="CVE"/>
	<description>
	Integer overflow in the TFM font parser in the dvi-backend component in Evince 2.32 and earlier allows remote attackers to execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer.
	</description>
 </metadata>
<!-- 625b56e690b7e91964f2b45637eb0b04 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009065542" comment="evince-lang less than 2.28.2-0.3.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009065543" comment="evince less than 2.28.2-0.3.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102713" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2713</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2713" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2713" source="CVE"/>
	<description>
	The vte_sequence_handler_window_manipulation function in vteseq.c in libvte (aka libvte9) in VTE 0.25.1 and earlier, as used in gnome-terminal, does not properly handle escape sequences, which allows remote attackers to execute arbitrary commands or obtain potentially sensitive information via a (1) window title or (2) icon title sequence.  NOTE: this issue exists because of a CVE-2003-0070 regression.
	</description>
 </metadata>
<!-- 6a3beb3117af5d396e2b650b8babbc2e -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009061710" comment="vte-lang less than 0.22.5-0.2.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061711" comment="vte less than 0.22.5-0.2.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102751" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2751</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2751" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2751" source="CVE"/>
	<description>
	The nsDocShell::OnRedirectStateChange function in docshell/base/nsDocShell.cpp in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to spoof the SSL security status of a document via vectors involving multiple requests, a redirect, and the history.back and history.forward JavaScript functions.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0d0d8706df2d64128121ceea3338a129 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061819" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061840" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
	<!-- f23d3ef3410fecb23cf62a058d285514 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061819" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061840" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102752" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2752</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2752" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2752" source="CVE"/>
	<description>
	Integer overflow in an array class in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code by placing many Cascading Style Sheets (CSS) values in an array, related to references to external font resources and an inconsistency between 16-bit and 32-bit integers.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0d0d8706df2d64128121ceea3338a129 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061819" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061840" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
	<!-- f23d3ef3410fecb23cf62a058d285514 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061819" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061840" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102753" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2753</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2753" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2753" source="CVE"/>
	<description>
	Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code via a large selection attribute in a XUL tree element, which triggers a use-after-free.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 090848ec46b4dd478bc9cd3ba9442531 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063420" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063422" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 0c29d728f4fd029a2fbf4ea1e669fc81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
	<!-- 0d0d8706df2d64128121ceea3338a129 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061819" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061840" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 50a3e55a414b85ba53fc6385752379a7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063420" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063422" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 8f1a8feab628d727a6016f2016a02361 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
	<!-- f23d3ef3410fecb23cf62a058d285514 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061819" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061840" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102754" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2754</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2754" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2754" source="CVE"/>
	<description>
	dom/base/nsJSEnvironment.cpp in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 does not properly suppress a script's URL in certain circumstances involving a redirect and an error message, which allows remote attackers to obtain sensitive information about script parameters via a crafted HTML document, related to the window.onerror handler.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0d0d8706df2d64128121ceea3338a129 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061819" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061840" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
	<!-- f23d3ef3410fecb23cf62a058d285514 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061819" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061840" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102760" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2760</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2760" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2760" source="CVE"/>
	<description>
	Use-after-free vulnerability in the nsTreeSelection function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 might allow remote attackers to execute arbitrary code via vectors involving a XUL tree selection, related to a "dangling pointer vulnerability." NOTE: this issue exists because of an incomplete fix for CVE-2010-2753.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 090848ec46b4dd478bc9cd3ba9442531 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063420" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063422" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 0c29d728f4fd029a2fbf4ea1e669fc81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
	<!-- 50a3e55a414b85ba53fc6385752379a7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063420" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063422" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 8f1a8feab628d727a6016f2016a02361 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102761" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2761</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2761" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2761" source="CVE"/>
	<description>
	The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier uses a hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, which allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input that contains this value, a different vulnerability than CVE-2010-3172.
	</description>
 </metadata>
<!-- 31907ff5cbd65bb3539b83632a7125a2 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009065589" comment="perl-32bit less than 5.10.0-64.53.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009065590" comment="perl-base less than 5.10.0-64.53.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009065591" comment="perl-doc less than 5.10.0-64.53.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009065593" comment="perl less than 5.10.0-64.53.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102762" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2762</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2762" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2762" source="CVE"/>
	<description>
	The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Firefox 3.6.x before 3.6.9 and Thunderbird 3.1.x before 3.1.3 does not properly restrict objects at the end of scope chains, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via vectors related to a chrome privileged object and a chain ending in an outer object.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 090848ec46b4dd478bc9cd3ba9442531 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063420" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063422" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 0c29d728f4fd029a2fbf4ea1e669fc81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
	<!-- 50a3e55a414b85ba53fc6385752379a7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063420" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063422" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 8f1a8feab628d727a6016f2016a02361 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102763" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2763</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2763" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2763" source="CVE"/>
	<description>
	The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Firefox before 3.5.12, Thunderbird before 3.0.7, and SeaMonkey before 2.0.7 does not properly restrict scripted functions, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted function.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 090848ec46b4dd478bc9cd3ba9442531 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063420" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063422" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 0c29d728f4fd029a2fbf4ea1e669fc81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
	<!-- 50a3e55a414b85ba53fc6385752379a7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063420" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063422" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 8f1a8feab628d727a6016f2016a02361 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102764" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2764</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2764" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2764" source="CVE"/>
	<description>
	Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 do not properly restrict read access to the statusText property of XMLHttpRequest objects, which allows remote attackers to discover the existence of intranet web servers via cross-origin requests.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 090848ec46b4dd478bc9cd3ba9442531 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063420" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063422" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 0c29d728f4fd029a2fbf4ea1e669fc81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
	<!-- 50a3e55a414b85ba53fc6385752379a7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063420" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063422" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 8f1a8feab628d727a6016f2016a02361 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102765" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2765</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2765" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2765" source="CVE"/>
	<description>
	Integer overflow in the FRAMESET element implementation in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 might allow remote attackers to execute arbitrary code via a large number of values in the cols (aka columns) attribute, leading to a heap-based buffer overflow.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 090848ec46b4dd478bc9cd3ba9442531 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063420" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063422" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 0c29d728f4fd029a2fbf4ea1e669fc81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
	<!-- 50a3e55a414b85ba53fc6385752379a7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063420" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063422" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 8f1a8feab628d727a6016f2016a02361 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102766" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2766</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2766" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2766" source="CVE"/>
	<description>
	The normalizeDocument function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle the removal of DOM nodes during normalization, which might allow remote attackers to execute arbitrary code via vectors involving access to a deleted object.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 090848ec46b4dd478bc9cd3ba9442531 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063420" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063422" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 0c29d728f4fd029a2fbf4ea1e669fc81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
	<!-- 50a3e55a414b85ba53fc6385752379a7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063420" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063422" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 8f1a8feab628d727a6016f2016a02361 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102767" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2767</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2767" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2767" source="CVE"/>
	<description>
	The navigator.plugins implementation in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle destruction of the DOM plugin array, which might allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via crafted access to the navigator object, related to a "dangling pointer vulnerability."
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 090848ec46b4dd478bc9cd3ba9442531 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063420" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063422" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 0c29d728f4fd029a2fbf4ea1e669fc81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
	<!-- 50a3e55a414b85ba53fc6385752379a7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063420" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063422" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 8f1a8feab628d727a6016f2016a02361 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102768" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2768</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2768" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2768" source="CVE"/>
	<description>
	Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 do not properly restrict use of the type attribute of an OBJECT element to set a document's charset, which allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms via UTF-7 encoding.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 090848ec46b4dd478bc9cd3ba9442531 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063420" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063422" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 0c29d728f4fd029a2fbf4ea1e669fc81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
	<!-- 50a3e55a414b85ba53fc6385752379a7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063420" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063422" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 8f1a8feab628d727a6016f2016a02361 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102769" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2769</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2769" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2769" source="CVE"/>
	<description>
	Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 allows user-assisted remote attackers to inject arbitrary web script or HTML via a selection that is added to a document in which the designMode property is enabled.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 090848ec46b4dd478bc9cd3ba9442531 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063420" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063422" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 0c29d728f4fd029a2fbf4ea1e669fc81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
	<!-- 50a3e55a414b85ba53fc6385752379a7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063420" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063422" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 8f1a8feab628d727a6016f2016a02361 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102770" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2770</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2770" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2770" source="CVE"/>
	<description>
	Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 on Mac OS X allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted font in a data: URL.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 090848ec46b4dd478bc9cd3ba9442531 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063420" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063422" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 0c29d728f4fd029a2fbf4ea1e669fc81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
	<!-- 50a3e55a414b85ba53fc6385752379a7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063420" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063422" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 8f1a8feab628d727a6016f2016a02361 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102798" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2798</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2798" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2798" source="CVE"/>
	<description>
	The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, which allows local users to cause a denial of service (NULL pointer dereference and panic) and possibly have unspecified other impact by renaming a file in a GFS2 filesystem, related to the gfs2_rename function in fs/gfs2/ops_inode.c.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 397f45e4eb102e91e10ebd86d7e1eb7b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063845" comment="kernel-pae-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063855" comment="kernel-pae-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063846" comment="kernel-pae less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063851" comment="kernel-xen-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063856" comment="kernel-xen-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063852" comment="kernel-xen less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- 70608756570f270952a30400f0f97a67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062623" comment="kernel-default-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062624" comment="kernel-desktop-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062625" comment="kernel-xen-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
	<!-- d69f430f61b72448377e859dd89a3663 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063851" comment="kernel-xen-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063856" comment="kernel-xen-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063852" comment="kernel-xen less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- e2f6c6cc02f7dc05554cab87c9f88650 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062408" comment="btrfs-kmp-pae less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062410" comment="hyper-v-kmp-pae less than 0_2.6.32.19_0.2-0.7.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062623" comment="kernel-default-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062624" comment="kernel-desktop-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062411" comment="kernel-pae-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062412" comment="kernel-pae-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062626" comment="kernel-pae-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062413" comment="kernel-pae less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062625" comment="kernel-xen-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102803" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2803</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2803" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2803" source="CVE"/>
	<description>
	The drm_ioctl function in drivers/gpu/drm/drm_drv.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.27.53, 2.6.32.x before 2.6.32.21, 2.6.34.x before 2.6.34.6, and 2.6.35.x before 2.6.35.4 allows local users to obtain potentially sensitive information from kernel memory by requesting a large memory-allocation amount.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 397f45e4eb102e91e10ebd86d7e1eb7b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063845" comment="kernel-pae-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063855" comment="kernel-pae-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063846" comment="kernel-pae less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063851" comment="kernel-xen-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063856" comment="kernel-xen-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063852" comment="kernel-xen less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- 70608756570f270952a30400f0f97a67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062623" comment="kernel-default-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062624" comment="kernel-desktop-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062625" comment="kernel-xen-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
	<!-- d69f430f61b72448377e859dd89a3663 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063851" comment="kernel-xen-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063856" comment="kernel-xen-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063852" comment="kernel-xen less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- e2f6c6cc02f7dc05554cab87c9f88650 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062408" comment="btrfs-kmp-pae less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062410" comment="hyper-v-kmp-pae less than 0_2.6.32.19_0.2-0.7.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062623" comment="kernel-default-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062624" comment="kernel-desktop-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062411" comment="kernel-pae-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062412" comment="kernel-pae-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062626" comment="kernel-pae-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062413" comment="kernel-pae less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062625" comment="kernel-xen-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102805" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2805</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2805" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2805" source="CVE"/>
	<description>
	The FT_Stream_EnterFrame function in base/ftstream.c in FreeType before 2.4.2 does not properly validate certain position values, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 7bcc9a1fade88c7620df728424de42c5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062111" comment="freetype2-devel less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
	<!-- f28613bd3eb0b0f8e83bbf97c432760b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062111" comment="freetype2-devel less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102806" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2806</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2806" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2806" source="CVE"/>
	<description>
	Array index error in the t42_parse_sfnts function in type42/t42parse.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via negative size values for certain strings in FontType42 font files, leading to a heap-based buffer overflow.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 7bcc9a1fade88c7620df728424de42c5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062111" comment="freetype2-devel less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
	<!-- f28613bd3eb0b0f8e83bbf97c432760b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062111" comment="freetype2-devel less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102807" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2807</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2807" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2807" source="CVE"/>
	<description>
	FreeType before 2.4.2 uses incorrect integer data types during bounds checking, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 7bcc9a1fade88c7620df728424de42c5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062111" comment="freetype2-devel less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
	<!-- f28613bd3eb0b0f8e83bbf97c432760b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062111" comment="freetype2-devel less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102808" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2808</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2808" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2808" source="CVE"/>
	<description>
	Buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Adobe Type 1 Mac Font File (aka LWFN) font.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 7bcc9a1fade88c7620df728424de42c5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062111" comment="freetype2-devel less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
	<!-- f28613bd3eb0b0f8e83bbf97c432760b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062111" comment="freetype2-devel less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102862" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2862</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2862" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2862" source="CVE"/>
	<description>
	Integer overflow in CoolType.dll in Adobe Reader 8.2.3 and 9.3.3, and Acrobat 9.3.3, allows remote attackers to execute arbitrary code via a TrueType font with a large maxCompositePoints value in a Maximum Profile (maxp) table.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 095cf91c7a73fc7f8adfcb7b68dd1ea9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062194" comment="acroread_ja less than 9.3.4-0.1.1"/>
	</criteria>
	<!-- 36a9cbb312d6ad766eed81d158f1dc01 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062194" comment="acroread_ja less than 9.3.4-0.1.1"/>
	</criteria>
	<!-- df4199604d1ebfce8b612958957eb533 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062202" comment="acroread-cmaps less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062203" comment="acroread-fonts-ja less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062204" comment="acroread-fonts-ko less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062205" comment="acroread-fonts-zh_CN less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062206" comment="acroread-fonts-zh_TW less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062207" comment="acroread less than 9.3.4-0.6.1"/>
		</criteria>
	</criteria>
	<!-- f1ea8f5a6e6b82355c9b5987cea86fa1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062202" comment="acroread-cmaps less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062203" comment="acroread-fonts-ja less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062204" comment="acroread-fonts-ko less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062205" comment="acroread-fonts-zh_CN less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062206" comment="acroread-fonts-zh_TW less than 9.3.4-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062207" comment="acroread less than 9.3.4-0.6.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102883" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2883</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2883" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2883" source="CVE"/>
	<description>
	Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PDF document with a long field in a Smart INdependent Glyphlets (SING) table in a TTF font, as exploited in the wild in September 2010. NOTE: some of these details are obtained from third party information.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 3c2582b28a6df00c0044711409f98535 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063369" comment="acroread_ja less than 9.4-0.1.1"/>
	</criteria>
	<!-- 54194dab635014e7c5bd3bc55a981c18 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063369" comment="acroread_ja less than 9.4-0.1.1"/>
	</criteria>
	<!-- 61384960a1cfb69ccdbfdf71d156025c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063363" comment="acroread-cmaps less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063364" comment="acroread-fonts-ja less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063365" comment="acroread-fonts-ko less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063366" comment="acroread-fonts-zh_CN less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063367" comment="acroread-fonts-zh_TW less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063368" comment="acroread less than 9.4-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 8aa212875de59e00a30c68fbc6c66084 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063363" comment="acroread-cmaps less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063364" comment="acroread-fonts-ja less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063365" comment="acroread-fonts-ko less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063366" comment="acroread-fonts-zh_CN less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063367" comment="acroread-fonts-zh_TW less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063368" comment="acroread less than 9.4-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102884" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2884</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2884" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2884" source="CVE"/>
	<description>
	Adobe Flash Player 10.1.82.76 and earlier on Windows, Mac OS X, Linux, and Solaris and 10.1.92.10 on Android; authplay.dll in Adobe Reader and Acrobat 9.x before 9.4; and authplay.dll in Adobe Reader and Acrobat 8.x before 8.2.5 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in September 2010.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1d653bf3426f00be62b14a0b1125c791 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062813" comment="flash-player less than 10.1.85.3-0.1.1"/>
	</criteria>
	<!-- 3c2582b28a6df00c0044711409f98535 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063369" comment="acroread_ja less than 9.4-0.1.1"/>
	</criteria>
	<!-- 54194dab635014e7c5bd3bc55a981c18 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063369" comment="acroread_ja less than 9.4-0.1.1"/>
	</criteria>
	<!-- 61384960a1cfb69ccdbfdf71d156025c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063363" comment="acroread-cmaps less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063364" comment="acroread-fonts-ja less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063365" comment="acroread-fonts-ko less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063366" comment="acroread-fonts-zh_CN less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063367" comment="acroread-fonts-zh_TW less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063368" comment="acroread less than 9.4-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 8aa212875de59e00a30c68fbc6c66084 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063363" comment="acroread-cmaps less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063364" comment="acroread-fonts-ja less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063365" comment="acroread-fonts-ko less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063366" comment="acroread-fonts-zh_CN less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063367" comment="acroread-fonts-zh_TW less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063368" comment="acroread less than 9.4-0.1.1"/>
		</criteria>
	</criteria>
	<!-- c00d57dfe8ed1ac9b122438618807c85 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062813" comment="flash-player less than 10.1.85.3-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102887" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2887</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2887" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2887" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in Adobe Reader and Acrobat 9.x before 9.4 on Linux allow attackers to gain privileges via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 3c2582b28a6df00c0044711409f98535 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063369" comment="acroread_ja less than 9.4-0.1.1"/>
	</criteria>
	<!-- 54194dab635014e7c5bd3bc55a981c18 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063369" comment="acroread_ja less than 9.4-0.1.1"/>
	</criteria>
	<!-- 61384960a1cfb69ccdbfdf71d156025c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063363" comment="acroread-cmaps less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063364" comment="acroread-fonts-ja less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063365" comment="acroread-fonts-ko less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063366" comment="acroread-fonts-zh_CN less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063367" comment="acroread-fonts-zh_TW less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063368" comment="acroread less than 9.4-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 8aa212875de59e00a30c68fbc6c66084 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063363" comment="acroread-cmaps less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063364" comment="acroread-fonts-ja less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063365" comment="acroread-fonts-ko less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063366" comment="acroread-fonts-zh_CN less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063367" comment="acroread-fonts-zh_TW less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063368" comment="acroread less than 9.4-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102889" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2889</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2889" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2889" source="CVE"/>
	<description>
	Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to execute arbitrary code via a crafted font, a different vulnerability than CVE-2010-3626.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 3c2582b28a6df00c0044711409f98535 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063369" comment="acroread_ja less than 9.4-0.1.1"/>
	</criteria>
	<!-- 54194dab635014e7c5bd3bc55a981c18 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063369" comment="acroread_ja less than 9.4-0.1.1"/>
	</criteria>
	<!-- 61384960a1cfb69ccdbfdf71d156025c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063363" comment="acroread-cmaps less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063364" comment="acroread-fonts-ja less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063365" comment="acroread-fonts-ko less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063366" comment="acroread-fonts-zh_CN less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063367" comment="acroread-fonts-zh_TW less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063368" comment="acroread less than 9.4-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 8aa212875de59e00a30c68fbc6c66084 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063363" comment="acroread-cmaps less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063364" comment="acroread-fonts-ja less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063365" comment="acroread-fonts-ko less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063366" comment="acroread-fonts-zh_CN less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063367" comment="acroread-fonts-zh_TW less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063368" comment="acroread less than 9.4-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102890" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2890</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2890" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2890" source="CVE"/>
	<description>
	Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-3619, CVE-2010-3621, CVE-2010-3622, CVE-2010-3628, CVE-2010-3632, and CVE-2010-3658.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 3c2582b28a6df00c0044711409f98535 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063369" comment="acroread_ja less than 9.4-0.1.1"/>
	</criteria>
	<!-- 54194dab635014e7c5bd3bc55a981c18 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063369" comment="acroread_ja less than 9.4-0.1.1"/>
	</criteria>
	<!-- 61384960a1cfb69ccdbfdf71d156025c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063363" comment="acroread-cmaps less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063364" comment="acroread-fonts-ja less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063365" comment="acroread-fonts-ko less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063366" comment="acroread-fonts-zh_CN less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063367" comment="acroread-fonts-zh_TW less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063368" comment="acroread less than 9.4-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 8aa212875de59e00a30c68fbc6c66084 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063363" comment="acroread-cmaps less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063364" comment="acroread-fonts-ja less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063365" comment="acroread-fonts-ko less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063366" comment="acroread-fonts-zh_CN less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063367" comment="acroread-fonts-zh_TW less than 9.4-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063368" comment="acroread less than 9.4-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102901" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2901</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2901" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2901" source="CVE"/>
	<description>
	The rendering implementation in Google Chrome before 5.0.375.125 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
	</description>
 </metadata>
<!-- f57e4769dd3aca778aead0ead7cd3c6f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009069232" comment="libwebkit-1_0-2 less than 1.2.7-0.11.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009069234" comment="libwebkit-lang less than 1.2.7-0.11.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009069235" comment="webkit-sharp less than 0.2-2.45.3"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102935" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2935</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2935" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2935" source="CVE"/>
	<description>
	simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle integer values associated with dictionary property items, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PowerPoint document that triggers a heap-based buffer overflow, related to an "integer truncation error."
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 40ef767aa8cfa452b350fadc49a55ce0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063682" comment="OpenOffice_org-base-drivers-postgresql less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063683" comment="OpenOffice_org-base-extensions less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063619" comment="OpenOffice_org-base less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063684" comment="OpenOffice_org-calc-extensions less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063622" comment="OpenOffice_org-calc less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063624" comment="OpenOffice_org-components less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063685" comment="OpenOffice_org-draw-extensions less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063625" comment="OpenOffice_org-draw less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063627" comment="OpenOffice_org-filters-optional less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063628" comment="OpenOffice_org-filters less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063629" comment="OpenOffice_org-gnome less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063630" comment="OpenOffice_org-help-en-US-devel less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063631" comment="OpenOffice_org-help-en-US less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063632" comment="OpenOffice_org-icon-themes less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063686" comment="OpenOffice_org-impress-extensions less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063634" comment="OpenOffice_org-impress less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063635" comment="OpenOffice_org-kde less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063636" comment="OpenOffice_org-l10n-af less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063637" comment="OpenOffice_org-l10n-ar less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063638" comment="OpenOffice_org-l10n-ca less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063639" comment="OpenOffice_org-l10n-cs less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063640" comment="OpenOffice_org-l10n-da less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063641" comment="OpenOffice_org-l10n-de less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063642" comment="OpenOffice_org-l10n-el less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063643" comment="OpenOffice_org-l10n-en-GB less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063644" comment="OpenOffice_org-l10n-es less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063646" comment="OpenOffice_org-l10n-extras less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063647" comment="OpenOffice_org-l10n-fi less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063648" comment="OpenOffice_org-l10n-fr less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063687" comment="OpenOffice_org-l10n-gu-IN less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063688" comment="OpenOffice_org-l10n-hi-IN less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063649" comment="OpenOffice_org-l10n-hu less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063650" comment="OpenOffice_org-l10n-it less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063651" comment="OpenOffice_org-l10n-ja less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063689" comment="OpenOffice_org-l10n-ko less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063652" comment="OpenOffice_org-l10n-nb less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063653" comment="OpenOffice_org-l10n-nl less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063654" comment="OpenOffice_org-l10n-nn less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063655" comment="OpenOffice_org-l10n-pl less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063656" comment="OpenOffice_org-l10n-pt-BR less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063657" comment="OpenOffice_org-l10n-pt less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063658" comment="OpenOffice_org-l10n-ru less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063659" comment="OpenOffice_org-l10n-sk less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063660" comment="OpenOffice_org-l10n-sv less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063661" comment="OpenOffice_org-l10n-xh less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063662" comment="OpenOffice_org-l10n-zh-CN less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063663" comment="OpenOffice_org-l10n-zh-TW less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063664" comment="OpenOffice_org-l10n-zu less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063666" comment="OpenOffice_org-libs-core less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063668" comment="OpenOffice_org-libs-extern less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063670" comment="OpenOffice_org-libs-gui less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063671" comment="OpenOffice_org-mailmerge less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063672" comment="OpenOffice_org-math less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063673" comment="OpenOffice_org-mono less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063674" comment="OpenOffice_org-officebean less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063675" comment="OpenOffice_org-pyuno less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063678" comment="OpenOffice_org-ure less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063690" comment="OpenOffice_org-writer-extensions less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063680" comment="OpenOffice_org-writer less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063681" comment="OpenOffice_org less than 3.2.1.6-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 9c036937b6a42810ef9c8a7caff47b50 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009066355" comment="libreoffice-base-drivers-postgresql less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066356" comment="libreoffice-base-extensions less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066228" comment="libreoffice-base less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066230" comment="libreoffice-branding-SLED less than 3.3.1-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066357" comment="libreoffice-calc-extensions less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066233" comment="libreoffice-calc less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066235" comment="libreoffice-components less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066358" comment="libreoffice-converter less than 3.3-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066359" comment="libreoffice-draw-extensions less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066236" comment="libreoffice-draw less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066238" comment="libreoffice-filters-optional less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066239" comment="libreoffice-filters less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066240" comment="libreoffice-gnome less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066241" comment="libreoffice-help-ar less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066242" comment="libreoffice-help-cs less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066243" comment="libreoffice-help-da less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066244" comment="libreoffice-help-de less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066245" comment="libreoffice-help-en-GB less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066247" comment="libreoffice-help-en-US less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066248" comment="libreoffice-help-es less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066249" comment="libreoffice-help-fr less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066360" comment="libreoffice-help-gu-IN less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066361" comment="libreoffice-help-hi-IN less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066250" comment="libreoffice-help-hu less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066251" comment="libreoffice-help-it less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066252" comment="libreoffice-help-ja less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066362" comment="libreoffice-help-ko less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066253" comment="libreoffice-help-nl less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066254" comment="libreoffice-help-pl less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066255" comment="libreoffice-help-pt-BR less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066256" comment="libreoffice-help-pt less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066257" comment="libreoffice-help-ru less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066258" comment="libreoffice-help-sv less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066259" comment="libreoffice-help-zh-CN less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066260" comment="libreoffice-help-zh-TW less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066261" comment="libreoffice-hyphen less than 20110217-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066262" comment="libreoffice-icon-themes less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066363" comment="libreoffice-impress-extensions less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066264" comment="libreoffice-impress less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066265" comment="libreoffice-kde4 less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066266" comment="libreoffice-kde less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066267" comment="libreoffice-l10n-af less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066268" comment="libreoffice-l10n-ar less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066269" comment="libreoffice-l10n-ca less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066270" comment="libreoffice-l10n-cs less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066271" comment="libreoffice-l10n-da less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066272" comment="libreoffice-l10n-de less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066274" comment="libreoffice-l10n-en-GB less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066275" comment="libreoffice-l10n-es less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066277" comment="libreoffice-l10n-extras less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066278" comment="libreoffice-l10n-fi less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066279" comment="libreoffice-l10n-fr less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066364" comment="libreoffice-l10n-gu-IN less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066365" comment="libreoffice-l10n-hi-IN less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066280" comment="libreoffice-l10n-hu less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066281" comment="libreoffice-l10n-it less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066282" comment="libreoffice-l10n-ja less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066366" comment="libreoffice-l10n-ko less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066283" comment="libreoffice-l10n-nb less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066284" comment="libreoffice-l10n-nl less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066285" comment="libreoffice-l10n-nn less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066286" comment="libreoffice-l10n-pl less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066287" comment="libreoffice-l10n-pt-BR less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066288" comment="libreoffice-l10n-pt less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066289" comment="libreoffice-l10n-ru less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066290" comment="libreoffice-l10n-sk less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066291" comment="libreoffice-l10n-sv less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066292" comment="libreoffice-l10n-xh less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066293" comment="libreoffice-l10n-zh-CN less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066294" comment="libreoffice-l10n-zh-TW less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066295" comment="libreoffice-l10n-zu less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066367" comment="libreoffice-languagetool-de less than 1.2-7.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066368" comment="libreoffice-languagetool-en less than 1.2-7.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066369" comment="libreoffice-languagetool-es less than 1.2-7.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066370" comment="libreoffice-languagetool-fr less than 1.2-7.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066371" comment="libreoffice-languagetool-it less than 1.2-7.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066372" comment="libreoffice-languagetool-nl less than 1.2-7.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066373" comment="libreoffice-languagetool-pl less than 1.2-7.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066374" comment="libreoffice-languagetool-sv less than 1.2-7.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066375" comment="libreoffice-languagetool less than 1.2-7.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066297" comment="libreoffice-libs-core less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066299" comment="libreoffice-libs-extern less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066301" comment="libreoffice-libs-gui less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066302" comment="libreoffice-mailmerge less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066303" comment="libreoffice-math less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066304" comment="libreoffice-mono less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066305" comment="libreoffice-officebean less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066306" comment="libreoffice-openclipart less than 3.3-1.12.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066307" comment="libreoffice-pyuno less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066308" comment="libreoffice-templates-de less than 3.3-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066309" comment="libreoffice-templates-en less than 3.3-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066310" comment="libreoffice-templates-labels-a4 less than 1.0.1-1.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066311" comment="libreoffice-templates-labels-letter less than 1.0.1-1.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066312" comment="libreoffice-templates-presentation-layouts less than 3.3-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066314" comment="libreoffice-thesaurus-cs less than 20070913.1-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066315" comment="libreoffice-thesaurus-de less than 20080406.1-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066316" comment="libreoffice-thesaurus-en less than 20060111.1-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066317" comment="libreoffice-thesaurus-es less than 20050720.1-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066318" comment="libreoffice-thesaurus-fr less than 20060511.1-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066319" comment="libreoffice-thesaurus-hu less than 20080319.1-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066320" comment="libreoffice-thesaurus-nb less than 20080310.1-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066321" comment="libreoffice-thesaurus-pl less than 20061223.1-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066322" comment="libreoffice-thesaurus-pt less than 20060817.1-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066323" comment="libreoffice-thesaurus-ru less than 20061016.1-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066324" comment="libreoffice-thesaurus-sk less than 20080926.1-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066325" comment="libreoffice-thesaurus-sv less than 20080609.1-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066327" comment="libreoffice-ure less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066376" comment="libreoffice-writer-extensions less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066329" comment="libreoffice-writer less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066330" comment="libreoffice less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066331" comment="myspell-african less than 20060117-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066332" comment="myspell-american less than 20060207-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066333" comment="myspell-brazilian less than 20070606-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066334" comment="myspell-british less than 20050526-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066335" comment="myspell-catalan less than 0.1-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066336" comment="myspell-czech less than 20060303-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066337" comment="myspell-danish less than 20080314-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066338" comment="myspell-dutch less than 20070603-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066339" comment="myspell-french less than 20060914-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066340" comment="myspell-german less than 20071211-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066341" comment="myspell-gujarati less than 20060929-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066342" comment="myspell-hindi less than 0.1-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066343" comment="myspell-hungarian less than 20080315-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066344" comment="myspell-italian less than 20050711-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066345" comment="myspell-norsk-bokmaal less than 20080310-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066346" comment="myspell-norsk-nynorsk less than 20080310-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066347" comment="myspell-polish less than 20080514-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066348" comment="myspell-portuguese less than 20020629-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066349" comment="myspell-russian less than 20040406-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066350" comment="myspell-slovak less than 20060724-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066351" comment="myspell-spanish less than 20051029-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066352" comment="myspell-swedish less than 20080821-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066353" comment="myspell-xhosa less than 20060123-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066354" comment="myspell-zulu less than 20060120-8.21.1"/>
		</criteria>
	</criteria>
	<!-- a58d78e28808900595b905f3d0c7251e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063757" comment="OpenOffice_org-base-drivers-postgresql less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063758" comment="OpenOffice_org-base-extensions less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063693" comment="OpenOffice_org-base less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063759" comment="OpenOffice_org-calc-extensions less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063697" comment="OpenOffice_org-calc less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063699" comment="OpenOffice_org-components less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063760" comment="OpenOffice_org-draw-extensions less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063700" comment="OpenOffice_org-draw less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063702" comment="OpenOffice_org-filters-optional less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063703" comment="OpenOffice_org-filters less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063704" comment="OpenOffice_org-gnome less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063706" comment="OpenOffice_org-help-en-US less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063707" comment="OpenOffice_org-icon-themes less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063761" comment="OpenOffice_org-impress-extensions less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063709" comment="OpenOffice_org-impress less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063710" comment="OpenOffice_org-kde less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063711" comment="OpenOffice_org-l10n-af less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063712" comment="OpenOffice_org-l10n-ar less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063713" comment="OpenOffice_org-l10n-ca less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063714" comment="OpenOffice_org-l10n-cs less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063715" comment="OpenOffice_org-l10n-da less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063716" comment="OpenOffice_org-l10n-de less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063718" comment="OpenOffice_org-l10n-en-GB less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063719" comment="OpenOffice_org-l10n-es less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063721" comment="OpenOffice_org-l10n-extras less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063722" comment="OpenOffice_org-l10n-fi less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063723" comment="OpenOffice_org-l10n-fr less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063762" comment="OpenOffice_org-l10n-gu-IN less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063763" comment="OpenOffice_org-l10n-hi-IN less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063724" comment="OpenOffice_org-l10n-hu less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063725" comment="OpenOffice_org-l10n-it less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063726" comment="OpenOffice_org-l10n-ja less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063764" comment="OpenOffice_org-l10n-ko less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063727" comment="OpenOffice_org-l10n-nb less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063728" comment="OpenOffice_org-l10n-nl less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063729" comment="OpenOffice_org-l10n-nn less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063730" comment="OpenOffice_org-l10n-pl less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063731" comment="OpenOffice_org-l10n-pt-BR less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063732" comment="OpenOffice_org-l10n-pt less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063733" comment="OpenOffice_org-l10n-ru less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063734" comment="OpenOffice_org-l10n-sk less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063735" comment="OpenOffice_org-l10n-sv less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063736" comment="OpenOffice_org-l10n-xh less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063737" comment="OpenOffice_org-l10n-zh-CN less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063738" comment="OpenOffice_org-l10n-zh-TW less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063739" comment="OpenOffice_org-l10n-zu less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063741" comment="OpenOffice_org-libs-core less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063743" comment="OpenOffice_org-libs-extern less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063745" comment="OpenOffice_org-libs-gui less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063746" comment="OpenOffice_org-mailmerge less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063747" comment="OpenOffice_org-math less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063748" comment="OpenOffice_org-mono less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063749" comment="OpenOffice_org-officebean less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063750" comment="OpenOffice_org-pyuno less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063753" comment="OpenOffice_org-ure less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063765" comment="OpenOffice_org-writer-extensions less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063755" comment="OpenOffice_org-writer less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063756" comment="OpenOffice_org less than 3.2.1.6-0.7.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102936" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2936</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2936" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2936" source="CVE"/>
	<description>
	Integer overflow in simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted polygons in a PowerPoint document that triggers a heap-based buffer overflow.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 40ef767aa8cfa452b350fadc49a55ce0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063682" comment="OpenOffice_org-base-drivers-postgresql less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063683" comment="OpenOffice_org-base-extensions less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063619" comment="OpenOffice_org-base less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063684" comment="OpenOffice_org-calc-extensions less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063622" comment="OpenOffice_org-calc less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063624" comment="OpenOffice_org-components less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063685" comment="OpenOffice_org-draw-extensions less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063625" comment="OpenOffice_org-draw less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063627" comment="OpenOffice_org-filters-optional less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063628" comment="OpenOffice_org-filters less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063629" comment="OpenOffice_org-gnome less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063630" comment="OpenOffice_org-help-en-US-devel less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063631" comment="OpenOffice_org-help-en-US less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063632" comment="OpenOffice_org-icon-themes less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063686" comment="OpenOffice_org-impress-extensions less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063634" comment="OpenOffice_org-impress less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063635" comment="OpenOffice_org-kde less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063636" comment="OpenOffice_org-l10n-af less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063637" comment="OpenOffice_org-l10n-ar less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063638" comment="OpenOffice_org-l10n-ca less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063639" comment="OpenOffice_org-l10n-cs less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063640" comment="OpenOffice_org-l10n-da less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063641" comment="OpenOffice_org-l10n-de less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063642" comment="OpenOffice_org-l10n-el less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063643" comment="OpenOffice_org-l10n-en-GB less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063644" comment="OpenOffice_org-l10n-es less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063646" comment="OpenOffice_org-l10n-extras less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063647" comment="OpenOffice_org-l10n-fi less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063648" comment="OpenOffice_org-l10n-fr less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063687" comment="OpenOffice_org-l10n-gu-IN less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063688" comment="OpenOffice_org-l10n-hi-IN less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063649" comment="OpenOffice_org-l10n-hu less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063650" comment="OpenOffice_org-l10n-it less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063651" comment="OpenOffice_org-l10n-ja less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063689" comment="OpenOffice_org-l10n-ko less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063652" comment="OpenOffice_org-l10n-nb less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063653" comment="OpenOffice_org-l10n-nl less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063654" comment="OpenOffice_org-l10n-nn less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063655" comment="OpenOffice_org-l10n-pl less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063656" comment="OpenOffice_org-l10n-pt-BR less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063657" comment="OpenOffice_org-l10n-pt less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063658" comment="OpenOffice_org-l10n-ru less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063659" comment="OpenOffice_org-l10n-sk less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063660" comment="OpenOffice_org-l10n-sv less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063661" comment="OpenOffice_org-l10n-xh less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063662" comment="OpenOffice_org-l10n-zh-CN less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063663" comment="OpenOffice_org-l10n-zh-TW less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063664" comment="OpenOffice_org-l10n-zu less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063666" comment="OpenOffice_org-libs-core less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063668" comment="OpenOffice_org-libs-extern less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063670" comment="OpenOffice_org-libs-gui less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063671" comment="OpenOffice_org-mailmerge less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063672" comment="OpenOffice_org-math less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063673" comment="OpenOffice_org-mono less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063674" comment="OpenOffice_org-officebean less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063675" comment="OpenOffice_org-pyuno less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063678" comment="OpenOffice_org-ure less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063690" comment="OpenOffice_org-writer-extensions less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063680" comment="OpenOffice_org-writer less than 3.2.1.6-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063681" comment="OpenOffice_org less than 3.2.1.6-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 9c036937b6a42810ef9c8a7caff47b50 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009066355" comment="libreoffice-base-drivers-postgresql less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066356" comment="libreoffice-base-extensions less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066228" comment="libreoffice-base less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066230" comment="libreoffice-branding-SLED less than 3.3.1-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066357" comment="libreoffice-calc-extensions less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066233" comment="libreoffice-calc less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066235" comment="libreoffice-components less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066358" comment="libreoffice-converter less than 3.3-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066359" comment="libreoffice-draw-extensions less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066236" comment="libreoffice-draw less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066238" comment="libreoffice-filters-optional less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066239" comment="libreoffice-filters less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066240" comment="libreoffice-gnome less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066241" comment="libreoffice-help-ar less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066242" comment="libreoffice-help-cs less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066243" comment="libreoffice-help-da less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066244" comment="libreoffice-help-de less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066245" comment="libreoffice-help-en-GB less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066247" comment="libreoffice-help-en-US less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066248" comment="libreoffice-help-es less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066249" comment="libreoffice-help-fr less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066360" comment="libreoffice-help-gu-IN less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066361" comment="libreoffice-help-hi-IN less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066250" comment="libreoffice-help-hu less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066251" comment="libreoffice-help-it less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066252" comment="libreoffice-help-ja less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066362" comment="libreoffice-help-ko less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066253" comment="libreoffice-help-nl less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066254" comment="libreoffice-help-pl less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066255" comment="libreoffice-help-pt-BR less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066256" comment="libreoffice-help-pt less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066257" comment="libreoffice-help-ru less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066258" comment="libreoffice-help-sv less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066259" comment="libreoffice-help-zh-CN less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066260" comment="libreoffice-help-zh-TW less than 3.3.1.2-1.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066261" comment="libreoffice-hyphen less than 20110217-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066262" comment="libreoffice-icon-themes less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066363" comment="libreoffice-impress-extensions less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066264" comment="libreoffice-impress less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066265" comment="libreoffice-kde4 less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066266" comment="libreoffice-kde less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066267" comment="libreoffice-l10n-af less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066268" comment="libreoffice-l10n-ar less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066269" comment="libreoffice-l10n-ca less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066270" comment="libreoffice-l10n-cs less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066271" comment="libreoffice-l10n-da less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066272" comment="libreoffice-l10n-de less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066274" comment="libreoffice-l10n-en-GB less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066275" comment="libreoffice-l10n-es less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066277" comment="libreoffice-l10n-extras less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066278" comment="libreoffice-l10n-fi less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066279" comment="libreoffice-l10n-fr less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066364" comment="libreoffice-l10n-gu-IN less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066365" comment="libreoffice-l10n-hi-IN less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066280" comment="libreoffice-l10n-hu less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066281" comment="libreoffice-l10n-it less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066282" comment="libreoffice-l10n-ja less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066366" comment="libreoffice-l10n-ko less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066283" comment="libreoffice-l10n-nb less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066284" comment="libreoffice-l10n-nl less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066285" comment="libreoffice-l10n-nn less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066286" comment="libreoffice-l10n-pl less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066287" comment="libreoffice-l10n-pt-BR less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066288" comment="libreoffice-l10n-pt less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066289" comment="libreoffice-l10n-ru less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066290" comment="libreoffice-l10n-sk less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066291" comment="libreoffice-l10n-sv less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066292" comment="libreoffice-l10n-xh less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066293" comment="libreoffice-l10n-zh-CN less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066294" comment="libreoffice-l10n-zh-TW less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066295" comment="libreoffice-l10n-zu less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066367" comment="libreoffice-languagetool-de less than 1.2-7.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066368" comment="libreoffice-languagetool-en less than 1.2-7.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066369" comment="libreoffice-languagetool-es less than 1.2-7.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066370" comment="libreoffice-languagetool-fr less than 1.2-7.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066371" comment="libreoffice-languagetool-it less than 1.2-7.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066372" comment="libreoffice-languagetool-nl less than 1.2-7.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066373" comment="libreoffice-languagetool-pl less than 1.2-7.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066374" comment="libreoffice-languagetool-sv less than 1.2-7.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066375" comment="libreoffice-languagetool less than 1.2-7.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066297" comment="libreoffice-libs-core less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066299" comment="libreoffice-libs-extern less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066301" comment="libreoffice-libs-gui less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066302" comment="libreoffice-mailmerge less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066303" comment="libreoffice-math less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066304" comment="libreoffice-mono less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066305" comment="libreoffice-officebean less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066306" comment="libreoffice-openclipart less than 3.3-1.12.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066307" comment="libreoffice-pyuno less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066308" comment="libreoffice-templates-de less than 3.3-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066309" comment="libreoffice-templates-en less than 3.3-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066310" comment="libreoffice-templates-labels-a4 less than 1.0.1-1.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066311" comment="libreoffice-templates-labels-letter less than 1.0.1-1.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066312" comment="libreoffice-templates-presentation-layouts less than 3.3-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066314" comment="libreoffice-thesaurus-cs less than 20070913.1-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066315" comment="libreoffice-thesaurus-de less than 20080406.1-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066316" comment="libreoffice-thesaurus-en less than 20060111.1-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066317" comment="libreoffice-thesaurus-es less than 20050720.1-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066318" comment="libreoffice-thesaurus-fr less than 20060511.1-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066319" comment="libreoffice-thesaurus-hu less than 20080319.1-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066320" comment="libreoffice-thesaurus-nb less than 20080310.1-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066321" comment="libreoffice-thesaurus-pl less than 20061223.1-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066322" comment="libreoffice-thesaurus-pt less than 20060817.1-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066323" comment="libreoffice-thesaurus-ru less than 20061016.1-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066324" comment="libreoffice-thesaurus-sk less than 20080926.1-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066325" comment="libreoffice-thesaurus-sv less than 20080609.1-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066327" comment="libreoffice-ure less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066376" comment="libreoffice-writer-extensions less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066329" comment="libreoffice-writer less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066330" comment="libreoffice less than 3.3.1.2-1.3.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066331" comment="myspell-african less than 20060117-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066332" comment="myspell-american less than 20060207-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066333" comment="myspell-brazilian less than 20070606-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066334" comment="myspell-british less than 20050526-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066335" comment="myspell-catalan less than 0.1-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066336" comment="myspell-czech less than 20060303-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066337" comment="myspell-danish less than 20080314-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066338" comment="myspell-dutch less than 20070603-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066339" comment="myspell-french less than 20060914-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066340" comment="myspell-german less than 20071211-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066341" comment="myspell-gujarati less than 20060929-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066342" comment="myspell-hindi less than 0.1-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066343" comment="myspell-hungarian less than 20080315-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066344" comment="myspell-italian less than 20050711-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066345" comment="myspell-norsk-bokmaal less than 20080310-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066346" comment="myspell-norsk-nynorsk less than 20080310-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066347" comment="myspell-polish less than 20080514-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066348" comment="myspell-portuguese less than 20020629-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066349" comment="myspell-russian less than 20040406-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066350" comment="myspell-slovak less than 20060724-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066351" comment="myspell-spanish less than 20051029-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066352" comment="myspell-swedish less than 20080821-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066353" comment="myspell-xhosa less than 20060123-8.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066354" comment="myspell-zulu less than 20060120-8.21.1"/>
		</criteria>
	</criteria>
	<!-- a58d78e28808900595b905f3d0c7251e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063757" comment="OpenOffice_org-base-drivers-postgresql less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063758" comment="OpenOffice_org-base-extensions less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063693" comment="OpenOffice_org-base less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063759" comment="OpenOffice_org-calc-extensions less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063697" comment="OpenOffice_org-calc less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063699" comment="OpenOffice_org-components less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063760" comment="OpenOffice_org-draw-extensions less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063700" comment="OpenOffice_org-draw less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063702" comment="OpenOffice_org-filters-optional less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063703" comment="OpenOffice_org-filters less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063704" comment="OpenOffice_org-gnome less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063706" comment="OpenOffice_org-help-en-US less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063707" comment="OpenOffice_org-icon-themes less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063761" comment="OpenOffice_org-impress-extensions less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063709" comment="OpenOffice_org-impress less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063710" comment="OpenOffice_org-kde less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063711" comment="OpenOffice_org-l10n-af less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063712" comment="OpenOffice_org-l10n-ar less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063713" comment="OpenOffice_org-l10n-ca less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063714" comment="OpenOffice_org-l10n-cs less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063715" comment="OpenOffice_org-l10n-da less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063716" comment="OpenOffice_org-l10n-de less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063718" comment="OpenOffice_org-l10n-en-GB less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063719" comment="OpenOffice_org-l10n-es less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063721" comment="OpenOffice_org-l10n-extras less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063722" comment="OpenOffice_org-l10n-fi less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063723" comment="OpenOffice_org-l10n-fr less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063762" comment="OpenOffice_org-l10n-gu-IN less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063763" comment="OpenOffice_org-l10n-hi-IN less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063724" comment="OpenOffice_org-l10n-hu less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063725" comment="OpenOffice_org-l10n-it less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063726" comment="OpenOffice_org-l10n-ja less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063764" comment="OpenOffice_org-l10n-ko less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063727" comment="OpenOffice_org-l10n-nb less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063728" comment="OpenOffice_org-l10n-nl less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063729" comment="OpenOffice_org-l10n-nn less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063730" comment="OpenOffice_org-l10n-pl less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063731" comment="OpenOffice_org-l10n-pt-BR less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063732" comment="OpenOffice_org-l10n-pt less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063733" comment="OpenOffice_org-l10n-ru less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063734" comment="OpenOffice_org-l10n-sk less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063735" comment="OpenOffice_org-l10n-sv less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063736" comment="OpenOffice_org-l10n-xh less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063737" comment="OpenOffice_org-l10n-zh-CN less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063738" comment="OpenOffice_org-l10n-zh-TW less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063739" comment="OpenOffice_org-l10n-zu less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063741" comment="OpenOffice_org-libs-core less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063743" comment="OpenOffice_org-libs-extern less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063745" comment="OpenOffice_org-libs-gui less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063746" comment="OpenOffice_org-mailmerge less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063747" comment="OpenOffice_org-math less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063748" comment="OpenOffice_org-mono less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063749" comment="OpenOffice_org-officebean less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063750" comment="OpenOffice_org-pyuno less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063753" comment="OpenOffice_org-ure less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063765" comment="OpenOffice_org-writer-extensions less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063755" comment="OpenOffice_org-writer less than 3.2.1.6-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063756" comment="OpenOffice_org less than 3.2.1.6-0.7.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102939" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2939</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2939" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2939" source="CVE"/>
	<description>
	Double free vulnerability in the ssl3_get_key_exchange function in the OpenSSL client (ssl/s3_clnt.c) in OpenSSL 1.0.0a, 0.9.8, 0.9.7, and possibly other versions, when using ECDH, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted private key with an invalid prime.  NOTE: some sources refer to this as a use-after-free issue.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- b2240bd1cc1b86d466bf4511cb5287fd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064298" comment="libopenssl0_9_8-32bit less than 0.9.8h-30.22.22.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064300" comment="libopenssl0_9_8 less than 0.9.8h-30.22.22.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064302" comment="openssl less than 0.9.8h-30.22.22.1"/>
		</criteria>
	</criteria>
	<!-- d4275070c6d35e2cd6ce91e877bc91e7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064303" comment="libopenssl0_9_8-32bit less than 0.9.8h-30.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064305" comment="libopenssl0_9_8 less than 0.9.8h-30.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064307" comment="openssl less than 0.9.8h-30.28.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102941" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2941</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2941" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2941" source="CVE"/>
	<description>
	ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted IPP request.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- d603aeff8a309d9d04651d4469e31973 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064776" comment="cups-client less than 1.3.9-8.37.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064777" comment="cups-libs-32bit less than 1.3.9-8.37.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064779" comment="cups-libs less than 1.3.9-8.37.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064780" comment="cups less than 1.3.9-8.37.1"/>
		</criteria>
	</criteria>
	<!-- e290f3059978b800480c09727b4b714a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064776" comment="cups-client less than 1.3.9-8.37.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064777" comment="cups-libs-32bit less than 1.3.9-8.37.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064779" comment="cups-libs less than 1.3.9-8.37.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064780" comment="cups less than 1.3.9-8.37.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102942" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2942</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2942" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2942" source="CVE"/>
	<description>
	The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump operations, which allows local users to obtain potentially sensitive information from kernel memory via vectors related to (1) the tcf_gact_dump function in net/sched/act_gact.c, (2) the tcf_mirred_dump function in net/sched/act_mirred.c, (3) the tcf_nat_dump function in net/sched/act_nat.c, (4) the tcf_simp_dump function in net/sched/act_simple.c, and (5) the tcf_skbedit_dump function in net/sched/act_skbedit.c.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 397f45e4eb102e91e10ebd86d7e1eb7b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063845" comment="kernel-pae-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063855" comment="kernel-pae-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063846" comment="kernel-pae less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063851" comment="kernel-xen-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063856" comment="kernel-xen-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063852" comment="kernel-xen less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- 70608756570f270952a30400f0f97a67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062623" comment="kernel-default-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062624" comment="kernel-desktop-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062625" comment="kernel-xen-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
	<!-- d69f430f61b72448377e859dd89a3663 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063851" comment="kernel-xen-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063856" comment="kernel-xen-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063852" comment="kernel-xen less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- e2f6c6cc02f7dc05554cab87c9f88650 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062408" comment="btrfs-kmp-pae less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062410" comment="hyper-v-kmp-pae less than 0_2.6.32.19_0.2-0.7.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062623" comment="kernel-default-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062624" comment="kernel-desktop-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062411" comment="kernel-pae-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062412" comment="kernel-pae-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062626" comment="kernel-pae-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062413" comment="kernel-pae less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062625" comment="kernel-xen-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102943" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2943</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2943" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2943" source="CVE"/>
	<description>
	The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read or overwrite disk blocks that are currently assigned to an active file but were previously assigned to an unlinked file, by accessing a stale NFS filehandle.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- abeba8d6c807360502c7dfc6ca6f2b4d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009065986" comment="btrfs-kmp-default less than 0_2.6.32.29_0.3-0.3.34"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066001" comment="btrfs-kmp-pae less than 0_2.6.32.29_0.3-0.3.34"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066002" comment="btrfs-kmp-xen less than 0_2.6.32.29_0.3-0.3.34"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066005" comment="hyper-v-kmp-default less than 0_2.6.32.29_0.3-0.10.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066006" comment="hyper-v-kmp-pae less than 0_2.6.32.29_0.3-0.10.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065988" comment="kernel-default-base less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065989" comment="kernel-default-devel less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066015" comment="kernel-default-extra less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065991" comment="kernel-default less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066016" comment="kernel-desktop-devel less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066009" comment="kernel-pae-base less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066010" comment="kernel-pae-devel less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066017" comment="kernel-pae-extra less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066011" comment="kernel-pae less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065992" comment="kernel-source less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065993" comment="kernel-syms less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066012" comment="kernel-xen-base less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066013" comment="kernel-xen-devel less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066018" comment="kernel-xen-extra less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066014" comment="kernel-xen less than 2.6.32.29-0.3.1"/>
		</criteria>
	</criteria>
	<!-- b296065a76246d5eb3b84a54249a6ab9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009065986" comment="btrfs-kmp-default less than 0_2.6.32.29_0.3-0.3.34"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066002" comment="btrfs-kmp-xen less than 0_2.6.32.29_0.3-0.3.34"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066005" comment="hyper-v-kmp-default less than 0_2.6.32.29_0.3-0.10.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065988" comment="kernel-default-base less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065989" comment="kernel-default-devel less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066015" comment="kernel-default-extra less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065991" comment="kernel-default less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066016" comment="kernel-desktop-devel less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065992" comment="kernel-source less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065993" comment="kernel-syms less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066012" comment="kernel-xen-base less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066013" comment="kernel-xen-devel less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066018" comment="kernel-xen-extra less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066014" comment="kernel-xen less than 2.6.32.29-0.3.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102946" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2946</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2946" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2946" source="CVE"/>
	<description>
	fs/jfs/xattr.c in the Linux kernel before 2.6.35.2 does not properly handle a certain legacy format for storage of extended attributes, which might allow local users by bypass intended xattr namespace restrictions via an "os2." substring at the beginning of a name.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 397f45e4eb102e91e10ebd86d7e1eb7b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063845" comment="kernel-pae-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063855" comment="kernel-pae-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063846" comment="kernel-pae less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063851" comment="kernel-xen-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063856" comment="kernel-xen-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063852" comment="kernel-xen less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- 70608756570f270952a30400f0f97a67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062623" comment="kernel-default-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062624" comment="kernel-desktop-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062625" comment="kernel-xen-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
	<!-- d69f430f61b72448377e859dd89a3663 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063851" comment="kernel-xen-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063856" comment="kernel-xen-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063852" comment="kernel-xen less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- e2f6c6cc02f7dc05554cab87c9f88650 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062408" comment="btrfs-kmp-pae less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062410" comment="hyper-v-kmp-pae less than 0_2.6.32.19_0.2-0.7.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062623" comment="kernel-default-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062624" comment="kernel-desktop-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062411" comment="kernel-pae-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062412" comment="kernel-pae-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062626" comment="kernel-pae-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062413" comment="kernel-pae less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062625" comment="kernel-xen-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102947" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2947</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2947" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2947" source="CVE"/>
	<description>
	Heap-based buffer overflow in the HX_split function in string.c in libHX before 3.6 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a string that is inconsistent with the expected number of fields.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 4e77557a3a7b0f2f19676adf628cafc7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063455" comment="libHX13-32bit less than 1.23-4.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063457" comment="libHX13 less than 1.23-4.1.1"/>
		</criteria>
	</criteria>
	<!-- cbb98a2d5ddca9caae96d5d63dee035f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063455" comment="libHX13-32bit less than 1.23-4.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063457" comment="libHX13 less than 1.23-4.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102954" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2954</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2954" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2954" source="CVE"/>
	<description>
	The irda_bind function in net/irda/af_irda.c in the Linux kernel before 2.6.36-rc3-next-20100901 does not properly handle failure of the irda_open_tsap function, which allows local users to cause a denial of service (NULL pointer dereference and panic) and possibly have unspecified other impact via multiple unsuccessful calls to bind on an AF_IRDA (aka PF_IRDA) socket.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 039ba32580d28580329514de944be593 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063425" comment="btrfs-kmp-default less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063426" comment="btrfs-kmp-xen less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063429" comment="hyper-v-kmp-default less than 0_2.6.32.23_0.3-0.7.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063430" comment="kernel-default-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063431" comment="kernel-default-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063451" comment="kernel-default-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063432" comment="kernel-default less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063452" comment="kernel-desktop-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063436" comment="kernel-source less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063437" comment="kernel-syms less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063441" comment="kernel-xen-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063442" comment="kernel-xen-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063453" comment="kernel-xen-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063443" comment="kernel-xen less than 2.6.32.23-0.3.1"/>
		</criteria>
	</criteria>
	<!-- 397f45e4eb102e91e10ebd86d7e1eb7b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063845" comment="kernel-pae-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063855" comment="kernel-pae-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063846" comment="kernel-pae less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063851" comment="kernel-xen-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063856" comment="kernel-xen-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063852" comment="kernel-xen less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- a412f327abfdfb030c31be1c37133055 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063425" comment="btrfs-kmp-default less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063445" comment="btrfs-kmp-pae less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063426" comment="btrfs-kmp-xen less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063429" comment="hyper-v-kmp-default less than 0_2.6.32.23_0.3-0.7.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063447" comment="hyper-v-kmp-pae less than 0_2.6.32.23_0.3-0.7.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063430" comment="kernel-default-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063431" comment="kernel-default-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063451" comment="kernel-default-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063432" comment="kernel-default less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063452" comment="kernel-desktop-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063448" comment="kernel-pae-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063449" comment="kernel-pae-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063454" comment="kernel-pae-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063450" comment="kernel-pae less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063436" comment="kernel-source less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063437" comment="kernel-syms less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063441" comment="kernel-xen-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063442" comment="kernel-xen-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063453" comment="kernel-xen-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063443" comment="kernel-xen less than 2.6.32.23-0.3.1"/>
		</criteria>
	</criteria>
	<!-- d69f430f61b72448377e859dd89a3663 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063851" comment="kernel-xen-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063856" comment="kernel-xen-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063852" comment="kernel-xen less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102955" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2955</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2955" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2955" source="CVE"/>
	<description>
	The cfg80211_wext_giwessid function in net/wireless/wext-compat.c in the Linux kernel before 2.6.36-rc3-next-20100831 does not properly initialize certain structure members, which allows local users to leverage an off-by-one error in the ioctl_standard_iw_point function in net/wireless/wext-core.c, and obtain potentially sensitive information from kernel heap memory, via vectors involving an SIOCGIWESSID ioctl call that specifies a large buffer size.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 397f45e4eb102e91e10ebd86d7e1eb7b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063845" comment="kernel-pae-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063855" comment="kernel-pae-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063846" comment="kernel-pae less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063851" comment="kernel-xen-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063856" comment="kernel-xen-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063852" comment="kernel-xen less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- 43635d2ef5db017de2e87f6c750727d5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062814" comment="btrfs-kmp-default less than 0_2.6.32.19_0.3-0.3.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062824" comment="btrfs-kmp-pae less than 0_2.6.32.19_0.3-0.3.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062825" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.3-0.3.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062828" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.3-0.7.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062829" comment="hyper-v-kmp-pae less than 0_2.6.32.19_0.3-0.7.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062816" comment="kernel-default-base less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062817" comment="kernel-default-devel less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063027" comment="kernel-default-extra less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062818" comment="kernel-default less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063028" comment="kernel-desktop-devel less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062830" comment="kernel-pae-base less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062831" comment="kernel-pae-devel less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063029" comment="kernel-pae-extra less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062832" comment="kernel-pae less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062819" comment="kernel-source less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062820" comment="kernel-syms less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062833" comment="kernel-xen-base less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062834" comment="kernel-xen-devel less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063030" comment="kernel-xen-extra less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062835" comment="kernel-xen less than 2.6.32.19-0.3.1"/>
		</criteria>
	</criteria>
	<!-- d69f430f61b72448377e859dd89a3663 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063851" comment="kernel-xen-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063856" comment="kernel-xen-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063852" comment="kernel-xen less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- e3a70946dce5e9e1b1288c5039b9d611 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062814" comment="btrfs-kmp-default less than 0_2.6.32.19_0.3-0.3.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062825" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.3-0.3.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062828" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.3-0.7.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062816" comment="kernel-default-base less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062817" comment="kernel-default-devel less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063027" comment="kernel-default-extra less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062818" comment="kernel-default less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063028" comment="kernel-desktop-devel less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062819" comment="kernel-source less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062820" comment="kernel-syms less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062833" comment="kernel-xen-base less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062834" comment="kernel-xen-devel less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063030" comment="kernel-xen-extra less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062835" comment="kernel-xen less than 2.6.32.19-0.3.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102959" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2959</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2959" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2959" source="CVE"/>
	<description>
	Integer overflow in net/can/bcm.c in the Controller Area Network (CAN) implementation in the Linux kernel before 2.6.27.53, 2.6.32.x before 2.6.32.21, 2.6.34.x before 2.6.34.6, and 2.6.35.x before 2.6.35.4 allows attackers to execute arbitrary code or cause a denial of service (system crash) via crafted CAN traffic.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 55039b9be6c6d4667182aa22f0adb117 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062844" comment="kernel-default-base less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062849" comment="kernel-default-extra less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062846" comment="kernel-default less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062858" comment="kernel-pae-base less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062864" comment="kernel-pae-extra less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062859" comment="kernel-pae less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062847" comment="kernel-source less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062848" comment="kernel-syms less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062862" comment="kernel-xen-base less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062865" comment="kernel-xen-extra less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062863" comment="kernel-xen less than 2.6.27.48-0.12.1"/>
		</criteria>
	</criteria>
	<!-- 70608756570f270952a30400f0f97a67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062623" comment="kernel-default-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062624" comment="kernel-desktop-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062625" comment="kernel-xen-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
	<!-- 909c914eb25a1f9ef2f32bb54309146e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062844" comment="kernel-default-base less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062849" comment="kernel-default-extra less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062846" comment="kernel-default less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062847" comment="kernel-source less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062848" comment="kernel-syms less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062862" comment="kernel-xen-base less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062865" comment="kernel-xen-extra less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062863" comment="kernel-xen less than 2.6.27.48-0.12.1"/>
		</criteria>
	</criteria>
	<!-- e2f6c6cc02f7dc05554cab87c9f88650 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062408" comment="btrfs-kmp-pae less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062410" comment="hyper-v-kmp-pae less than 0_2.6.32.19_0.2-0.7.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062623" comment="kernel-default-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062624" comment="kernel-desktop-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062411" comment="kernel-pae-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062412" comment="kernel-pae-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062626" comment="kernel-pae-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062413" comment="kernel-pae less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062625" comment="kernel-xen-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102960" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2960</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2960" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2960" source="CVE"/>
	<description>
	The keyctl_session_to_parent function in security/keys/keyctl.c in the Linux kernel 2.6.35.4 and earlier expects that a certain parent session keyring exists, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a KEYCTL_SESSION_TO_PARENT argument to the keyctl function.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 039ba32580d28580329514de944be593 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063425" comment="btrfs-kmp-default less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063426" comment="btrfs-kmp-xen less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063429" comment="hyper-v-kmp-default less than 0_2.6.32.23_0.3-0.7.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063430" comment="kernel-default-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063431" comment="kernel-default-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063451" comment="kernel-default-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063432" comment="kernel-default less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063452" comment="kernel-desktop-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063436" comment="kernel-source less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063437" comment="kernel-syms less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063441" comment="kernel-xen-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063442" comment="kernel-xen-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063453" comment="kernel-xen-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063443" comment="kernel-xen less than 2.6.32.23-0.3.1"/>
		</criteria>
	</criteria>
	<!-- a412f327abfdfb030c31be1c37133055 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063425" comment="btrfs-kmp-default less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063445" comment="btrfs-kmp-pae less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063426" comment="btrfs-kmp-xen less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063429" comment="hyper-v-kmp-default less than 0_2.6.32.23_0.3-0.7.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063447" comment="hyper-v-kmp-pae less than 0_2.6.32.23_0.3-0.7.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063430" comment="kernel-default-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063431" comment="kernel-default-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063451" comment="kernel-default-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063432" comment="kernel-default less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063452" comment="kernel-desktop-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063448" comment="kernel-pae-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063449" comment="kernel-pae-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063454" comment="kernel-pae-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063450" comment="kernel-pae less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063436" comment="kernel-source less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063437" comment="kernel-syms less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063441" comment="kernel-xen-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063442" comment="kernel-xen-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063453" comment="kernel-xen-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063443" comment="kernel-xen less than 2.6.32.23-0.3.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102962" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2962</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2962" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2962" source="CVE"/>
	<description>
	drivers/gpu/drm/i915/i915_gem.c in the Graphics Execution Manager (GEM) in the Intel i915 driver in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.36 does not properly validate pointers to blocks of memory, which allows local users to write to arbitrary kernel memory locations, and consequently gain privileges, via crafted use of the ioctl interface, related to (1) pwrite and (2) pread operations.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 039ba32580d28580329514de944be593 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063425" comment="btrfs-kmp-default less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063426" comment="btrfs-kmp-xen less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063429" comment="hyper-v-kmp-default less than 0_2.6.32.23_0.3-0.7.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063430" comment="kernel-default-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063431" comment="kernel-default-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063451" comment="kernel-default-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063432" comment="kernel-default less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063452" comment="kernel-desktop-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063436" comment="kernel-source less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063437" comment="kernel-syms less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063441" comment="kernel-xen-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063442" comment="kernel-xen-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063453" comment="kernel-xen-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063443" comment="kernel-xen less than 2.6.32.23-0.3.1"/>
		</criteria>
	</criteria>
	<!-- a412f327abfdfb030c31be1c37133055 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063425" comment="btrfs-kmp-default less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063445" comment="btrfs-kmp-pae less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063426" comment="btrfs-kmp-xen less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063429" comment="hyper-v-kmp-default less than 0_2.6.32.23_0.3-0.7.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063447" comment="hyper-v-kmp-pae less than 0_2.6.32.23_0.3-0.7.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063430" comment="kernel-default-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063431" comment="kernel-default-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063451" comment="kernel-default-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063432" comment="kernel-default less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063452" comment="kernel-desktop-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063448" comment="kernel-pae-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063449" comment="kernel-pae-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063454" comment="kernel-pae-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063450" comment="kernel-pae less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063436" comment="kernel-source less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063437" comment="kernel-syms less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063441" comment="kernel-xen-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063442" comment="kernel-xen-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063453" comment="kernel-xen-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063443" comment="kernel-xen less than 2.6.32.23-0.3.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102963" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2963</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2963" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2963" source="CVE"/>
	<description>
	drivers/media/video/v4l2-compat-ioctl32.c in the Video4Linux (V4L) implementation in the Linux kernel before 2.6.36 on 64-bit platforms does not validate the destination of a memory copy operation, which allows local users to write to arbitrary kernel memory locations, and consequently gain privileges, via a VIDIOCSTUNER ioctl call on a /dev/video device, followed by a VIDIOCSMICROCODE ioctl call on this device.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 4b53dedac262e9445a17875eb5c427c1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064260" comment="btrfs-kmp-default less than 0_2.6.32.24_0.2-0.3.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064261" comment="btrfs-kmp-pae less than 0_2.6.32.24_0.2-0.3.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064262" comment="btrfs-kmp-xen less than 0_2.6.32.24_0.2-0.3.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064266" comment="hyper-v-kmp-default less than 0_2.6.32.24_0.2-0.7.17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064267" comment="hyper-v-kmp-pae less than 0_2.6.32.24_0.2-0.7.17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064268" comment="kernel-default-base less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064269" comment="kernel-default-devel less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064294" comment="kernel-default-extra less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064270" comment="kernel-default less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064295" comment="kernel-desktop-devel less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064271" comment="kernel-pae-base less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064272" comment="kernel-pae-devel less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064296" comment="kernel-pae-extra less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064273" comment="kernel-pae less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064274" comment="kernel-source less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064275" comment="kernel-syms less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064279" comment="kernel-xen-base less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064280" comment="kernel-xen-devel less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064297" comment="kernel-xen-extra less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064281" comment="kernel-xen less than 2.6.32.24-0.2.1"/>
		</criteria>
	</criteria>
	<!-- f01275198337ab5cb5d84d49e735536a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064260" comment="btrfs-kmp-default less than 0_2.6.32.24_0.2-0.3.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064262" comment="btrfs-kmp-xen less than 0_2.6.32.24_0.2-0.3.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064266" comment="hyper-v-kmp-default less than 0_2.6.32.24_0.2-0.7.17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064268" comment="kernel-default-base less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064269" comment="kernel-default-devel less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064294" comment="kernel-default-extra less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064270" comment="kernel-default less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064295" comment="kernel-desktop-devel less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064274" comment="kernel-source less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064275" comment="kernel-syms less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064279" comment="kernel-xen-base less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064280" comment="kernel-xen-devel less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064297" comment="kernel-xen-extra less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064281" comment="kernel-xen less than 2.6.32.24-0.2.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102992" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2992</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2992" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2992" source="CVE"/>
	<description>
	packet-gsm_a_rr.c in the GSM A RR dissector in Wireshark 1.2.2 through 1.2.9 allows remote attackers to cause a denial of service (crash) via unknown vectors that trigger a NULL pointer dereference.
	</description>
 </metadata>
<!-- 6e5fc6e202651e8b93c830786b3ea82f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066948" comment="wireshark less than 1.4.4-0.2.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102993" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2993</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2993" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2993" source="CVE"/>
	<description>
	The IPMI dissector in Wireshark 1.2.0 through 1.2.9 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.
	</description>
 </metadata>
<!-- 6e5fc6e202651e8b93c830786b3ea82f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066948" comment="wireshark less than 1.4.4-0.2.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102994" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2994</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2994" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2994" source="CVE"/>
	<description>
	Stack-based buffer overflow in the ASN.1 BER dissector in Wireshark 0.10.13 through 1.0.14 and 1.2.0 through 1.2.9 has unknown impact and remote attack vectors.  NOTE: this issue exists because of a CVE-2010-2284 regression.
	</description>
 </metadata>
<!-- 6e5fc6e202651e8b93c830786b3ea82f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066948" comment="wireshark less than 1.4.4-0.2.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102995" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2995</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2995" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2995" source="CVE"/>
	<description>
	The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0.10.8 through 1.0.14 and 1.2.0 through 1.2.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to sigcomp-udvm.c and an off-by-one error, which triggers a buffer overflow, different vulnerabilities than CVE-2010-2287.
	</description>
 </metadata>
<!-- 6e5fc6e202651e8b93c830786b3ea82f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066948" comment="wireshark less than 1.4.4-0.2.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103015" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3015</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3015" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3015" source="CVE"/>
	<description>
	Integer overflow in the ext4_ext_get_blocks function in fs/ext4/extents.c in the Linux kernel before 2.6.34 allows local users to cause a denial of service (BUG and system crash) via a write operation on the last block of a large file, followed by a sync operation.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 397f45e4eb102e91e10ebd86d7e1eb7b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063845" comment="kernel-pae-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063855" comment="kernel-pae-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063846" comment="kernel-pae less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063851" comment="kernel-xen-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063856" comment="kernel-xen-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063852" comment="kernel-xen less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- 70608756570f270952a30400f0f97a67 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062623" comment="kernel-default-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062624" comment="kernel-desktop-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062625" comment="kernel-xen-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
	<!-- d69f430f61b72448377e859dd89a3663 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063851" comment="kernel-xen-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063856" comment="kernel-xen-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063852" comment="kernel-xen less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- e2f6c6cc02f7dc05554cab87c9f88650 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062408" comment="btrfs-kmp-pae less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062410" comment="hyper-v-kmp-pae less than 0_2.6.32.19_0.2-0.7.11"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062623" comment="kernel-default-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062624" comment="kernel-desktop-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062411" comment="kernel-pae-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062412" comment="kernel-pae-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062626" comment="kernel-pae-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062413" comment="kernel-pae less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062625" comment="kernel-xen-extra less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103053" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3053</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3053" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3053" source="CVE"/>
	<description>
	bdf/bdflib.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (application crash) via a crafted BDF font file, related to an attempted modification of a value in a static string.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 82d6887b2f70a5e8338a67da7664d81a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063351" comment="freetype2-32bit less than 2.3.7-25.17.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063378" comment="freetype2-devel less than 2.3.7-25.17.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063353" comment="freetype2 less than 2.3.7-25.17.1"/>
		</criteria>
	</criteria>
	<!-- f37351b8a4e423933441713b6c749951 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063351" comment="freetype2-32bit less than 2.3.7-25.17.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063378" comment="freetype2-devel less than 2.3.7-25.17.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063353" comment="freetype2 less than 2.3.7-25.17.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103054" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3054</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3054" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3054" source="CVE"/>
	<description>
	Unspecified vulnerability in FreeType 2.3.9, and other versions before 2.4.2, allows remote attackers to cause a denial of service via vectors involving nested Standard Encoding Accented Character (aka seac) calls, related to psaux.h, cffgload.c, cffgload.h, and t1decode.c.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 82d6887b2f70a5e8338a67da7664d81a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063351" comment="freetype2-32bit less than 2.3.7-25.17.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063378" comment="freetype2-devel less than 2.3.7-25.17.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063353" comment="freetype2 less than 2.3.7-25.17.1"/>
		</criteria>
	</criteria>
	<!-- f37351b8a4e423933441713b6c749951 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063351" comment="freetype2-32bit less than 2.3.7-25.17.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063378" comment="freetype2-devel less than 2.3.7-25.17.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063353" comment="freetype2 less than 2.3.7-25.17.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103069" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3069</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3069" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3069" source="CVE"/>
	<description>
	Stack-based buffer overflow in the (1) sid_parse and (2) dom_sid_parse functions in Samba before 3.5.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted Windows Security ID (SID) on a file share.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 15d682c7bffff64895dac834a3cb4e22 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062866" comment="cifs-mount less than 3.4.3-1.19.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062868" comment="libsmbclient0-32bit less than 3.4.3-1.19.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062870" comment="libsmbclient0 less than 3.4.3-1.19.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062871" comment="libtalloc1-32bit less than 3.4.3-1.19.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062873" comment="libtalloc1 less than 3.4.3-1.19.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062874" comment="libtdb1-32bit less than 3.4.3-1.19.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062876" comment="libtdb1 less than 3.4.3-1.19.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062877" comment="libwbclient0-32bit less than 3.4.3-1.19.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062879" comment="libwbclient0 less than 3.4.3-1.19.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062880" comment="samba-32bit less than 3.4.3-1.19.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062881" comment="samba-client-32bit less than 3.4.3-1.19.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062883" comment="samba-client less than 3.4.3-1.19.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062884" comment="samba-krb-printing less than 3.4.3-1.19.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062885" comment="samba-winbind-32bit less than 3.4.3-1.19.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062887" comment="samba-winbind less than 3.4.3-1.19.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062889" comment="samba less than 3.4.3-1.19.1"/>
		</criteria>
	</criteria>
	<!-- 415135a36635d0da8ff8c8589059c1b8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062890" comment="cifs-mount less than 3.2.7-11.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062892" comment="libsmbclient0-32bit less than 3.2.7-11.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062894" comment="libsmbclient0 less than 3.2.7-11.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062895" comment="libtalloc1-32bit less than 3.2.7-11.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062897" comment="libtalloc1 less than 3.2.7-11.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062898" comment="libtdb1-32bit less than 3.2.7-11.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062900" comment="libtdb1 less than 3.2.7-11.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062901" comment="libwbclient0-32bit less than 3.2.7-11.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062903" comment="libwbclient0 less than 3.2.7-11.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062904" comment="samba-32bit less than 3.2.7-11.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062905" comment="samba-client-32bit less than 3.2.7-11.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062907" comment="samba-client less than 3.2.7-11.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062908" comment="samba-krb-printing less than 3.2.7-11.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063087" comment="samba-vscan less than 0.3.6b-11.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062909" comment="samba-winbind-32bit less than 3.2.7-11.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062911" comment="samba-winbind less than 3.2.7-11.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062913" comment="samba less than 3.2.7-11.21.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103078" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3078</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3078" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3078" source="CVE"/>
	<description>
	The xfs_ioc_fsgetxattr function in fs/xfs/linux-2.6/xfs_ioctl.c in the Linux kernel before 2.6.36-rc4 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an ioctl call.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 039ba32580d28580329514de944be593 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063425" comment="btrfs-kmp-default less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063426" comment="btrfs-kmp-xen less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063429" comment="hyper-v-kmp-default less than 0_2.6.32.23_0.3-0.7.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063430" comment="kernel-default-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063431" comment="kernel-default-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063451" comment="kernel-default-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063432" comment="kernel-default less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063452" comment="kernel-desktop-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063436" comment="kernel-source less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063437" comment="kernel-syms less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063441" comment="kernel-xen-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063442" comment="kernel-xen-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063453" comment="kernel-xen-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063443" comment="kernel-xen less than 2.6.32.23-0.3.1"/>
		</criteria>
	</criteria>
	<!-- 397f45e4eb102e91e10ebd86d7e1eb7b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063845" comment="kernel-pae-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063855" comment="kernel-pae-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063846" comment="kernel-pae less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063851" comment="kernel-xen-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063856" comment="kernel-xen-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063852" comment="kernel-xen less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- a412f327abfdfb030c31be1c37133055 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063425" comment="btrfs-kmp-default less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063445" comment="btrfs-kmp-pae less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063426" comment="btrfs-kmp-xen less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063429" comment="hyper-v-kmp-default less than 0_2.6.32.23_0.3-0.7.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063447" comment="hyper-v-kmp-pae less than 0_2.6.32.23_0.3-0.7.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063430" comment="kernel-default-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063431" comment="kernel-default-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063451" comment="kernel-default-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063432" comment="kernel-default less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063452" comment="kernel-desktop-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063448" comment="kernel-pae-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063449" comment="kernel-pae-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063454" comment="kernel-pae-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063450" comment="kernel-pae less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063436" comment="kernel-source less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063437" comment="kernel-syms less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063441" comment="kernel-xen-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063442" comment="kernel-xen-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063453" comment="kernel-xen-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063443" comment="kernel-xen less than 2.6.32.23-0.3.1"/>
		</criteria>
	</criteria>
	<!-- d69f430f61b72448377e859dd89a3663 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063851" comment="kernel-xen-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063856" comment="kernel-xen-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063852" comment="kernel-xen less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103079" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3079</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3079" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3079" source="CVE"/>
	<description>
	kernel/trace/ftrace.c in the Linux kernel before 2.6.35.5, when debugfs is enabled, does not properly handle interaction between mutex possession and llseek operations, which allows local users to cause a denial of service (NULL pointer dereference and outage of all function tracing files) via an lseek call on a file descriptor associated with the set_ftrace_filter file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 039ba32580d28580329514de944be593 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063425" comment="btrfs-kmp-default less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063426" comment="btrfs-kmp-xen less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063429" comment="hyper-v-kmp-default less than 0_2.6.32.23_0.3-0.7.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063430" comment="kernel-default-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063431" comment="kernel-default-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063451" comment="kernel-default-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063432" comment="kernel-default less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063452" comment="kernel-desktop-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063436" comment="kernel-source less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063437" comment="kernel-syms less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063441" comment="kernel-xen-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063442" comment="kernel-xen-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063453" comment="kernel-xen-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063443" comment="kernel-xen less than 2.6.32.23-0.3.1"/>
		</criteria>
	</criteria>
	<!-- a412f327abfdfb030c31be1c37133055 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063425" comment="btrfs-kmp-default less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063445" comment="btrfs-kmp-pae less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063426" comment="btrfs-kmp-xen less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063429" comment="hyper-v-kmp-default less than 0_2.6.32.23_0.3-0.7.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063447" comment="hyper-v-kmp-pae less than 0_2.6.32.23_0.3-0.7.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063430" comment="kernel-default-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063431" comment="kernel-default-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063451" comment="kernel-default-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063432" comment="kernel-default less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063452" comment="kernel-desktop-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063448" comment="kernel-pae-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063449" comment="kernel-pae-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063454" comment="kernel-pae-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063450" comment="kernel-pae less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063436" comment="kernel-source less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063437" comment="kernel-syms less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063441" comment="kernel-xen-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063442" comment="kernel-xen-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063453" comment="kernel-xen-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063443" comment="kernel-xen less than 2.6.32.23-0.3.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103080" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3080</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3080" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3080" source="CVE"/>
	<description>
	Double free vulnerability in the snd_seq_oss_open function in sound/core/seq/oss/seq_oss_init.c in the Linux kernel before 2.6.36-rc4 might allow local users to cause a denial of service or possibly have unspecified other impact via an unsuccessful attempt to open the /dev/sequencer device.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 039ba32580d28580329514de944be593 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063425" comment="btrfs-kmp-default less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063426" comment="btrfs-kmp-xen less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063429" comment="hyper-v-kmp-default less than 0_2.6.32.23_0.3-0.7.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063430" comment="kernel-default-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063431" comment="kernel-default-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063451" comment="kernel-default-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063432" comment="kernel-default less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063452" comment="kernel-desktop-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063436" comment="kernel-source less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063437" comment="kernel-syms less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063441" comment="kernel-xen-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063442" comment="kernel-xen-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063453" comment="kernel-xen-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063443" comment="kernel-xen less than 2.6.32.23-0.3.1"/>
		</criteria>
	</criteria>
	<!-- 397f45e4eb102e91e10ebd86d7e1eb7b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063845" comment="kernel-pae-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063855" comment="kernel-pae-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063846" comment="kernel-pae less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063851" comment="kernel-xen-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063856" comment="kernel-xen-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063852" comment="kernel-xen less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- a412f327abfdfb030c31be1c37133055 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063425" comment="btrfs-kmp-default less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063445" comment="btrfs-kmp-pae less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063426" comment="btrfs-kmp-xen less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063429" comment="hyper-v-kmp-default less than 0_2.6.32.23_0.3-0.7.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063447" comment="hyper-v-kmp-pae less than 0_2.6.32.23_0.3-0.7.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063430" comment="kernel-default-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063431" comment="kernel-default-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063451" comment="kernel-default-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063432" comment="kernel-default less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063452" comment="kernel-desktop-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063448" comment="kernel-pae-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063449" comment="kernel-pae-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063454" comment="kernel-pae-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063450" comment="kernel-pae less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063436" comment="kernel-source less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063437" comment="kernel-syms less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063441" comment="kernel-xen-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063442" comment="kernel-xen-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063453" comment="kernel-xen-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063443" comment="kernel-xen less than 2.6.32.23-0.3.1"/>
		</criteria>
	</criteria>
	<!-- d69f430f61b72448377e859dd89a3663 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063851" comment="kernel-xen-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063856" comment="kernel-xen-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063852" comment="kernel-xen less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103081" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3081</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3081" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3081" source="CVE"/>
	<description>
	The compat_alloc_user_space functions in include/asm/compat.h files in the Linux kernel before 2.6.36-rc4-git2 on 64-bit platforms do not properly allocate the userspace memory required for the 32-bit compatibility layer, which allows local users to gain privileges by leveraging the ability of the compat_mc_getsockopt function (aka the MCAST_MSFILTER getsockopt support) to control a certain length value, related to a "stack pointer underflow" issue, as exploited in the wild in September 2010.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 039ba32580d28580329514de944be593 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063425" comment="btrfs-kmp-default less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063426" comment="btrfs-kmp-xen less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063429" comment="hyper-v-kmp-default less than 0_2.6.32.23_0.3-0.7.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063430" comment="kernel-default-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063431" comment="kernel-default-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063451" comment="kernel-default-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063432" comment="kernel-default less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063452" comment="kernel-desktop-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063436" comment="kernel-source less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063437" comment="kernel-syms less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063441" comment="kernel-xen-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063442" comment="kernel-xen-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063453" comment="kernel-xen-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063443" comment="kernel-xen less than 2.6.32.23-0.3.1"/>
		</criteria>
	</criteria>
	<!-- 43635d2ef5db017de2e87f6c750727d5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062814" comment="btrfs-kmp-default less than 0_2.6.32.19_0.3-0.3.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062824" comment="btrfs-kmp-pae less than 0_2.6.32.19_0.3-0.3.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062825" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.3-0.3.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062828" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.3-0.7.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062829" comment="hyper-v-kmp-pae less than 0_2.6.32.19_0.3-0.7.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062816" comment="kernel-default-base less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062817" comment="kernel-default-devel less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063027" comment="kernel-default-extra less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062818" comment="kernel-default less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063028" comment="kernel-desktop-devel less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062830" comment="kernel-pae-base less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062831" comment="kernel-pae-devel less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063029" comment="kernel-pae-extra less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062832" comment="kernel-pae less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062819" comment="kernel-source less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062820" comment="kernel-syms less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062833" comment="kernel-xen-base less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062834" comment="kernel-xen-devel less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063030" comment="kernel-xen-extra less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062835" comment="kernel-xen less than 2.6.32.19-0.3.1"/>
		</criteria>
	</criteria>
	<!-- 55039b9be6c6d4667182aa22f0adb117 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062844" comment="kernel-default-base less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062849" comment="kernel-default-extra less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062846" comment="kernel-default less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062858" comment="kernel-pae-base less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062864" comment="kernel-pae-extra less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062859" comment="kernel-pae less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062847" comment="kernel-source less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062848" comment="kernel-syms less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062862" comment="kernel-xen-base less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062865" comment="kernel-xen-extra less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062863" comment="kernel-xen less than 2.6.27.48-0.12.1"/>
		</criteria>
	</criteria>
	<!-- 909c914eb25a1f9ef2f32bb54309146e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062844" comment="kernel-default-base less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062849" comment="kernel-default-extra less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062846" comment="kernel-default less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062847" comment="kernel-source less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062848" comment="kernel-syms less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062862" comment="kernel-xen-base less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062865" comment="kernel-xen-extra less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062863" comment="kernel-xen less than 2.6.27.48-0.12.1"/>
		</criteria>
	</criteria>
	<!-- a412f327abfdfb030c31be1c37133055 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063425" comment="btrfs-kmp-default less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063445" comment="btrfs-kmp-pae less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063426" comment="btrfs-kmp-xen less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063429" comment="hyper-v-kmp-default less than 0_2.6.32.23_0.3-0.7.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063447" comment="hyper-v-kmp-pae less than 0_2.6.32.23_0.3-0.7.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063430" comment="kernel-default-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063431" comment="kernel-default-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063451" comment="kernel-default-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063432" comment="kernel-default less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063452" comment="kernel-desktop-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063448" comment="kernel-pae-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063449" comment="kernel-pae-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063454" comment="kernel-pae-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063450" comment="kernel-pae less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063436" comment="kernel-source less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063437" comment="kernel-syms less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063441" comment="kernel-xen-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063442" comment="kernel-xen-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063453" comment="kernel-xen-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063443" comment="kernel-xen less than 2.6.32.23-0.3.1"/>
		</criteria>
	</criteria>
	<!-- e3a70946dce5e9e1b1288c5039b9d611 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062814" comment="btrfs-kmp-default less than 0_2.6.32.19_0.3-0.3.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062825" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.3-0.3.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062828" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.3-0.7.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062816" comment="kernel-default-base less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062817" comment="kernel-default-devel less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063027" comment="kernel-default-extra less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062818" comment="kernel-default less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063028" comment="kernel-desktop-devel less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062819" comment="kernel-source less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062820" comment="kernel-syms less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062833" comment="kernel-xen-base less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062834" comment="kernel-xen-devel less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063030" comment="kernel-xen-extra less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062835" comment="kernel-xen less than 2.6.32.19-0.3.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103084" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3084</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3084" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3084" source="CVE"/>
	<description>
	Buffer overflow in the niu_get_ethtool_tcam_all function in drivers/net/niu.c in the Linux kernel before 2.6.36-rc4 allows local users to cause a denial of service or possibly have unspecified other impact via the ETHTOOL_GRXCLSRLALL ethtool command.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 43635d2ef5db017de2e87f6c750727d5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062814" comment="btrfs-kmp-default less than 0_2.6.32.19_0.3-0.3.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062824" comment="btrfs-kmp-pae less than 0_2.6.32.19_0.3-0.3.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062825" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.3-0.3.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062828" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.3-0.7.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062829" comment="hyper-v-kmp-pae less than 0_2.6.32.19_0.3-0.7.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062816" comment="kernel-default-base less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062817" comment="kernel-default-devel less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063027" comment="kernel-default-extra less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062818" comment="kernel-default less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063028" comment="kernel-desktop-devel less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062830" comment="kernel-pae-base less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062831" comment="kernel-pae-devel less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063029" comment="kernel-pae-extra less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062832" comment="kernel-pae less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062819" comment="kernel-source less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062820" comment="kernel-syms less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062833" comment="kernel-xen-base less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062834" comment="kernel-xen-devel less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063030" comment="kernel-xen-extra less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062835" comment="kernel-xen less than 2.6.32.19-0.3.1"/>
		</criteria>
	</criteria>
	<!-- e3a70946dce5e9e1b1288c5039b9d611 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062814" comment="btrfs-kmp-default less than 0_2.6.32.19_0.3-0.3.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062825" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.3-0.3.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062828" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.3-0.7.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062816" comment="kernel-default-base less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062817" comment="kernel-default-devel less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063027" comment="kernel-default-extra less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062818" comment="kernel-default less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063028" comment="kernel-desktop-devel less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062819" comment="kernel-source less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062820" comment="kernel-syms less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062833" comment="kernel-xen-base less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062834" comment="kernel-xen-devel less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063030" comment="kernel-xen-extra less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062835" comment="kernel-xen less than 2.6.32.19-0.3.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103110" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3110</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3110" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3110" source="CVE"/>
	<description>
	Multiple buffer overflows in the Novell Client novfs module for the Linux kernel in SUSE Linux Enterprise 11 SP1 and openSUSE 11.3 allow local users to gain privileges via unspecified vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 01f44594f9d8615a4c725ad4472abb2b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061868" comment="btrfs-kmp-default less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061869" comment="btrfs-kmp-xen less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061872" comment="hyper-v-kmp-default less than 0_2.6.32.13_0.5-0.7.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061873" comment="kernel-default-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061874" comment="kernel-default-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061945" comment="kernel-default-extra less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061875" comment="kernel-default less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061946" comment="kernel-desktop-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061876" comment="kernel-source less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061877" comment="kernel-syms less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061881" comment="kernel-xen-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061882" comment="kernel-xen-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061947" comment="kernel-xen-extra less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061883" comment="kernel-xen less than 2.6.32.13-0.5.1"/>
		</criteria>
	</criteria>
	<!-- caf966715fc66f993dd8892aa75742ad -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061868" comment="btrfs-kmp-default less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061889" comment="btrfs-kmp-pae less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061869" comment="btrfs-kmp-xen less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061872" comment="hyper-v-kmp-default less than 0_2.6.32.13_0.5-0.7.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061891" comment="hyper-v-kmp-pae less than 0_2.6.32.13_0.5-0.7.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061873" comment="kernel-default-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061874" comment="kernel-default-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061945" comment="kernel-default-extra less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061875" comment="kernel-default less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061946" comment="kernel-desktop-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061892" comment="kernel-pae-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061893" comment="kernel-pae-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061948" comment="kernel-pae-extra less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061894" comment="kernel-pae less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061876" comment="kernel-source less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061877" comment="kernel-syms less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061881" comment="kernel-xen-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061882" comment="kernel-xen-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061947" comment="kernel-xen-extra less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061883" comment="kernel-xen less than 2.6.32.13-0.5.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103131" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3131</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3131" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3131" source="CVE"/>
	<description>
	Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 on Windows XP allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .htm, .html, .jtx, .mfp, or .eml file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 090848ec46b4dd478bc9cd3ba9442531 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063420" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063422" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 0c29d728f4fd029a2fbf4ea1e669fc81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
	<!-- 50a3e55a414b85ba53fc6385752379a7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063420" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063422" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 8f1a8feab628d727a6016f2016a02361 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103166" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3166</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3166" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3166" source="CVE"/>
	<description>
	Heap-based buffer overflow in the nsTextFrameUtils::TransformText function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 might allow remote attackers to execute arbitrary code via a bidirectional text run.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 090848ec46b4dd478bc9cd3ba9442531 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063420" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063422" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 0c29d728f4fd029a2fbf4ea1e669fc81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
	<!-- 50a3e55a414b85ba53fc6385752379a7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063420" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063422" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 8f1a8feab628d727a6016f2016a02361 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103167" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3167</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3167" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3167" source="CVE"/>
	<description>
	The nsTreeContentView function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle node removal in XUL trees, which allows remote attackers to execute arbitrary code via vectors involving access to deleted memory, related to a "dangling pointer vulnerability."
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 090848ec46b4dd478bc9cd3ba9442531 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063420" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063422" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 0c29d728f4fd029a2fbf4ea1e669fc81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
	<!-- 50a3e55a414b85ba53fc6385752379a7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063420" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063422" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 8f1a8feab628d727a6016f2016a02361 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103168" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3168</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3168" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3168" source="CVE"/>
	<description>
	Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 do not properly restrict the role of property changes in triggering XUL tree removal, which allows remote attackers to cause a denial of service (deleted memory access and application crash) or possibly execute arbitrary code by setting unspecified properties.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 090848ec46b4dd478bc9cd3ba9442531 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063420" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063422" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 0c29d728f4fd029a2fbf4ea1e669fc81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
	<!-- 50a3e55a414b85ba53fc6385752379a7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063420" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063422" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 8f1a8feab628d727a6016f2016a02361 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103169" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3169</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3169" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3169" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 090848ec46b4dd478bc9cd3ba9442531 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063420" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063422" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 0c29d728f4fd029a2fbf4ea1e669fc81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
	<!-- 50a3e55a414b85ba53fc6385752379a7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063420" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063422" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 8f1a8feab628d727a6016f2016a02361 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103170" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3170</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3170" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3170" source="CVE"/>
	<description>
	Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 recognize a wildcard IP address in the subject's Common Name field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0c29d728f4fd029a2fbf4ea1e669fc81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
	<!-- 116103bfe49b8e2bfd349aa9f816fab5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064215" comment="MozillaFirefox-translations less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064216" comment="MozillaFirefox less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064217" comment="mozilla-xulrunner192-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064239" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064218" comment="mozilla-xulrunner192-gnome less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064241" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064219" comment="mozilla-xulrunner192-translations less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064221" comment="mozilla-xulrunner192 less than 1.9.2.12-0.6.1"/>
		</criteria>
	</criteria>
	<!-- 39fc917e274c1fa69f30c295d10c49cc -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064190" comment="mozilla-xulrunner191-32bit less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064191" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064192" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064193" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064194" comment="mozilla-xulrunner191-translations less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064195" comment="mozilla-xulrunner191 less than 1.9.1.15-0.5.1"/>
		</criteria>
	</criteria>
	<!-- 4c17d9a6d1b2e9ae1edf389f45b41877 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064222" comment="libfreebl3-32bit less than 3.12.8-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064224" comment="libfreebl3 less than 3.12.8-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064225" comment="mozilla-nspr-32bit less than 4.8.6-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064227" comment="mozilla-nspr less than 4.8.6-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064228" comment="mozilla-nss-32bit less than 3.12.8-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064229" comment="mozilla-nss-tools less than 3.12.8-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064231" comment="mozilla-nss less than 3.12.8-1.2.1"/>
		</criteria>
	</criteria>
	<!-- 678a93e0b782752078c6f33a225f1398 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064215" comment="MozillaFirefox-translations less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064216" comment="MozillaFirefox less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064217" comment="mozilla-xulrunner192-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064239" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064218" comment="mozilla-xulrunner192-gnome less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064241" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064219" comment="mozilla-xulrunner192-translations less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064221" comment="mozilla-xulrunner192 less than 1.9.2.12-0.6.1"/>
		</criteria>
	</criteria>
	<!-- 8f1a8feab628d727a6016f2016a02361 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
	<!-- c25352f45f1758916e7f8547202e8737 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064222" comment="libfreebl3-32bit less than 3.12.8-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064224" comment="libfreebl3 less than 3.12.8-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064225" comment="mozilla-nspr-32bit less than 4.8.6-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064227" comment="mozilla-nspr less than 4.8.6-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064228" comment="mozilla-nss-32bit less than 3.12.8-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064229" comment="mozilla-nss-tools less than 3.12.8-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064231" comment="mozilla-nss less than 3.12.8-1.2.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103172" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3172</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3172" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3172" source="CVE"/>
	<description>
	CRLF injection vulnerability in Bugzilla before 3.2.9, 3.4.x before 3.4.9, 3.6.x before 3.6.3, and 4.0.x before 4.0rc1, when Server Push is enabled in a web browser, allows remote attackers to inject arbitrary HTTP headers and content, and conduct HTTP response splitting attacks, via a crafted URL.
	</description>
 </metadata>
<!-- 31907ff5cbd65bb3539b83632a7125a2 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009065589" comment="perl-32bit less than 5.10.0-64.53.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009065590" comment="perl-base less than 5.10.0-64.53.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009065591" comment="perl-doc less than 5.10.0-64.53.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009065593" comment="perl less than 5.10.0-64.53.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103173" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3173</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3173" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3173" source="CVE"/>
	<description>
	The SSL implementation in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 does not properly set the minimum key length for Diffie-Hellman Ephemeral (DHE) mode, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack.
	</description>
 </metadata>
<!-- 4c17d9a6d1b2e9ae1edf389f45b41877 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009064222" comment="libfreebl3-32bit less than 3.12.8-1.2.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009064224" comment="libfreebl3 less than 3.12.8-1.2.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009064225" comment="mozilla-nspr-32bit less than 4.8.6-1.2.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009064227" comment="mozilla-nspr less than 4.8.6-1.2.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009064228" comment="mozilla-nss-32bit less than 3.12.8-1.2.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009064229" comment="mozilla-nss-tools less than 3.12.8-1.2.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009064231" comment="mozilla-nss less than 3.12.8-1.2.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103174" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3174</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3174" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3174" source="CVE"/>
	<description>
	Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.14, Thunderbird before 3.0.9, and SeaMonkey before 2.0.9 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0c29d728f4fd029a2fbf4ea1e669fc81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
	<!-- 116103bfe49b8e2bfd349aa9f816fab5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064215" comment="MozillaFirefox-translations less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064216" comment="MozillaFirefox less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064217" comment="mozilla-xulrunner192-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064239" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064218" comment="mozilla-xulrunner192-gnome less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064241" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064219" comment="mozilla-xulrunner192-translations less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064221" comment="mozilla-xulrunner192 less than 1.9.2.12-0.6.1"/>
		</criteria>
	</criteria>
	<!-- 678a93e0b782752078c6f33a225f1398 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064215" comment="MozillaFirefox-translations less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064216" comment="MozillaFirefox less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064217" comment="mozilla-xulrunner192-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064239" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064218" comment="mozilla-xulrunner192-gnome less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064241" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064219" comment="mozilla-xulrunner192-translations less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064221" comment="mozilla-xulrunner192 less than 1.9.2.12-0.6.1"/>
		</criteria>
	</criteria>
	<!-- 8f1a8feab628d727a6016f2016a02361 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103175" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3175</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3175" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3175" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.6.x before 3.6.11 and Thunderbird 3.1.x before 3.1.5 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0c29d728f4fd029a2fbf4ea1e669fc81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
	<!-- 116103bfe49b8e2bfd349aa9f816fab5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064215" comment="MozillaFirefox-translations less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064216" comment="MozillaFirefox less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064217" comment="mozilla-xulrunner192-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064239" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064218" comment="mozilla-xulrunner192-gnome less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064241" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064219" comment="mozilla-xulrunner192-translations less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064221" comment="mozilla-xulrunner192 less than 1.9.2.12-0.6.1"/>
		</criteria>
	</criteria>
	<!-- 39fc917e274c1fa69f30c295d10c49cc -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064190" comment="mozilla-xulrunner191-32bit less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064191" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064192" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064193" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064194" comment="mozilla-xulrunner191-translations less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064195" comment="mozilla-xulrunner191 less than 1.9.1.15-0.5.1"/>
		</criteria>
	</criteria>
	<!-- 678a93e0b782752078c6f33a225f1398 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064215" comment="MozillaFirefox-translations less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064216" comment="MozillaFirefox less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064217" comment="mozilla-xulrunner192-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064239" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064218" comment="mozilla-xulrunner192-gnome less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064241" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064219" comment="mozilla-xulrunner192-translations less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064221" comment="mozilla-xulrunner192 less than 1.9.2.12-0.6.1"/>
		</criteria>
	</criteria>
	<!-- 8f1a8feab628d727a6016f2016a02361 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103176" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3176</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3176" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3176" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0c29d728f4fd029a2fbf4ea1e669fc81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
	<!-- 116103bfe49b8e2bfd349aa9f816fab5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064215" comment="MozillaFirefox-translations less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064216" comment="MozillaFirefox less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064217" comment="mozilla-xulrunner192-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064239" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064218" comment="mozilla-xulrunner192-gnome less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064241" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064219" comment="mozilla-xulrunner192-translations less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064221" comment="mozilla-xulrunner192 less than 1.9.2.12-0.6.1"/>
		</criteria>
	</criteria>
	<!-- 39fc917e274c1fa69f30c295d10c49cc -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064190" comment="mozilla-xulrunner191-32bit less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064191" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064192" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064193" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064194" comment="mozilla-xulrunner191-translations less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064195" comment="mozilla-xulrunner191 less than 1.9.1.15-0.5.1"/>
		</criteria>
	</criteria>
	<!-- 678a93e0b782752078c6f33a225f1398 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064215" comment="MozillaFirefox-translations less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064216" comment="MozillaFirefox less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064217" comment="mozilla-xulrunner192-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064239" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064218" comment="mozilla-xulrunner192-gnome less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064241" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064219" comment="mozilla-xulrunner192-translations less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064221" comment="mozilla-xulrunner192 less than 1.9.2.12-0.6.1"/>
		</criteria>
	</criteria>
	<!-- 8f1a8feab628d727a6016f2016a02361 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103177" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3177</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3177" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3177" source="CVE"/>
	<description>
	Multiple cross-site scripting (XSS) vulnerabilities in the Gopher parser in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, and SeaMonkey before 2.0.9, allow remote attackers to inject arbitrary web script or HTML via a crafted name of a (1) file or (2) directory on a Gopher server.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0c29d728f4fd029a2fbf4ea1e669fc81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
	<!-- 116103bfe49b8e2bfd349aa9f816fab5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064215" comment="MozillaFirefox-translations less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064216" comment="MozillaFirefox less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064217" comment="mozilla-xulrunner192-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064239" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064218" comment="mozilla-xulrunner192-gnome less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064241" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064219" comment="mozilla-xulrunner192-translations less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064221" comment="mozilla-xulrunner192 less than 1.9.2.12-0.6.1"/>
		</criteria>
	</criteria>
	<!-- 39fc917e274c1fa69f30c295d10c49cc -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064190" comment="mozilla-xulrunner191-32bit less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064191" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064192" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064193" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064194" comment="mozilla-xulrunner191-translations less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064195" comment="mozilla-xulrunner191 less than 1.9.1.15-0.5.1"/>
		</criteria>
	</criteria>
	<!-- 678a93e0b782752078c6f33a225f1398 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064215" comment="MozillaFirefox-translations less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064216" comment="MozillaFirefox less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064217" comment="mozilla-xulrunner192-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064239" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064218" comment="mozilla-xulrunner192-gnome less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064241" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064219" comment="mozilla-xulrunner192-translations less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064221" comment="mozilla-xulrunner192 less than 1.9.2.12-0.6.1"/>
		</criteria>
	</criteria>
	<!-- 8f1a8feab628d727a6016f2016a02361 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103178" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3178</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3178" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3178" source="CVE"/>
	<description>
	Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 do not properly handle certain modal calls made by javascript: URLs in circumstances related to opening a new window and performing cross-domain navigation, which allows remote attackers to bypass the Same Origin Policy via a crafted HTML document.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0c29d728f4fd029a2fbf4ea1e669fc81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
	<!-- 116103bfe49b8e2bfd349aa9f816fab5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064215" comment="MozillaFirefox-translations less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064216" comment="MozillaFirefox less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064217" comment="mozilla-xulrunner192-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064239" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064218" comment="mozilla-xulrunner192-gnome less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064241" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064219" comment="mozilla-xulrunner192-translations less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064221" comment="mozilla-xulrunner192 less than 1.9.2.12-0.6.1"/>
		</criteria>
	</criteria>
	<!-- 39fc917e274c1fa69f30c295d10c49cc -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064190" comment="mozilla-xulrunner191-32bit less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064191" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064192" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064193" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064194" comment="mozilla-xulrunner191-translations less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064195" comment="mozilla-xulrunner191 less than 1.9.1.15-0.5.1"/>
		</criteria>
	</criteria>
	<!-- 678a93e0b782752078c6f33a225f1398 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064215" comment="MozillaFirefox-translations less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064216" comment="MozillaFirefox less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064217" comment="mozilla-xulrunner192-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064239" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064218" comment="mozilla-xulrunner192-gnome less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064241" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064219" comment="mozilla-xulrunner192-translations less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064221" comment="mozilla-xulrunner192 less than 1.9.2.12-0.6.1"/>
		</criteria>
	</criteria>
	<!-- 8f1a8feab628d727a6016f2016a02361 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103179" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3179</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3179" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3179" source="CVE"/>
	<description>
	Stack-based buffer overflow in the text-rendering functionality in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a long argument to the document.write method.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0c29d728f4fd029a2fbf4ea1e669fc81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
	<!-- 116103bfe49b8e2bfd349aa9f816fab5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064215" comment="MozillaFirefox-translations less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064216" comment="MozillaFirefox less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064217" comment="mozilla-xulrunner192-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064239" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064218" comment="mozilla-xulrunner192-gnome less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064241" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064219" comment="mozilla-xulrunner192-translations less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064221" comment="mozilla-xulrunner192 less than 1.9.2.12-0.6.1"/>
		</criteria>
	</criteria>
	<!-- 39fc917e274c1fa69f30c295d10c49cc -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064190" comment="mozilla-xulrunner191-32bit less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064191" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064192" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064193" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064194" comment="mozilla-xulrunner191-translations less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064195" comment="mozilla-xulrunner191 less than 1.9.1.15-0.5.1"/>
		</criteria>
	</criteria>
	<!-- 678a93e0b782752078c6f33a225f1398 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064215" comment="MozillaFirefox-translations less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064216" comment="MozillaFirefox less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064217" comment="mozilla-xulrunner192-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064239" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064218" comment="mozilla-xulrunner192-gnome less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064241" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064219" comment="mozilla-xulrunner192-translations less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064221" comment="mozilla-xulrunner192 less than 1.9.2.12-0.6.1"/>
		</criteria>
	</criteria>
	<!-- 8f1a8feab628d727a6016f2016a02361 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103180" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3180</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3180" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3180" source="CVE"/>
	<description>
	Use-after-free vulnerability in the nsBarProp function in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 allows remote attackers to execute arbitrary code by accessing the locationbar property of a closed window.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0c29d728f4fd029a2fbf4ea1e669fc81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
	<!-- 116103bfe49b8e2bfd349aa9f816fab5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064215" comment="MozillaFirefox-translations less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064216" comment="MozillaFirefox less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064217" comment="mozilla-xulrunner192-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064239" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064218" comment="mozilla-xulrunner192-gnome less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064241" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064219" comment="mozilla-xulrunner192-translations less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064221" comment="mozilla-xulrunner192 less than 1.9.2.12-0.6.1"/>
		</criteria>
	</criteria>
	<!-- 39fc917e274c1fa69f30c295d10c49cc -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064190" comment="mozilla-xulrunner191-32bit less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064191" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064192" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064193" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064194" comment="mozilla-xulrunner191-translations less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064195" comment="mozilla-xulrunner191 less than 1.9.1.15-0.5.1"/>
		</criteria>
	</criteria>
	<!-- 678a93e0b782752078c6f33a225f1398 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064215" comment="MozillaFirefox-translations less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064216" comment="MozillaFirefox less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064217" comment="mozilla-xulrunner192-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064239" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064218" comment="mozilla-xulrunner192-gnome less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064241" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064219" comment="mozilla-xulrunner192-translations less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064221" comment="mozilla-xulrunner192 less than 1.9.2.12-0.6.1"/>
		</criteria>
	</criteria>
	<!-- 8f1a8feab628d727a6016f2016a02361 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103182" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3182</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3182" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3182" source="CVE"/>
	<description>
	A certain application-launch script in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 on Linux places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0c29d728f4fd029a2fbf4ea1e669fc81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
	<!-- 116103bfe49b8e2bfd349aa9f816fab5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064215" comment="MozillaFirefox-translations less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064216" comment="MozillaFirefox less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064217" comment="mozilla-xulrunner192-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064239" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064218" comment="mozilla-xulrunner192-gnome less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064241" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064219" comment="mozilla-xulrunner192-translations less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064221" comment="mozilla-xulrunner192 less than 1.9.2.12-0.6.1"/>
		</criteria>
	</criteria>
	<!-- 39fc917e274c1fa69f30c295d10c49cc -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064190" comment="mozilla-xulrunner191-32bit less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064191" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064192" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064193" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064194" comment="mozilla-xulrunner191-translations less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064195" comment="mozilla-xulrunner191 less than 1.9.1.15-0.5.1"/>
		</criteria>
	</criteria>
	<!-- 678a93e0b782752078c6f33a225f1398 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064215" comment="MozillaFirefox-translations less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064216" comment="MozillaFirefox less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064217" comment="mozilla-xulrunner192-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064239" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064218" comment="mozilla-xulrunner192-gnome less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064241" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064219" comment="mozilla-xulrunner192-translations less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064221" comment="mozilla-xulrunner192 less than 1.9.2.12-0.6.1"/>
		</criteria>
	</criteria>
	<!-- 8f1a8feab628d727a6016f2016a02361 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103183" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3183</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3183" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3183" source="CVE"/>
	<description>
	The LookupGetterOrSetter function in js3250.dll in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 does not properly support window.__lookupGetter__ function calls that lack arguments, which allows remote attackers to execute arbitrary code or cause a denial of service (incorrect pointer dereference and application crash) via vectors involving a "dangling pointer" and the JS_ValueToId function.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0c29d728f4fd029a2fbf4ea1e669fc81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
	<!-- 116103bfe49b8e2bfd349aa9f816fab5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064215" comment="MozillaFirefox-translations less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064216" comment="MozillaFirefox less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064217" comment="mozilla-xulrunner192-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064239" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064218" comment="mozilla-xulrunner192-gnome less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064241" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064219" comment="mozilla-xulrunner192-translations less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064221" comment="mozilla-xulrunner192 less than 1.9.2.12-0.6.1"/>
		</criteria>
	</criteria>
	<!-- 39fc917e274c1fa69f30c295d10c49cc -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064190" comment="mozilla-xulrunner191-32bit less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064191" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064192" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064193" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064194" comment="mozilla-xulrunner191-translations less than 1.9.1.15-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064195" comment="mozilla-xulrunner191 less than 1.9.1.15-0.5.1"/>
		</criteria>
	</criteria>
	<!-- 678a93e0b782752078c6f33a225f1398 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064215" comment="MozillaFirefox-translations less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064216" comment="MozillaFirefox less than 3.6.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064217" comment="mozilla-xulrunner192-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064239" comment="mozilla-xulrunner192-gnome-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064218" comment="mozilla-xulrunner192-gnome less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064241" comment="mozilla-xulrunner192-translations-32bit less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064219" comment="mozilla-xulrunner192-translations less than 1.9.2.12-0.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064221" comment="mozilla-xulrunner192 less than 1.9.2.12-0.6.1"/>
		</criteria>
	</criteria>
	<!-- 8f1a8feab628d727a6016f2016a02361 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064234" comment="mozilla-xulrunner191-gnomevfs-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064236" comment="mozilla-xulrunner191-translations-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103296" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3296</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3296" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3296" source="CVE"/>
	<description>
	The cxgb_extension_ioctl function in drivers/net/cxgb3/cxgb3_main.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a CHELSIO_GET_QSET_NUM ioctl call.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 039ba32580d28580329514de944be593 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063425" comment="btrfs-kmp-default less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063426" comment="btrfs-kmp-xen less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063429" comment="hyper-v-kmp-default less than 0_2.6.32.23_0.3-0.7.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063430" comment="kernel-default-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063431" comment="kernel-default-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063451" comment="kernel-default-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063432" comment="kernel-default less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063452" comment="kernel-desktop-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063436" comment="kernel-source less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063437" comment="kernel-syms less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063441" comment="kernel-xen-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063442" comment="kernel-xen-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063453" comment="kernel-xen-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063443" comment="kernel-xen less than 2.6.32.23-0.3.1"/>
		</criteria>
	</criteria>
	<!-- 397f45e4eb102e91e10ebd86d7e1eb7b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063845" comment="kernel-pae-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063855" comment="kernel-pae-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063846" comment="kernel-pae less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063851" comment="kernel-xen-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063856" comment="kernel-xen-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063852" comment="kernel-xen less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- a412f327abfdfb030c31be1c37133055 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063425" comment="btrfs-kmp-default less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063445" comment="btrfs-kmp-pae less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063426" comment="btrfs-kmp-xen less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063429" comment="hyper-v-kmp-default less than 0_2.6.32.23_0.3-0.7.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063447" comment="hyper-v-kmp-pae less than 0_2.6.32.23_0.3-0.7.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063430" comment="kernel-default-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063431" comment="kernel-default-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063451" comment="kernel-default-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063432" comment="kernel-default less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063452" comment="kernel-desktop-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063448" comment="kernel-pae-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063449" comment="kernel-pae-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063454" comment="kernel-pae-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063450" comment="kernel-pae less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063436" comment="kernel-source less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063437" comment="kernel-syms less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063441" comment="kernel-xen-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063442" comment="kernel-xen-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063453" comment="kernel-xen-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063443" comment="kernel-xen less than 2.6.32.23-0.3.1"/>
		</criteria>
	</criteria>
	<!-- d69f430f61b72448377e859dd89a3663 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063851" comment="kernel-xen-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063856" comment="kernel-xen-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063852" comment="kernel-xen less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103297" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3297</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3297" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3297" source="CVE"/>
	<description>
	The eql_g_master_cfg function in drivers/net/eql.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an EQL_GETMASTRCFG ioctl call.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 039ba32580d28580329514de944be593 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063425" comment="btrfs-kmp-default less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063426" comment="btrfs-kmp-xen less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063429" comment="hyper-v-kmp-default less than 0_2.6.32.23_0.3-0.7.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063430" comment="kernel-default-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063431" comment="kernel-default-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063451" comment="kernel-default-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063432" comment="kernel-default less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063452" comment="kernel-desktop-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063436" comment="kernel-source less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063437" comment="kernel-syms less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063441" comment="kernel-xen-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063442" comment="kernel-xen-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063453" comment="kernel-xen-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063443" comment="kernel-xen less than 2.6.32.23-0.3.1"/>
		</criteria>
	</criteria>
	<!-- 397f45e4eb102e91e10ebd86d7e1eb7b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063845" comment="kernel-pae-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063855" comment="kernel-pae-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063846" comment="kernel-pae less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063851" comment="kernel-xen-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063856" comment="kernel-xen-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063852" comment="kernel-xen less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- a412f327abfdfb030c31be1c37133055 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063425" comment="btrfs-kmp-default less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063445" comment="btrfs-kmp-pae less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063426" comment="btrfs-kmp-xen less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063429" comment="hyper-v-kmp-default less than 0_2.6.32.23_0.3-0.7.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063447" comment="hyper-v-kmp-pae less than 0_2.6.32.23_0.3-0.7.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063430" comment="kernel-default-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063431" comment="kernel-default-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063451" comment="kernel-default-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063432" comment="kernel-default less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063452" comment="kernel-desktop-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063448" comment="kernel-pae-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063449" comment="kernel-pae-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063454" comment="kernel-pae-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063450" comment="kernel-pae less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063436" comment="kernel-source less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063437" comment="kernel-syms less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063441" comment="kernel-xen-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063442" comment="kernel-xen-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063453" comment="kernel-xen-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063443" comment="kernel-xen less than 2.6.32.23-0.3.1"/>
		</criteria>
	</criteria>
	<!-- d69f430f61b72448377e859dd89a3663 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063851" comment="kernel-xen-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063856" comment="kernel-xen-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063852" comment="kernel-xen less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103298" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3298</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3298" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3298" source="CVE"/>
	<description>
	The hso_get_count function in drivers/net/usb/hso.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a TIOCGICOUNT ioctl call.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 039ba32580d28580329514de944be593 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063425" comment="btrfs-kmp-default less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063426" comment="btrfs-kmp-xen less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063429" comment="hyper-v-kmp-default less than 0_2.6.32.23_0.3-0.7.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063430" comment="kernel-default-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063431" comment="kernel-default-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063451" comment="kernel-default-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063432" comment="kernel-default less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063452" comment="kernel-desktop-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063436" comment="kernel-source less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063437" comment="kernel-syms less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063441" comment="kernel-xen-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063442" comment="kernel-xen-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063453" comment="kernel-xen-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063443" comment="kernel-xen less than 2.6.32.23-0.3.1"/>
		</criteria>
	</criteria>
	<!-- a412f327abfdfb030c31be1c37133055 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063425" comment="btrfs-kmp-default less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063445" comment="btrfs-kmp-pae less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063426" comment="btrfs-kmp-xen less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063429" comment="hyper-v-kmp-default less than 0_2.6.32.23_0.3-0.7.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063447" comment="hyper-v-kmp-pae less than 0_2.6.32.23_0.3-0.7.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063430" comment="kernel-default-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063431" comment="kernel-default-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063451" comment="kernel-default-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063432" comment="kernel-default less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063452" comment="kernel-desktop-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063448" comment="kernel-pae-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063449" comment="kernel-pae-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063454" comment="kernel-pae-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063450" comment="kernel-pae less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063436" comment="kernel-source less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063437" comment="kernel-syms less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063441" comment="kernel-xen-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063442" comment="kernel-xen-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063453" comment="kernel-xen-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063443" comment="kernel-xen less than 2.6.32.23-0.3.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103301" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3301</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3301" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3301" source="CVE"/>
	<description>
	The IA32 system call emulation functionality in arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.36-rc4-git2 on the x86_64 platform does not zero extend the %eax register after the 32-bit entry path to ptrace is used, which allows local users to gain privileges by triggering an out-of-bounds access to the system call table using the %rax register.  NOTE: this vulnerability exists because of a CVE-2007-4573 regression.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 43635d2ef5db017de2e87f6c750727d5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062814" comment="btrfs-kmp-default less than 0_2.6.32.19_0.3-0.3.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062824" comment="btrfs-kmp-pae less than 0_2.6.32.19_0.3-0.3.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062825" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.3-0.3.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062828" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.3-0.7.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062829" comment="hyper-v-kmp-pae less than 0_2.6.32.19_0.3-0.7.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062816" comment="kernel-default-base less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062817" comment="kernel-default-devel less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063027" comment="kernel-default-extra less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062818" comment="kernel-default less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063028" comment="kernel-desktop-devel less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062830" comment="kernel-pae-base less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062831" comment="kernel-pae-devel less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063029" comment="kernel-pae-extra less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062832" comment="kernel-pae less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062819" comment="kernel-source less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062820" comment="kernel-syms less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062833" comment="kernel-xen-base less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062834" comment="kernel-xen-devel less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063030" comment="kernel-xen-extra less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062835" comment="kernel-xen less than 2.6.32.19-0.3.1"/>
		</criteria>
	</criteria>
	<!-- 55039b9be6c6d4667182aa22f0adb117 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062844" comment="kernel-default-base less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062849" comment="kernel-default-extra less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062846" comment="kernel-default less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062858" comment="kernel-pae-base less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062864" comment="kernel-pae-extra less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062859" comment="kernel-pae less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062847" comment="kernel-source less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062848" comment="kernel-syms less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062862" comment="kernel-xen-base less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062865" comment="kernel-xen-extra less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062863" comment="kernel-xen less than 2.6.27.48-0.12.1"/>
		</criteria>
	</criteria>
	<!-- 909c914eb25a1f9ef2f32bb54309146e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062844" comment="kernel-default-base less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062849" comment="kernel-default-extra less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062846" comment="kernel-default less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062847" comment="kernel-source less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062848" comment="kernel-syms less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062862" comment="kernel-xen-base less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062865" comment="kernel-xen-extra less than 2.6.27.48-0.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062863" comment="kernel-xen less than 2.6.27.48-0.12.1"/>
		</criteria>
	</criteria>
	<!-- e3a70946dce5e9e1b1288c5039b9d611 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062814" comment="btrfs-kmp-default less than 0_2.6.32.19_0.3-0.3.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062825" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.3-0.3.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062828" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.3-0.7.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062816" comment="kernel-default-base less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062817" comment="kernel-default-devel less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063027" comment="kernel-default-extra less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062818" comment="kernel-default less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063028" comment="kernel-desktop-devel less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062819" comment="kernel-source less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062820" comment="kernel-syms less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062833" comment="kernel-xen-base less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062834" comment="kernel-xen-devel less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063030" comment="kernel-xen-extra less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062835" comment="kernel-xen less than 2.6.32.19-0.3.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103310" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3310</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3310" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3310" source="CVE"/>
	<description>
	Multiple integer signedness errors in net/rose/af_rose.c in the Linux kernel before 2.6.36-rc5-next-20100923 allow local users to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a rose_getname function call, related to the rose_bind and rose_connect functions.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 039ba32580d28580329514de944be593 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063425" comment="btrfs-kmp-default less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063426" comment="btrfs-kmp-xen less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063429" comment="hyper-v-kmp-default less than 0_2.6.32.23_0.3-0.7.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063430" comment="kernel-default-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063431" comment="kernel-default-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063451" comment="kernel-default-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063432" comment="kernel-default less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063452" comment="kernel-desktop-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063436" comment="kernel-source less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063437" comment="kernel-syms less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063441" comment="kernel-xen-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063442" comment="kernel-xen-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063453" comment="kernel-xen-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063443" comment="kernel-xen less than 2.6.32.23-0.3.1"/>
		</criteria>
	</criteria>
	<!-- 397f45e4eb102e91e10ebd86d7e1eb7b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063845" comment="kernel-pae-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063855" comment="kernel-pae-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063846" comment="kernel-pae less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063851" comment="kernel-xen-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063856" comment="kernel-xen-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063852" comment="kernel-xen less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- a412f327abfdfb030c31be1c37133055 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063425" comment="btrfs-kmp-default less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063445" comment="btrfs-kmp-pae less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063426" comment="btrfs-kmp-xen less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063429" comment="hyper-v-kmp-default less than 0_2.6.32.23_0.3-0.7.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063447" comment="hyper-v-kmp-pae less than 0_2.6.32.23_0.3-0.7.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063430" comment="kernel-default-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063431" comment="kernel-default-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063451" comment="kernel-default-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063432" comment="kernel-default less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063452" comment="kernel-desktop-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063448" comment="kernel-pae-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063449" comment="kernel-pae-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063454" comment="kernel-pae-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063450" comment="kernel-pae less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063436" comment="kernel-source less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063437" comment="kernel-syms less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063441" comment="kernel-xen-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063442" comment="kernel-xen-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063453" comment="kernel-xen-extra less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063443" comment="kernel-xen less than 2.6.32.23-0.3.1"/>
		</criteria>
	</criteria>
	<!-- d69f430f61b72448377e859dd89a3663 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063851" comment="kernel-xen-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063856" comment="kernel-xen-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063852" comment="kernel-xen less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103311" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3311</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3311" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3311" source="CVE"/>
	<description>
	Integer overflow in base/ftstream.c in libXft (aka the X FreeType library) in FreeType before 2.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Compact Font Format (CFF) font file that triggers a heap-based buffer overflow, related to an "input stream position error" issue, a different vulnerability than CVE-2010-1797.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 82d6887b2f70a5e8338a67da7664d81a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063351" comment="freetype2-32bit less than 2.3.7-25.17.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063378" comment="freetype2-devel less than 2.3.7-25.17.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063353" comment="freetype2 less than 2.3.7-25.17.1"/>
		</criteria>
	</criteria>
	<!-- f37351b8a4e423933441713b6c749951 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063351" comment="freetype2-32bit less than 2.3.7-25.17.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063378" comment="freetype2-devel less than 2.3.7-25.17.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063353" comment="freetype2 less than 2.3.7-25.17.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103312" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3312</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3312" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3312" source="CVE"/>
	<description>
	Epiphany 2.28 and 2.29, when WebKit and LibSoup are used, unconditionally displays a closed-lock icon for any URL beginning with the https: substring, without any warning to the user, which allows man-in-the-middle attackers to spoof arbitrary https web sites via a crafted X.509 server certificate.
	</description>
 </metadata>
<!-- 7568c9f68c8d9f3d93df8fa93628362e -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009064855" comment="epiphany-lang less than 2.28.2-0.5.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009064856" comment="epiphany less than 2.28.2-0.5.2"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103316" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3316</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3316" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3316" source="CVE"/>
	<description>
	The run_coprocess function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) before 1.1.2 does not check the return values of the setuid, setgid, and setgroups system calls, which might allow local users to read arbitrary files by executing a program that relies on the pam_xauth PAM check.
	</description>
 </metadata>
<!-- fd9b46439ba47c737129f58734f894dc -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009071640" comment="pam-32bit less than 1.0.4-0.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009071641" comment="pam-doc less than 1.0.4-0.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009071643" comment="pam less than 1.0.4-0.7.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103332" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3332</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3332" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3332" source="CVE"/>
	<description>
	Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Services (IIS), provides detailed error codes during decryption attempts, which allows remote attackers to decrypt and modify encrypted View State (aka __VIEWSTATE) form data, and possibly forge cookies or read application files, via a padding oracle attack, aka "ASP.NET Padding Oracle Vulnerability."
	</description>
 </metadata>
<!-- 4b4fd333829431dc46ababe3070f9b3f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009067816" comment="bytefx-data-mysql less than 2.0.1-1.34.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009067823" comment="ibm-data-db2 less than 2.0.1-1.34.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009067793" comment="mono-core less than 2.0.1-1.34.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009067817" comment="mono-data-firebird less than 2.0.1-1.34.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009067818" comment="mono-data-oracle less than 2.0.1-1.34.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009067794" comment="mono-data-postgresql less than 2.0.1-1.34.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009067795" comment="mono-data-sqlite less than 2.0.1-1.34.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009067819" comment="mono-data-sybase less than 2.0.1-1.34.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009067796" comment="mono-data less than 2.0.1-1.34.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009067820" comment="mono-devel less than 2.0.1-1.34.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009067821" comment="mono-extras less than 2.0.1-1.34.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009067822" comment="mono-jscript less than 2.0.1-1.34.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009067797" comment="mono-locale-extras less than 2.0.1-1.34.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009067798" comment="mono-nunit less than 2.0.1-1.34.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009067799" comment="mono-web less than 2.0.1-1.34.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009067800" comment="mono-winforms less than 2.0.1-1.34.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103432" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3432</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3432" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3432" source="CVE"/>
	<description>
	The sctp_packet_config function in net/sctp/output.c in the Linux kernel before 2.6.35.6 performs extraneous initializations of packet data structures, which allows remote attackers to cause a denial of service (panic) via a certain sequence of SCTP traffic.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 4b53dedac262e9445a17875eb5c427c1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064260" comment="btrfs-kmp-default less than 0_2.6.32.24_0.2-0.3.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064261" comment="btrfs-kmp-pae less than 0_2.6.32.24_0.2-0.3.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064262" comment="btrfs-kmp-xen less than 0_2.6.32.24_0.2-0.3.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064266" comment="hyper-v-kmp-default less than 0_2.6.32.24_0.2-0.7.17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064267" comment="hyper-v-kmp-pae less than 0_2.6.32.24_0.2-0.7.17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064268" comment="kernel-default-base less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064269" comment="kernel-default-devel less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064294" comment="kernel-default-extra less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064270" comment="kernel-default less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064295" comment="kernel-desktop-devel less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064271" comment="kernel-pae-base less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064272" comment="kernel-pae-devel less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064296" comment="kernel-pae-extra less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064273" comment="kernel-pae less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064274" comment="kernel-source less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064275" comment="kernel-syms less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064279" comment="kernel-xen-base less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064280" comment="kernel-xen-devel less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064297" comment="kernel-xen-extra less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064281" comment="kernel-xen less than 2.6.32.24-0.2.1"/>
		</criteria>
	</criteria>
	<!-- f01275198337ab5cb5d84d49e735536a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064260" comment="btrfs-kmp-default less than 0_2.6.32.24_0.2-0.3.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064262" comment="btrfs-kmp-xen less than 0_2.6.32.24_0.2-0.3.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064266" comment="hyper-v-kmp-default less than 0_2.6.32.24_0.2-0.7.17"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064268" comment="kernel-default-base less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064269" comment="kernel-default-devel less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064294" comment="kernel-default-extra less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064270" comment="kernel-default less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064295" comment="kernel-desktop-devel less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064274" comment="kernel-source less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064275" comment="kernel-syms less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064279" comment="kernel-xen-base less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064280" comment="kernel-xen-devel less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064297" comment="kernel-xen-extra less than 2.6.32.24-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064281" comment="kernel-xen less than 2.6.32.24-0.2.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103434" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3434</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 GA</platform>
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3434" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3434" source="CVE"/>
	<description>
	Buffer overflow in the find_stream_bounds function in pdf.c in libclamav in ClamAV before 0.96.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document.  NOTE: some of these details are obtained from third party information.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1d0764e8f349c937472e38df63ab80b6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064521" comment="clamav less than 0.96.4-0.2.1"/>
	</criteria>
	<!-- 4fbf44df6724cc75fa1ebd066513fd05 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009047612" comment="sled11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064521" comment="clamav less than 0.96.4-0.2.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103437" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3437</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3437" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3437" source="CVE"/>
	<description>
	Integer signedness error in the pkt_find_dev_from_minor function in drivers/block/pktcdvd.c in the Linux kernel before 2.6.36-rc6 allows local users to obtain sensitive information from kernel memory or cause a denial of service (invalid pointer dereference and system crash) via a crafted index value in a PKT_CTRL_CMD_STATUS ioctl call.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1e884403c52fc77802015c35ce13fbc4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009065507" comment="btrfs-kmp-default less than 0_2.6.32.27_0.2-0.3.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065508" comment="btrfs-kmp-pae less than 0_2.6.32.27_0.2-0.3.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065509" comment="btrfs-kmp-xen less than 0_2.6.32.27_0.2-0.3.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065513" comment="hyper-v-kmp-default less than 0_2.6.32.27_0.2-0.8.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065514" comment="hyper-v-kmp-pae less than 0_2.6.32.27_0.2-0.8.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065515" comment="kernel-default-base less than 2.6.32.27-0.2.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065516" comment="kernel-default-devel less than 2.6.32.27-0.2.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065537" comment="kernel-default-extra less than 2.6.32.27-0.2.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065517" comment="kernel-default less than 2.6.32.27-0.2.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065538" comment="kernel-desktop-devel less than 2.6.32.27-0.2.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065520" comment="kernel-pae-base less than 2.6.32.27-0.2.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065521" comment="kernel-pae-devel less than 2.6.32.27-0.2.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065539" comment="kernel-pae-extra less than 2.6.32.27-0.2.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065522" comment="kernel-pae less than 2.6.32.27-0.2.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065523" comment="kernel-source less than 2.6.32.27-0.2.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065524" comment="kernel-syms less than 2.6.32.27-0.2.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065528" comment="kernel-xen-base less than 2.6.32.27-0.2.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065529" comment="kernel-xen-devel less than 2.6.32.27-0.2.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065540" comment="kernel-xen-extra less than 2.6.32.27-0.2.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065530" comment="kernel-xen less than 2.6.32.27-0.2.2"/>
		</criteria>
	</criteria>
	<!-- 23f8d08c0e40d5d87542968bb0041a81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009065507" comment="btrfs-kmp-default less than 0_2.6.32.27_0.2-0.3.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065509" comment="btrfs-kmp-xen less than 0_2.6.32.27_0.2-0.3.29"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065513" comment="hyper-v-kmp-default less than 0_2.6.32.27_0.2-0.8.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065515" comment="kernel-default-base less than 2.6.32.27-0.2.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065516" comment="kernel-default-devel less than 2.6.32.27-0.2.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065537" comment="kernel-default-extra less than 2.6.32.27-0.2.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065517" comment="kernel-default less than 2.6.32.27-0.2.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065538" comment="kernel-desktop-devel less than 2.6.32.27-0.2.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065523" comment="kernel-source less than 2.6.32.27-0.2.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065524" comment="kernel-syms less than 2.6.32.27-0.2.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065528" comment="kernel-xen-base less than 2.6.32.27-0.2.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065529" comment="kernel-xen-devel less than 2.6.32.27-0.2.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065540" comment="kernel-xen-extra less than 2.6.32.27-0.2.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065530" comment="kernel-xen less than 2.6.32.27-0.2.2"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103445" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3445</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3445" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3445" source="CVE"/>
	<description>
	Stack consumption vulnerability in the dissect_ber_unknown function in epan/dissectors/packet-ber.c in the BER dissector in Wireshark 1.4.x before 1.4.1 and 1.2.x before 1.2.12 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a long string in an unknown ASN.1/BER encoded packet, as demonstrated using SNMP.
	</description>
 </metadata>
<!-- 6e5fc6e202651e8b93c830786b3ea82f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066948" comment="wireshark less than 1.4.4-0.2.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103450" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-3450</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Desktop 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-3450" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3450" source="CVE"/>
	<description>
	Multiple directory traversal vulnerabilities in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to overwrite arbitrary files via a .. (dot dot) in an entry in (1) an XSLT JAR filter description file, (2) an Extension (aka OXT) file, or unspecified other (3) JAR or (4) ZIP files.
	</description>
 </metadata>
<!-- 9c036937b6a42810ef9c8a7caff47b50 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060809" comment="sled11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009066355" comment="libreoffice-base-drivers-postgresql less than 3.3.1.2-1.3.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066356" comment="libreoffice-base-extensions less than 3.3.1.2-1.3.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066228" comment="libreoffice-base less than 3.3.1.2-1.3.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066230" comment="libreoffice-branding-SLED less than 3.3.1-0.3.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066357" comment="libreoffice-calc-extensions less than 3.3.1.2-1.3.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066233" comment="libreoffice-calc less than 3.3.1.2-1.3.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066235" comment="libreoffice-components less than 3.3.1.2-1.3.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066358" comment="libreoffice-converter less than 3.3-1.3.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066359" comment="libreoffice-draw-extensions less than 3.3.1.2-1.3.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066236" comment="libreoffice-draw less than 3.3.1.2-1.3.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066238" comment="libreoffice-filters-optional less than 3.3.1.2-1.3.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066239" comment="libreoffice-filters less than 3.3.1.2-1.3.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066240" comment="libreoffice-gnome less than 3.3.1.2-1.3.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066241" comment="libreoffice-help-ar less than 3.3.1.2-1.7.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066242" comment="libreoffice-help-cs less than 3.3.1.2-1.7.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066243" comment="libreoffice-help-da less than 3.3.1.2-1.7.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066244" comment="libreoffice-help-de less than 3.3.1.2-1.7.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066245" comment="libreoffice-help-en-GB less than 3.3.1.2-1.7.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066247" comment="libreoffice-help-en-US less than 3.3.1.2-1.7.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066248" comment="libreoffice-help-es less than 3.3.1.2-1.7.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066249" comment="libreoffice-help-fr less than 3.3.1.2-1.7.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066360" comment="libreoffice-help-gu-IN less than 3.3.1.2-1.7.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066361" comment="libreoffice-help-hi-IN less than 3.3.1.2-1.7.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066250" comment="libreoffice-help-hu less than 3.3.1.2-1.7.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066251" comment="libreoffice-help-it less than 3.3.1.2-1.7.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066252" comment="libreoffice-help-ja less than 3.3.1.2-1.7.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066362" comment="libreoffice-help-ko less than 3.3.1.2-1.7.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066253" comment="libreoffice-help-nl less than 3.3.1.2-1.7.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066254" comment="libreoffice-help-pl less than 3.3.1.2-1.7.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066255" comment="libreoffice-help-pt-BR less than 3.3.1.2-1.7.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066256" comment="libreoffice-help-pt less than 3.3.1.2-1.7.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066257" comment="libreoffice-help-ru less than 3.3.1.2-1.7.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066258" comment="libreoffice-help-sv less than 3.3.1.2-1.7.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066259" comment="libreoffice-help-zh-CN less than 3.3.1.2-1.7.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066260" comment="libreoffice-help-zh-TW less than 3.3.1.2-1.7.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066261" comment="libreoffice-hyphen less than 20110217-0.3.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066262" comment="libreoffice-icon-themes less than 3.3.1.2-1.3.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066363" comment="libreoffice-impress-extensions less than 3.3.1.2-1.3.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066264" comment="libreoffice-impress less than 3.3.1.2-1.3.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066265" comment="libreoffice-kde4 less than 3.3.1.2-1.3.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066266" comment="libreoffice-kde less than 3.3.1.2-1.3.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066267" comment="libreoffice-l10n-af less than 3.3.1.2-1.3.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066268" comment="libreoffice-l10n-ar less than 3.3.1.2-1.3.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066269" comment="libreoffice-l10n-ca less than
