<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions
	xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd"
	xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5"
	xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
	xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5"
	xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
      <oval:product_name>Marcus OVAL Generator</oval:product_name>
      <oval:schema_version>5.5</oval:schema_version>
      <oval:timestamp>2012-05-19T04:02:24</oval:timestamp>
  </generator>
  <definitions>
<definition id="oval:org.opensuse.security:def:20040801" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2004-0801</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for Teradata</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2004-0801" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0801" source="CVE"/>
	<description>
	Unknown vulnerability in foomatic-rip in Foomatic before 3.0.2 allows local users or remote attackers with access to CUPS to execute arbitrary commands.
	</description>
 </metadata>
<!-- 997ad18a4f4706edd462cae443e492f0 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009070056" comment="hplip-hpijs less than 3.9.8-3.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070057" comment="hplip less than 3.9.8-3.7.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20054881" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-4881</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2005-4881" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4881" source="CVE"/>
	<description>
	The netlink subsystem in the Linux kernel 2.4.x before 2.4.37.6 and 2.6.x before 2.6.13-rc1 does not initialize certain padding fields in structures, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors, related to the (1) tc_fill_qdisc, (2) tcf_fill_node, (3) neightbl_fill_info, (4) neightbl_fill_param_info, (5) neigh_fill_info, (6) rtnetlink_fill_ifinfo, (7) rtnetlink_fill_iwinfo, (8) vif_delete, (9) ipmr_destroy_unres, (10) ipmr_cache_alloc_unres, (11) ipmr_cache_resolve, (12) inet6_fill_ifinfo, (13) tca_get_fill, (14) tca_action_flush, (15) tcf_add_notify, (16) tc_dump_action, (17) cbq_dump_police, (18) __nlmsg_put, (19) __rta_fill, (20) __rta_reserve, (21) inet6_fill_prefix, (22) rsvp_dump, and (23) cbq_dump_ovl functions.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 114b9cf953db7d4a1a91082495d33414 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056506" comment="ext4dev-kmp-xen less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056511" comment="kernel-xen-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056512" comment="kernel-xen less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- 9b6d121530adca742ba4b1a99075559a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056513" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056514" comment="kernel-kdump less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056515" comment="kernel-ppc64-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056516" comment="kernel-ppc64 less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- a3c4f0428e25dca1993e5018e76d6758 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056517" comment="ext4dev-kmp-pae less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056518" comment="ext4dev-kmp-vmi less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056506" comment="ext4dev-kmp-xen less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056519" comment="kernel-pae-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056520" comment="kernel-pae less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056521" comment="kernel-vmi-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056522" comment="kernel-vmi less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056511" comment="kernel-xen-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056512" comment="kernel-xen less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- dfdf7dd3f18b0b2cf8024eb5a30e51ba -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- faf6558ee52bc90aea4840dc79e5757f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056523" comment="kernel-default-man less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20054890" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2005-4890</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2005-4890" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4890" source="CVE"/>
	<description>
	** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.
	</description>
 </metadata>
<!-- 398c4e6a90a6b6fe88e0b53589b8003b -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009072288" comment="coreutils-lang less than 6.12-32.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009072289" comment="coreutils-x86 less than 6.12-32.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009072290" comment="coreutils less than 6.12-32.26.1"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009072288" comment="coreutils-lang less than 6.12-32.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009072290" comment="coreutils less than 6.12-32.26.1"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20067246" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2006-7246</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for Teradata</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2006-7246" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-7246" source="CVE"/>
	<description>
	** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 470bd49885d23715755d7bb4f880b3c2 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009071988" comment="NetworkManager-glib less than 0.7.1_git20090811-3.9.9.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009071989" comment="NetworkManager-gnome less than 0.7.1-5.15.7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009071990" comment="NetworkManager less than 0.7.1_git20090811-3.9.9.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009071991" comment="wpa_supplicant less than 0.6.9-4.5.4"/>
		</criteria>
	</criteria>
	<!-- c7f58cba030474918054f80ae9b9d8f5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009072967" comment="NetworkManager-gnome less than 0.7.1-5.15.11.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20067250" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2006-7250</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for Teradata</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
		<platform>SUSE Linux Enterprise Server 11 SP2</platform>
	</affected>
	<reference ref_id="CVE-2006-7250" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-7250" source="CVE"/>
	<description>
	The mime_hdr_cmp function in crypto/asn1/asn_mime.c in OpenSSL 0.9.8t and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted S/MIME message.
	</description>
 </metadata>
<!-- 5c8a36f85c32f7d2796329c6695e45e9 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009073445" comment="libopenssl0_9_8-32bit less than 0.9.8j-0.32.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009073446" comment="libopenssl0_9_8-x86 less than 0.9.8j-0.32.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009073447" comment="libopenssl0_9_8 less than 0.9.8j-0.32.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009073448" comment="openssl-doc less than 0.9.8j-0.32.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009073449" comment="openssl less than 0.9.8j-0.32.1"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009073445" comment="libopenssl0_9_8-32bit less than 0.9.8j-0.32.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009073447" comment="libopenssl0_9_8 less than 0.9.8j-0.32.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009073448" comment="openssl-doc less than 0.9.8j-0.32.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009073449" comment="openssl less than 0.9.8j-0.32.1"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20076725" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2007-6725</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2007-6725" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6725" source="CVE"/>
	<description>
	The CCITTFax decoding filter in Ghostscript 8.60, 8.61, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF file that triggers a buffer underflow in the cf_decode_2d function.
	</description>
 </metadata>
<!-- ab7a3ecdd7f2b22db74d66fd6e23832b -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032106" comment="ghostscript-fonts-other less than 8.62-32.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032107" comment="ghostscript-fonts-rus less than 8.62-32.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032108" comment="ghostscript-fonts-std less than 8.62-32.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032109" comment="ghostscript-library less than 8.62-32.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032110" comment="ghostscript-omni less than 8.62-32.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032111" comment="ghostscript-x11 less than 8.62-32.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032112" comment="libgimpprint less than 4.2.7-32.25.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20076750" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2007-6750</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for Teradata</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2007-6750" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6750" source="CVE"/>
	<description>
	The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris, related to the lack of the mod_reqtimeout module in versions before 2.2.15.
	</description>
 </metadata>
<!-- 26fd37ffcda352499111cd00df8417e9 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009072976" comment="apache2-doc less than 2.2.12-1.30.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009072977" comment="apache2-example-pages less than 2.2.12-1.30.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009072978" comment="apache2-prefork less than 2.2.12-1.30.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009072979" comment="apache2-utils less than 2.2.12-1.30.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009072980" comment="apache2-worker less than 2.2.12-1.30.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009072981" comment="apache2 less than 2.2.12-1.30.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009072982" comment="libapr1-32bit less than 1.3.3-11.18.19.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009072983" comment="libapr1 less than 1.3.3-11.18.19.1"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009072976" comment="apache2-doc less than 2.2.12-1.30.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009072977" comment="apache2-example-pages less than 2.2.12-1.30.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009072978" comment="apache2-prefork less than 2.2.12-1.30.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009072979" comment="apache2-utils less than 2.2.12-1.30.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009072980" comment="apache2-worker less than 2.2.12-1.30.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009072981" comment="apache2 less than 2.2.12-1.30.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009072983" comment="libapr1 less than 1.3.3-11.18.19.1"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20081391" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-1391</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-1391" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1391" source="CVE"/>
	<description>
	Multiple integer overflows in libc in NetBSD 4.x, FreeBSD 6.x and 7.x, and probably other BSD and Apple Mac OS platforms allow context-dependent attackers to execute arbitrary code via large values of certain integer fields in the format argument to (1) the strfmon function in lib/libc/stdlib/strfmon.c, related to the GET_NUMBER macro; and (2) the printf function, related to left_prec and right_prec.
	</description>
 </metadata>
<!-- 5f11ad23d76a12882072f1f4032fd9a4 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009064033" comment="glibc-32bit less than 2.9-13.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009064034" comment="glibc-devel-32bit less than 2.9-13.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009064035" comment="glibc-devel less than 2.9-13.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009064036" comment="glibc-html less than 2.9-13.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009064037" comment="glibc-i18ndata less than 2.9-13.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009064038" comment="glibc-info less than 2.9-13.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009064039" comment="glibc-locale-32bit less than 2.9-13.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009064040" comment="glibc-locale less than 2.9-13.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009064041" comment="glibc-profile-32bit less than 2.9-13.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009064042" comment="glibc-profile less than 2.9-13.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009064043" comment="glibc less than 2.9-13.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009064044" comment="nscd less than 2.9-13.11.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20082086" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-2086</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-2086" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2086" source="CVE"/>
	<description>
	Sun Java Web Start and Java Plug-in for JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allow remote attackers to execute arbitrary code via a crafted jnlp file that modifies the (1) java.home, (2) java.ext.dirs, or (3) user.home System Properties, aka "Java Web Start File Inclusion" and CR 6694892.
	</description>
 </metadata>
<!-- 1113e80269ad51bda2997bfd043ad5b8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032113" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032114" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032115" comment="java-1_4_2-ibm less than 1.4.2_sr13-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20083443" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-3443</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-3443" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3443" source="CVE"/>
	<description>
	The regular expression engine (regex.c) in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows remote attackers to cause a denial of service (infinite loop and crash) via multiple long requests to a Ruby socket, related to memory allocation failure, and as demonstrated against Webrick.
	</description>
 </metadata>
<!-- c8369586b31bf86da2231acd00ad8f78 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053192" comment="ruby-doc-html less than 1.8.7.p72-5.22.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053193" comment="ruby-tk less than 1.8.7.p72-5.22.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053194" comment="ruby less than 1.8.7.p72-5.22.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20083655" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-3655</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-3655" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3655" source="CVE"/>
	<description>
	Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not properly restrict access to critical variables and methods at various safe levels, which allows context-dependent attackers to bypass intended access restrictions via (1) untrace_var, (2) $PROGRAM_NAME, and (3) syslog at safe level 4, and (4) insecure methods at safe levels 1 through 3.
	</description>
 </metadata>
<!-- c8369586b31bf86da2231acd00ad8f78 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053192" comment="ruby-doc-html less than 1.8.7.p72-5.22.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053193" comment="ruby-tk less than 1.8.7.p72-5.22.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053194" comment="ruby less than 1.8.7.p72-5.22.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20083656" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-3656</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-3656" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3656" source="CVE"/>
	<description>
	Algorithmic complexity vulnerability in the WEBrick::HTTPUtils.split_header_value function in WEBrick::HTTP::DefaultFileHandler in WEBrick in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted HTTP request that is processed by a backtracking regular expression.
	</description>
 </metadata>
<!-- c8369586b31bf86da2231acd00ad8f78 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053192" comment="ruby-doc-html less than 1.8.7.p72-5.22.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053193" comment="ruby-tk less than 1.8.7.p72-5.22.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053194" comment="ruby less than 1.8.7.p72-5.22.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20083657" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-3657</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-3657" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3657" source="CVE"/>
	<description>
	The dl module in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not check "taintness" of inputs, which allows context-dependent attackers to bypass safe levels and execute dangerous functions by accessing a library using DL.dlopen.
	</description>
 </metadata>
<!-- c8369586b31bf86da2231acd00ad8f78 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053192" comment="ruby-doc-html less than 1.8.7.p72-5.22.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053193" comment="ruby-tk less than 1.8.7.p72-5.22.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053194" comment="ruby less than 1.8.7.p72-5.22.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20083790" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-3790</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-3790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3790" source="CVE"/>
	<description>
	The REXML module in Ruby 1.8.6 through 1.8.6-p287, 1.8.7 through 1.8.7-p72, and 1.9 allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML document with recursively nested entities, aka an "XML entity explosion."
	</description>
 </metadata>
<!-- c8369586b31bf86da2231acd00ad8f78 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053192" comment="ruby-doc-html less than 1.8.7.p72-5.22.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053193" comment="ruby-tk less than 1.8.7.p72-5.22.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053194" comment="ruby less than 1.8.7.p72-5.22.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20083834" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-3834</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2008-3834" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3834" source="CVE"/>
	<description>
	The dbus_signature_validate function in the D-bus library (libdbus) before 1.2.4 allows remote attackers to cause a denial of service (application abort) via a message containing a malformed signature, which triggers a failed assertion error.
	</description>
 </metadata>
<!-- 54eee4e87a0d78b170de796964bdfc46 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009067850" comment="dbus-1-32bit less than 1.2.10-3.17.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009067851" comment="dbus-1-x11 less than 1.2.10-3.17.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009067852" comment="dbus-1-x86 less than 1.2.10-3.17.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009067853" comment="dbus-1 less than 1.2.10-3.17.1"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009067850" comment="dbus-1-32bit less than 1.2.10-3.17.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009067851" comment="dbus-1-x11 less than 1.2.10-3.17.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009067853" comment="dbus-1 less than 1.2.10-3.17.1"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20083905" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-3905</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-3905" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3905" source="CVE"/>
	<description>
	resolv.rb in Ruby 1.8.5 and earlier, 1.8.6 before 1.8.6-p287, 1.8.7 before 1.8.7-p72, and 1.9 r18423 and earlier uses sequential transaction IDs and constant source ports for DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447.
	</description>
 </metadata>
<!-- c8369586b31bf86da2231acd00ad8f78 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053192" comment="ruby-doc-html less than 1.8.7.p72-5.22.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053193" comment="ruby-tk less than 1.8.7.p72-5.22.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053194" comment="ruby less than 1.8.7.p72-5.22.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20083916" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-3916</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2008-3916" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3916" source="CVE"/>
	<description>
	Heap-based buffer overflow in the strip_escapes function in signal.c in GNU ed before 1.0 allows context-dependent or user-assisted attackers to execute arbitrary code via a long filename.  NOTE: since ed itself does not typically run with special privileges, this issue only crosses privilege boundaries when ed is invoked as a third-party component.
	</description>
 </metadata>
<!-- db1a7237caafa1fc9b7316fc8540dbaf -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009065506" comment="ed less than 0.2-1001.30.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20084311" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-4311</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-4311" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4311" source="CVE"/>
	<description>
	The default configuration of system.conf in D-Bus (aka DBus) before 1.2.6 omits the send_type attribute in certain rules, which allows local users to bypass intended access restrictions by (1) sending messages, related to send_requested_reply; and possibly (2) receiving messages, related to receive_requested_reply.
	</description>
 </metadata>
<!-- 9743b3e1bf7258cd935101dc92d337cb -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032116" comment="dbus-1-32bit less than 1.2.10-3.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032117" comment="dbus-1-x86 less than 1.2.10-3.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032118" comment="dbus-1 less than 1.2.10-3.9.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20084316" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-4316</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-4316" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4316" source="CVE"/>
	<description>
	Multiple integer overflows in glib/gbase64.c in GLib before 2.20 allow context-dependent attackers to execute arbitrary code via a long string that is converted either (1) from or (2) to a base64 representation.
	</description>
 </metadata>
<!-- 5e189989237df74cc60cee5f9491bdc4 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032119" comment="glib2-doc less than 2.18.2-7.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032120" comment="glib2-lang less than 2.18.2-7.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032121" comment="glib2 less than 2.18.2-7.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032122" comment="libgio-2_0-0-32bit less than 2.18.2-7.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032123" comment="libgio-2_0-0-x86 less than 2.18.2-7.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032124" comment="libgio-2_0-0 less than 2.18.2-7.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032125" comment="libglib-2_0-0-32bit less than 2.18.2-7.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032126" comment="libglib-2_0-0-x86 less than 2.18.2-7.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032127" comment="libglib-2_0-0 less than 2.18.2-7.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032128" comment="libgmodule-2_0-0-32bit less than 2.18.2-7.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032129" comment="libgmodule-2_0-0-x86 less than 2.18.2-7.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032130" comment="libgmodule-2_0-0 less than 2.18.2-7.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032131" comment="libgobject-2_0-0-32bit less than 2.18.2-7.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032132" comment="libgobject-2_0-0-x86 less than 2.18.2-7.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032133" comment="libgobject-2_0-0 less than 2.18.2-7.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032134" comment="libgthread-2_0-0-32bit less than 2.18.2-7.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032135" comment="libgthread-2_0-0-x86 less than 2.18.2-7.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032136" comment="libgthread-2_0-0 less than 2.18.2-7.7.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20084456" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-4456</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-4456" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4456" source="CVE"/>
	<description>
	Cross-site scripting (XSS) vulnerability in the command-line client in MySQL 5.0.26 through 5.0.45, and other versions including versions later than 5.0.45, when the --html option is enabled, allows attackers to inject arbitrary web script or HTML by placing it in a database cell, which might be accessed by this client when composing an HTML document.  NOTE: as of 20081031, the issue has not been fixed in MySQL 5.0.67.
	</description>
 </metadata>
<!-- 6b4ffc010711f4a40d2054f5fc473cc7 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009054286" comment="libmysqlclient15-32bit less than 5.0.67-13.16.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054287" comment="libmysqlclient15-x86 less than 5.0.67-13.16.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054288" comment="libmysqlclient15 less than 5.0.67-13.16.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054289" comment="libmysqlclient_r15 less than 5.0.67-13.16.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054290" comment="mysql-Max less than 5.0.67-13.16.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054291" comment="mysql-client less than 5.0.67-13.16.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054292" comment="mysql less than 5.0.67-13.16.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20084776" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-4776</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2008-4776" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4776" source="CVE"/>
	<description>
	libgadu before 1.8.2 allows remote servers to cause a denial of service (crash) via a contact description with a large length, which triggers a buffer over-read.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2fb2523f388f4f507725821f053b7b30 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009065196" comment="kdenetwork4-filesharing less than 4.3.5-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065197" comment="kget less than 4.3.5-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065198" comment="kopete less than 4.3.5-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065199" comment="krdc less than 4.3.5-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065200" comment="krfb less than 4.3.5-0.4.1"/>
		</criteria>
	</criteria>
	<!-- fb44440d868c7c3b0efae521994af0a4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009065165" comment="kde4-kget less than 4.1.3-7.9.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065166" comment="kde4-knewsticker less than 4.1.3-7.9.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065167" comment="kde4-kopete less than 4.1.3-7.9.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065168" comment="kde4-krdc less than 4.1.3-7.9.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065169" comment="kde4-krfb less than 4.1.3-7.9.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065170" comment="kdenetwork4-filesharing less than 4.1.3-7.9.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20084989" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-4989</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-4989" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4989" source="CVE"/>
	<description>
	The _gnutls_x509_verify_certificate function in lib/x509/verify.c in libgnutls in GnuTLS before 2.6.1 trusts certificate chains in which the last certificate is an arbitrary trusted, self-signed certificate, which allows man-in-the-middle attackers to insert a spoofed certificate for any Distinguished Name (DN).
	</description>
 </metadata>
<!-- e280121d3f2f9a8553bbbfef193309bf -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032137" comment="gnutls less than 2.4.1-24.16.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032138" comment="libgnutls26-32bit less than 2.4.1-24.16.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032139" comment="libgnutls26-x86 less than 2.4.1-24.16.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032140" comment="libgnutls26 less than 2.4.1-24.16.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20085339" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-5339</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-5339" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5339" source="CVE"/>
	<description>
	Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted JWS applications to perform network connections to unauthorized hosts via unknown vectors, aka CR 6727079.
	</description>
 </metadata>
<!-- 1113e80269ad51bda2997bfd043ad5b8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032113" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032114" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032115" comment="java-1_4_2-ibm less than 1.4.2_sr13-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20085340" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-5340</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-5340" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5340" source="CVE"/>
	<description>
	Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted JWS applications to gain privileges to access local files or applications via unknown vectors, aka 6727081.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1113e80269ad51bda2997bfd043ad5b8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032113" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032114" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032115" comment="java-1_4_2-ibm less than 1.4.2_sr13-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 7d9a96f54ebbdea55cd9630e7b8de703 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032141" comment="java-1_6_0-ibm-alsa less than 1.6.0-124.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032142" comment="java-1_6_0-ibm-fonts less than 1.6.0-124.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032143" comment="java-1_6_0-ibm-jdbc less than 1.6.0-124.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032144" comment="java-1_6_0-ibm-plugin less than 1.6.0-124.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032145" comment="java-1_6_0-ibm less than 1.6.0-124.6.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20085341" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-5341</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-5341" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5341" source="CVE"/>
	<description>
	Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier, and JDK and JRE 5.0 Update 16 and earlier, allows untrusted JWS applications to obtain the pathname of the JWS cache and the application username via unknown vectors, aka CR 6727071.
	</description>
 </metadata>
<!-- 7d9a96f54ebbdea55cd9630e7b8de703 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032141" comment="java-1_6_0-ibm-alsa less than 1.6.0-124.6.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032142" comment="java-1_6_0-ibm-fonts less than 1.6.0-124.6.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032143" comment="java-1_6_0-ibm-jdbc less than 1.6.0-124.6.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032144" comment="java-1_6_0-ibm-plugin less than 1.6.0-124.6.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032145" comment="java-1_6_0-ibm less than 1.6.0-124.6.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20085342" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-5342</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-5342" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5342" source="CVE"/>
	<description>
	Unspecified vulnerability in the BasicService for Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted downloaded applications to cause local files to be displayed in the browser of the user of the untrusted application via unknown vectors, aka 6767668.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1113e80269ad51bda2997bfd043ad5b8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032113" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032114" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032115" comment="java-1_4_2-ibm less than 1.4.2_sr13-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 7d9a96f54ebbdea55cd9630e7b8de703 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032141" comment="java-1_6_0-ibm-alsa less than 1.6.0-124.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032142" comment="java-1_6_0-ibm-fonts less than 1.6.0-124.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032143" comment="java-1_6_0-ibm-jdbc less than 1.6.0-124.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032144" comment="java-1_6_0-ibm-plugin less than 1.6.0-124.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032145" comment="java-1_6_0-ibm less than 1.6.0-124.6.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20085343" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-5343</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-5343" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5343" source="CVE"/>
	<description>
	Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows remote attackers to make unauthorized network connections and hijack HTTP sessions via a crafted file that validates as both a GIF and a Java JAR file, aka "GIFAR" and CR 6707535.
	</description>
 </metadata>
<!-- 1113e80269ad51bda2997bfd043ad5b8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032113" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032114" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032115" comment="java-1_4_2-ibm less than 1.4.2_sr13-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20085344" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-5344</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-5344" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5344" source="CVE"/>
	<description>
	Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted applets to read arbitrary files and make unauthorized network connections via unknown vectors related to applet classloading, aka 6716217.
	</description>
 </metadata>
<!-- 1113e80269ad51bda2997bfd043ad5b8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032113" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032114" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032115" comment="java-1_4_2-ibm less than 1.4.2_sr13-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20085345" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-5345</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-5345" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5345" source="CVE"/>
	<description>
	Unspecified vulnerability in Java Runtime Environment (JRE) with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier allows code that is loaded from a local filesystem to read arbitrary files and make unauthorized connections to localhost via unknown vectors.
	</description>
 </metadata>
<!-- 1113e80269ad51bda2997bfd043ad5b8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032113" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032114" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032115" comment="java-1_4_2-ibm less than 1.4.2_sr13-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20085346" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-5346</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-5346" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5346" source="CVE"/>
	<description>
	Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 or earlier allows untrusted applets and applications to read arbitrary memory via a crafted ZIP file.
	</description>
 </metadata>
<!-- 1113e80269ad51bda2997bfd043ad5b8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032113" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032114" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032115" comment="java-1_4_2-ibm less than 1.4.2_sr13-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20085348" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-5348</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-5348" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5348" source="CVE"/>
	<description>
	Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier, when using Kerberos authentication, allows remote attackers to cause a denial of service (OS resource consumption) via unknown vectors.
	</description>
 </metadata>
<!-- 1113e80269ad51bda2997bfd043ad5b8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032113" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032114" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032115" comment="java-1_4_2-ibm less than 1.4.2_sr13-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20085349" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-5349</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-5349" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5349" source="CVE"/>
	<description>
	Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier, and JDK and JRE 5.0 Update 16 and earlier, allows remote attackers to cause a denial of service (CPU consumption) via a crafted RSA public key.
	</description>
 </metadata>
<!-- d3ab7cbc3008183adb364cf6fbd6c4df -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009055058" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055059" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.1-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055060" comment="java-1_4_2-ibm less than 1.4.2_sr13.1-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20085350" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-5350</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-5350" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5350" source="CVE"/>
	<description>
	Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted applications and applets to list the contents of the operating user's directory via unknown vectors.
	</description>
 </metadata>
<!-- 1113e80269ad51bda2997bfd043ad5b8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032113" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032114" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032115" comment="java-1_4_2-ibm less than 1.4.2_sr13-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20085351" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-5351</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-5351" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5351" source="CVE"/>
	<description>
	Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier accepts UTF-8 encodings that are not the "shortest" form, which makes it easier for attackers to bypass protection mechanisms for other applications that rely on shortest-form UTF-8 encodings.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1113e80269ad51bda2997bfd043ad5b8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032113" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032114" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032115" comment="java-1_4_2-ibm less than 1.4.2_sr13-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 7d9a96f54ebbdea55cd9630e7b8de703 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032141" comment="java-1_6_0-ibm-alsa less than 1.6.0-124.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032142" comment="java-1_6_0-ibm-fonts less than 1.6.0-124.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032143" comment="java-1_6_0-ibm-jdbc less than 1.6.0-124.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032144" comment="java-1_6_0-ibm-plugin less than 1.6.0-124.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032145" comment="java-1_6_0-ibm less than 1.6.0-124.6.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20085353" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-5353</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-5353" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5353" source="CVE"/>
	<description>
	The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not properly enforce context of ZoneInfo objects during deserialization, which allows remote attackers to run untrusted applets and applications in a privileged context, as demonstrated by "deserializing Calendar objects".
	</description>
 </metadata>
<!-- 1113e80269ad51bda2997bfd043ad5b8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032113" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032114" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032115" comment="java-1_4_2-ibm less than 1.4.2_sr13-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20085354" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-5354</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-5354" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5354" source="CVE"/>
	<description>
	Stack-based buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows locally-launched and possibly remote untrusted Java applications to execute arbitrary code via a JAR file with a long Main-Class manifest entry.
	</description>
 </metadata>
<!-- 1113e80269ad51bda2997bfd043ad5b8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032113" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032114" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032115" comment="java-1_4_2-ibm less than 1.4.2_sr13-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20085356" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-5356</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-5356" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5356" source="CVE"/>
	<description>
	Heap-based buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier might allow remote attackers to execute arbitrary code via a crafted TrueType font file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1113e80269ad51bda2997bfd043ad5b8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032113" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032114" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032115" comment="java-1_4_2-ibm less than 1.4.2_sr13-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 7d9a96f54ebbdea55cd9630e7b8de703 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032141" comment="java-1_6_0-ibm-alsa less than 1.6.0-124.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032142" comment="java-1_6_0-ibm-fonts less than 1.6.0-124.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032143" comment="java-1_6_0-ibm-jdbc less than 1.6.0-124.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032144" comment="java-1_6_0-ibm-plugin less than 1.6.0-124.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032145" comment="java-1_6_0-ibm less than 1.6.0-124.6.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20085357" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-5357</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-5357" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5357" source="CVE"/>
	<description>
	Integer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier might allow remote attackers to execute arbitrary code via a crafted TrueType font file, which triggers a heap-based buffer overflow.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1113e80269ad51bda2997bfd043ad5b8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032113" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032114" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032115" comment="java-1_4_2-ibm less than 1.4.2_sr13-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 7d9a96f54ebbdea55cd9630e7b8de703 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032141" comment="java-1_6_0-ibm-alsa less than 1.6.0-124.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032142" comment="java-1_6_0-ibm-fonts less than 1.6.0-124.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032143" comment="java-1_6_0-ibm-jdbc less than 1.6.0-124.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032144" comment="java-1_6_0-ibm-plugin less than 1.6.0-124.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032145" comment="java-1_6_0-ibm less than 1.6.0-124.6.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20085358" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-5358</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-5358" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5358" source="CVE"/>
	<description>
	Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier might allow remote attackers to execute arbitrary code via a crafted GIF file that triggers memory corruption during display of the splash screen, possibly related to splashscreen.dll.
	</description>
 </metadata>
<!-- 7d9a96f54ebbdea55cd9630e7b8de703 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032141" comment="java-1_6_0-ibm-alsa less than 1.6.0-124.6.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032142" comment="java-1_6_0-ibm-fonts less than 1.6.0-124.6.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032143" comment="java-1_6_0-ibm-jdbc less than 1.6.0-124.6.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032144" comment="java-1_6_0-ibm-plugin less than 1.6.0-124.6.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032145" comment="java-1_6_0-ibm less than 1.6.0-124.6.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20085359" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-5359</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-5359" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5359" source="CVE"/>
	<description>
	Buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier might allow remote attackers to execute arbitrary code, related to a ConvolveOp operation in the Java AWT library.
	</description>
 </metadata>
<!-- 1113e80269ad51bda2997bfd043ad5b8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032113" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032114" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032115" comment="java-1_4_2-ibm less than 1.4.2_sr13-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20085360" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-5360</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-5360" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5360" source="CVE"/>
	<description>
	Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier creates temporary files with predictable file names, which allows attackers to write malicious JAR files via unknown vectors.
	</description>
 </metadata>
<!-- 1113e80269ad51bda2997bfd043ad5b8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032113" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032114" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032115" comment="java-1_4_2-ibm less than 1.4.2_sr13-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20085498" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-5498</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-5498" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5498" source="CVE"/>
	<description>
	Array index error in the imageRotate function in PHP 5.2.8 and earlier allows context-dependent attackers to read the contents of arbitrary memory locations via a crafted value of the third argument (aka the bgd_color or clrBack argument) for an indexed image.
	</description>
 </metadata>
<!-- d121477dd9cc7bfeaa1d7d8a6d824fa0 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032146" comment="apache2-mod_php5 less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032147" comment="php5-bcmath less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032148" comment="php5-bz2 less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032149" comment="php5-calendar less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032150" comment="php5-ctype less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032151" comment="php5-curl less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032152" comment="php5-dba less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032153" comment="php5-dbase less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032154" comment="php5-dom less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032155" comment="php5-exif less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032156" comment="php5-fastcgi less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032157" comment="php5-ftp less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032158" comment="php5-gd less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032159" comment="php5-gettext less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032160" comment="php5-gmp less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032161" comment="php5-hash less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032162" comment="php5-iconv less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032163" comment="php5-json less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032164" comment="php5-ldap less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032165" comment="php5-mbstring less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032166" comment="php5-mcrypt less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032167" comment="php5-mysql less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032168" comment="php5-odbc less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032169" comment="php5-openssl less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032170" comment="php5-pcntl less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032171" comment="php5-pdo less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032172" comment="php5-pear less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032173" comment="php5-pgsql less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032174" comment="php5-pspell less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032175" comment="php5-shmop less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032176" comment="php5-snmp less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032177" comment="php5-soap less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032178" comment="php5-suhosin less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032179" comment="php5-sysvmsg less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032180" comment="php5-sysvsem less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032181" comment="php5-sysvshm less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032182" comment="php5-tokenizer less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032183" comment="php5-wddx less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032184" comment="php5-xmlreader less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032185" comment="php5-xmlrpc less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032186" comment="php5-xmlwriter less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032187" comment="php5-xsl less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032188" comment="php5-zip less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032189" comment="php5-zlib less than 5.2.6-50.18.3"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20085518" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-5518</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-5518" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5518" source="CVE"/>
	<description>
	Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 on Windows allow remote attackers to upload files to arbitrary directories via directory traversal sequences in the (1) group, (2) artifact, (3) version, or (4) fileType parameter to console/portal//Services/Repository (aka the Services/Repository portlet); the (5) createDB parameter to console/portal/Embedded DB/DB Manager (aka the Embedded DB/DB Manager portlet); or the (6) filename parameter to the createKeystore script in the Security/Keystores portlet.
	</description>
 </metadata>
<!-- 1e030cf1aa564a63a9739f4894501a93 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053169" comment="websphere-as_ce less than 2.1.1.2-2.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053170" comment="websphere-as_ce less than 2.1.1.2-2.2"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20085624" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-5624</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-5624" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5624" source="CVE"/>
	<description>
	PHP 5 before 5.2.7 does not properly initialize the page_uid and page_gid global variables for use by the SAPI php_getuid function, which allows context-dependent attackers to bypass safe_mode restrictions via variable settings that are intended to be restricted to root, as demonstrated by a setting of /etc for the error_log variable.
	</description>
 </metadata>
<!-- bfb263e4c75cfb6dca1c2ee69633f369 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009058031" comment="apache2-mod_php5 less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058032" comment="php5-bcmath less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058033" comment="php5-bz2 less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058034" comment="php5-calendar less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058035" comment="php5-ctype less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058036" comment="php5-curl less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058037" comment="php5-dba less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058038" comment="php5-dbase less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058039" comment="php5-dom less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058040" comment="php5-exif less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058041" comment="php5-fastcgi less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058042" comment="php5-ftp less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058043" comment="php5-gd less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058044" comment="php5-gettext less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058045" comment="php5-gmp less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058046" comment="php5-hash less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058047" comment="php5-iconv less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058048" comment="php5-json less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058049" comment="php5-ldap less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058050" comment="php5-mbstring less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058051" comment="php5-mcrypt less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058052" comment="php5-mysql less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058053" comment="php5-odbc less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058054" comment="php5-openssl less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058055" comment="php5-pcntl less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058056" comment="php5-pdo less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058057" comment="php5-pear less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058058" comment="php5-pgsql less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058059" comment="php5-pspell less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058060" comment="php5-shmop less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058061" comment="php5-snmp less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058062" comment="php5-soap less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058063" comment="php5-suhosin less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058064" comment="php5-sysvmsg less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058065" comment="php5-sysvsem less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058066" comment="php5-sysvshm less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058067" comment="php5-tokenizer less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058068" comment="php5-wddx less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058069" comment="php5-xmlreader less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058070" comment="php5-xmlrpc less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058071" comment="php5-xmlwriter less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058072" comment="php5-xsl less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058073" comment="php5-zip less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058074" comment="php5-zlib less than 5.2.6-50.24.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20085625" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-5625</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-5625" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5625" source="CVE"/>
	<description>
	PHP 5 before 5.2.7 does not enforce the error_log safe_mode restrictions when safe_mode is enabled through a php_admin_flag setting in httpd.conf, which allows context-dependent attackers to write to arbitrary files by placing a "php_value error_log" entry in a .htaccess file.
	</description>
 </metadata>
<!-- bfb263e4c75cfb6dca1c2ee69633f369 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009058031" comment="apache2-mod_php5 less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058032" comment="php5-bcmath less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058033" comment="php5-bz2 less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058034" comment="php5-calendar less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058035" comment="php5-ctype less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058036" comment="php5-curl less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058037" comment="php5-dba less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058038" comment="php5-dbase less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058039" comment="php5-dom less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058040" comment="php5-exif less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058041" comment="php5-fastcgi less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058042" comment="php5-ftp less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058043" comment="php5-gd less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058044" comment="php5-gettext less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058045" comment="php5-gmp less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058046" comment="php5-hash less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058047" comment="php5-iconv less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058048" comment="php5-json less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058049" comment="php5-ldap less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058050" comment="php5-mbstring less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058051" comment="php5-mcrypt less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058052" comment="php5-mysql less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058053" comment="php5-odbc less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058054" comment="php5-openssl less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058055" comment="php5-pcntl less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058056" comment="php5-pdo less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058057" comment="php5-pear less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058058" comment="php5-pgsql less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058059" comment="php5-pspell less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058060" comment="php5-shmop less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058061" comment="php5-snmp less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058062" comment="php5-soap less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058063" comment="php5-suhosin less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058064" comment="php5-sysvmsg less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058065" comment="php5-sysvsem less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058066" comment="php5-sysvshm less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058067" comment="php5-tokenizer less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058068" comment="php5-wddx less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058069" comment="php5-xmlreader less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058070" comment="php5-xmlrpc less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058071" comment="php5-xmlwriter less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058072" comment="php5-xsl less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058073" comment="php5-zip less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058074" comment="php5-zlib less than 5.2.6-50.24.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20085814" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-5814</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-5814" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5814" source="CVE"/>
	<description>
	Cross-site scripting (XSS) vulnerability in PHP, possibly 5.2.7 and earlier, when display_errors is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: because of the lack of details, it is unclear whether this is related to CVE-2006-0208.
	</description>
 </metadata>
<!-- bfb263e4c75cfb6dca1c2ee69633f369 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009058031" comment="apache2-mod_php5 less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058032" comment="php5-bcmath less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058033" comment="php5-bz2 less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058034" comment="php5-calendar less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058035" comment="php5-ctype less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058036" comment="php5-curl less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058037" comment="php5-dba less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058038" comment="php5-dbase less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058039" comment="php5-dom less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058040" comment="php5-exif less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058041" comment="php5-fastcgi less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058042" comment="php5-ftp less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058043" comment="php5-gd less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058044" comment="php5-gettext less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058045" comment="php5-gmp less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058046" comment="php5-hash less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058047" comment="php5-iconv less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058048" comment="php5-json less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058049" comment="php5-ldap less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058050" comment="php5-mbstring less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058051" comment="php5-mcrypt less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058052" comment="php5-mysql less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058053" comment="php5-odbc less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058054" comment="php5-openssl less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058055" comment="php5-pcntl less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058056" comment="php5-pdo less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058057" comment="php5-pear less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058058" comment="php5-pgsql less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058059" comment="php5-pspell less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058060" comment="php5-shmop less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058061" comment="php5-snmp less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058062" comment="php5-soap less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058063" comment="php5-suhosin less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058064" comment="php5-sysvmsg less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058065" comment="php5-sysvsem less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058066" comment="php5-sysvshm less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058067" comment="php5-tokenizer less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058068" comment="php5-wddx less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058069" comment="php5-xmlreader less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058070" comment="php5-xmlrpc less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058071" comment="php5-xmlwriter less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058072" comment="php5-xsl less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058073" comment="php5-zip less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058074" comment="php5-zlib less than 5.2.6-50.24.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20085913" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-5913</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2008-5913" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5913" source="CVE"/>
	<description>
	The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses a random number generator that is seeded only once per browser session, which makes it easier for remote attackers to track a user, or trick a user into acting upon a spoofed pop-up message, by calculating the seed value, related to a "temporary footprint" and an "in-session phishing attack."
	</description>
 </metadata>
<!-- f9b2b1aaa535612c1bff26161e7cb381 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009061668" comment="MozillaFirefox-translations less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061192" comment="MozillaFirefox less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070643" comment="mozilla-xulrunner191-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070644" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061669" comment="mozilla-xulrunner191-translations less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070645" comment="mozilla-xulrunner191-x86 less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061670" comment="mozilla-xulrunner191 less than 1.9.1.10-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20086218" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-6218</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for Teradata</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2008-6218" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-6218" source="CVE"/>
	<description>
	Memory leak in the png_handle_tEXt function in pngrutil.c in libpng before 1.2.33 rc02 and 1.4.0 beta36 allows context-dependent attackers to cause a denial of service (memory exhaustion) via a crafted PNG file.
	</description>
 </metadata>
<!-- 5b292f48bbbe6202317380a339315fad -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009069805" comment="libpng12-0-32bit less than 1.2.31-5.25.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009069806" comment="libpng12-0-x86 less than 1.2.31-5.25.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009069807" comment="libpng12-0 less than 1.2.31-5.25.1"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009069805" comment="libpng12-0-32bit less than 1.2.31-5.25.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009069807" comment="libpng12-0 less than 1.2.31-5.25.1"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20086679" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-6679</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-6679" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-6679" source="CVE"/>
	<description>
	Buffer overflow in the BaseFont writer module in Ghostscript 8.62, and possibly other versions, allows remote attackers to cause a denial of service (ps2pdf crash) and possibly execute arbitrary code via a crafted Postscript file.
	</description>
 </metadata>
<!-- ab7a3ecdd7f2b22db74d66fd6e23832b -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032106" comment="ghostscript-fonts-other less than 8.62-32.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032107" comment="ghostscript-fonts-rus less than 8.62-32.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032108" comment="ghostscript-fonts-std less than 8.62-32.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032109" comment="ghostscript-library less than 8.62-32.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032110" comment="ghostscript-omni less than 8.62-32.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032111" comment="ghostscript-x11 less than 8.62-32.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032112" comment="libgimpprint less than 4.2.7-32.25.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20086680" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-6680</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-6680" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-6680" source="CVE"/>
	<description>
	libclamav/pe.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (crash) via a crafted EXE file that triggers a divide-by-zero error.
	</description>
 </metadata>
<!-- e036f8c1ee8c76653c4e246982056c02 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032190" comment="clamav less than 0.95-0.2.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20087247" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-7247</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2008-7247" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-7247" source="CVE"/>
	<description>
	sql/sql_table.cc in MySQL 5.0.x through 5.0.88, 5.1.x through 5.1.41, and 6.0 before 6.0.9-alpha, when the data home directory contains a symlink to a different filesystem, allows remote authenticated users to bypass intended access restrictions by calling CREATE TABLE with a (1) DATA DIRECTORY or (2) INDEX DIRECTORY argument referring to a subdirectory that requires following this symlink.
	</description>
 </metadata>
<!-- 920486ef8624fdf8d628849a50561aa6 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060043" comment="libmysqlclient15-32bit less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060044" comment="libmysqlclient15-x86 less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060045" comment="libmysqlclient15 less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060046" comment="libmysqlclient_r15 less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060047" comment="mysql-Max less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060048" comment="mysql-client less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060049" comment="mysql less than 5.0.67-13.17.7"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20087270" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2008-7270</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2008-7270" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-7270" source="CVE"/>
	<description>
	OpenSSL before 0.9.8j, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the use of a disabled cipher via vectors involving sniffing network traffic to discover a session identifier, a different vulnerability than CVE-2010-4180.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- b2240bd1cc1b86d466bf4511cb5287fd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064298" comment="libopenssl0_9_8-32bit less than 0.9.8h-30.22.22.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064299" comment="libopenssl0_9_8-x86 less than 0.9.8h-30.22.22.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064300" comment="libopenssl0_9_8 less than 0.9.8h-30.22.22.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064301" comment="openssl-doc less than 0.9.8h-30.22.22.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064302" comment="openssl less than 0.9.8h-30.22.22.1"/>
		</criteria>
	</criteria>
	<!-- d4275070c6d35e2cd6ce91e877bc91e7 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064303" comment="libopenssl0_9_8-32bit less than 0.9.8h-30.28.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064304" comment="libopenssl0_9_8-x86 less than 0.9.8h-30.28.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064305" comment="libopenssl0_9_8 less than 0.9.8h-30.28.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064306" comment="openssl-doc less than 0.9.8h-30.28.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064307" comment="openssl less than 0.9.8h-30.28.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064303" comment="libopenssl0_9_8-32bit less than 0.9.8h-30.28.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064305" comment="libopenssl0_9_8 less than 0.9.8h-30.28.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064306" comment="openssl-doc less than 0.9.8h-30.28.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064307" comment="openssl less than 0.9.8h-30.28.1"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090023" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0023</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0023" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0023" source="CVE"/>
	<description>
	The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive in the mod_dav_svn module in the Apache HTTP Server, (3) the mod_apreq2 module for the Apache HTTP Server, or (4) an application that uses the libapreq2 library, which triggers a heap-based buffer underflow.
	</description>
 </metadata>
<!-- 251e677d425d0b40e5a4c63e49b53955 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053393" comment="libapr-util1-32bit less than 1.3.4-12.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053394" comment="libapr-util1 less than 1.3.4-12.19.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090037" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0037</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0037" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0037" source="CVE"/>
	<description>
	The redirect implementation in curl and libcurl 5.11 through 7.19.3, when CURLOPT_FOLLOWLOCATION is enabled, accepts arbitrary Location values, which might allow remote HTTP servers to (1) trigger arbitrary requests to intranet servers, (2) read or overwrite arbitrary files via a redirect to a file: URL, or (3) execute arbitrary commands via a redirect to an scp: URL.
	</description>
 </metadata>
<!-- 4b5434075393861d396c976f9f14744f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032191" comment="curl less than 7.19.0-11.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032192" comment="libcurl4-32bit less than 7.19.0-11.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032193" comment="libcurl4-x86 less than 7.19.0-11.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032194" comment="libcurl4 less than 7.19.0-11.21.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090038" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0038</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0038" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0038" source="CVE"/>
	<description>
	Multiple cross-site scripting (XSS) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) ip, (3) username, or (4) description parameter to console/portal/Server/Monitoring; or (5) the PATH_INFO to the default URI under console/portal/.
	</description>
 </metadata>
<!-- 1e030cf1aa564a63a9739f4894501a93 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053169" comment="websphere-as_ce less than 2.1.1.2-2.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053170" comment="websphere-as_ce less than 2.1.1.2-2.2"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090039" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0039</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0039" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0039" source="CVE"/>
	<description>
	Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to hijack the authentication of administrators for requests that (1) change the web administration password, (2) upload applications, and perform unspecified other administrative actions, as demonstrated by (3) a Shutdown request to console/portal//Server/Shutdown.
	</description>
 </metadata>
<!-- 1e030cf1aa564a63a9739f4894501a93 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053169" comment="websphere-as_ce less than 2.1.1.2-2.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053170" comment="websphere-as_ce less than 2.1.1.2-2.2"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090040" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0040</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0040" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0040" source="CVE"/>
	<description>
	The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file that triggers a free of an uninitialized pointer in (1) the png_read_png function, (2) pCAL chunk handling, or (3) setup of 16-bit gamma tables.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 533cd9a6d7b1cabc1aceb3ab6070dba5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032195" comment="libpng12-0-32bit less than 1.2.31-5.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032196" comment="libpng12-0-x86 less than 1.2.31-5.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032197" comment="libpng12-0 less than 1.2.31-5.11.1"/>
		</criteria>
	</criteria>
	<!-- 64ea6139df28e916c5f627ff6f4b6b83 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032198" comment="MozillaFirefox-translations less than 3.0.7-1.1.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032199" comment="MozillaFirefox less than 3.0.7-1.1.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032200" comment="mozilla-xulrunner190-32bit less than 1.9.0.7-1.1.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032201" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.7-1.1.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032202" comment="mozilla-xulrunner190-translations less than 1.9.0.7-1.1.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032203" comment="mozilla-xulrunner190-x86 less than 1.9.0.7-1.1.4"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032204" comment="mozilla-xulrunner190 less than 1.9.0.7-1.1.4"/>
		</criteria>
	</criteria>
	<!-- 652fce5693522ba240a0007464788f7d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032205" comment="libpng12-0-32bit less than 1.2.31-7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032206" comment="libpng12-0-x86 less than 1.2.31-7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032207" comment="libpng12-0 less than 1.2.31-7.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090146" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0146</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0146" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0146" source="CVE"/>
	<description>
	Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2SymbolDict::setBitmap and (2) JBIG2Stream::readSymbolDictSeg.
	</description>
 </metadata>
<!-- f27d99aa7f35ddbc6bc5e4ac681ee974 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032208" comment="libpoppler4 less than 0.10.1-1.30.5"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090147" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0147</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0147" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0147" source="CVE"/>
	<description>
	Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2Stream::readSymbolDictSeg, (2) JBIG2Stream::readSymbolDictSeg, and (3) JBIG2Stream::readGenericBitmap.
	</description>
 </metadata>
<!-- f27d99aa7f35ddbc6bc5e4ac681ee974 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032208" comment="libpoppler4 less than 0.10.1-1.30.5"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090153" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0153</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0153" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0153" source="CVE"/>
	<description>
	International Components for Unicode (ICU) 4.0, 3.6, and other 3.x versions, as used in Apple Mac OS X 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Fedora 9 and 10, and possibly other operating systems, does not properly handle invalid byte sequences during Unicode conversion, which might allow remote attackers to conduct cross-site scripting (XSS) attacks.
	</description>
 </metadata>
<!-- 563cdc75b14ef0a824e09ace54d4dfac -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053691" comment="libicu-32bit less than 4.0-7.22.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053692" comment="libicu-doc less than 4.0-7.22.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053693" comment="libicu less than 4.0-7.22.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090159" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0159</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0159" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0159" source="CVE"/>
	<description>
	Stack-based buffer overflow in the cookedprint function in ntpq/ntpq.c in ntpq in NTP before 4.2.4p7-RC2 allows remote NTP servers to execute arbitrary code via a crafted response.
	</description>
 </metadata>
<!-- d95ed4c45d984fda65f18722242769a5 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032209" comment="ntp-doc less than 4.2.4p6-1.17.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032210" comment="ntp less than 4.2.4p6-1.17.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090163" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0163</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0163" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0163" source="CVE"/>
	<description>
	Integer overflow in the TIFF image decoding routines in CUPS 1.3.9 and earlier allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a crafted TIFF image, which is not properly handled by the (1) _cupsImageReadTIFF function in the imagetops filter and (2) imagetoraster filter, leading to a heap-based buffer overflow.
	</description>
 </metadata>
<!-- 22d7a0746f9c204f5ecc1395385739f7 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032211" comment="cups-client less than 1.3.9-8.15.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032212" comment="cups-libs-32bit less than 1.3.9-8.15.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032213" comment="cups-libs-x86 less than 1.3.9-8.15.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032214" comment="cups-libs less than 1.3.9-8.15.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032215" comment="cups less than 1.3.9-8.15.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090165" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0165</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0165" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0165" source="CVE"/>
	<description>
	Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, as used in Poppler and other products, when running on Mac OS X, has unspecified impact, related to "g*allocn."
	</description>
 </metadata>
<!-- f27d99aa7f35ddbc6bc5e4ac681ee974 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032208" comment="libpoppler4 less than 0.10.1-1.30.5"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090166" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0166</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0166" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0166" source="CVE"/>
	<description>
	The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a free of uninitialized memory.
	</description>
 </metadata>
<!-- f27d99aa7f35ddbc6bc5e4ac681ee974 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032208" comment="libpoppler4 less than 0.10.1-1.30.5"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090186" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0186</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0186" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0186" source="CVE"/>
	<description>
	Integer overflow in libsndfile 1.0.18, as used in Winamp and other products, allows context-dependent attackers to execute arbitrary code via crafted description chunks in a CAF audio file, leading to a heap-based buffer overflow.
	</description>
 </metadata>
<!-- b9a52ff0fc093ef2c5d7b985b5d8445a -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032216" comment="libsndfile-32bit less than 1.0.17-172.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032217" comment="libsndfile-x86 less than 1.0.17-172.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032218" comment="libsndfile less than 1.0.17-172.13.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090196" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0196</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0196" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0196" source="CVE"/>
	<description>
	Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol_dict.c) in the JBIG2 decoding library (jbig2dec) in Ghostscript 8.64, and probably earlier versions, allows remote attackers to execute arbitrary code via a PDF file with a JBIG2 symbol dictionary segment with a large run length value.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 821fdfa281de6b75cdc24c1e4f935e7e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032219" comment="ghostscript-fonts-other less than 8.62-32.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032220" comment="ghostscript-fonts-rus less than 8.62-32.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032221" comment="ghostscript-fonts-std less than 8.62-32.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032222" comment="ghostscript-library less than 8.62-32.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032223" comment="ghostscript-omni less than 8.62-32.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032224" comment="ghostscript-x11 less than 8.62-32.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032225" comment="libgimpprint less than 4.2.7-32.23.1"/>
		</criteria>
	</criteria>
	<!-- ab7a3ecdd7f2b22db74d66fd6e23832b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032106" comment="ghostscript-fonts-other less than 8.62-32.25.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032107" comment="ghostscript-fonts-rus less than 8.62-32.25.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032108" comment="ghostscript-fonts-std less than 8.62-32.25.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032109" comment="ghostscript-library less than 8.62-32.25.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032110" comment="ghostscript-omni less than 8.62-32.25.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032111" comment="ghostscript-x11 less than 8.62-32.25.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032112" comment="libgimpprint less than 4.2.7-32.25.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090217" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0217</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0217" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0217" source="CVE"/>
	<description>
	The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.2; (4) XML Security Library before 1.2.12; (5) IBM WebSphere Application Server Versions 6.0 through 6.0.2.33, 6.1 through 6.1.0.23, and 7.0 through 7.0.0.1; (6) Sun JDK and JRE Update 14 and earlier; (7) Microsoft .NET Framework 3.0 through 3.0 SP2, 3.5, and 4.0; and other products uses a parameter that defines an HMAC truncation length (HMACOutputLength) but does not require a minimum for this length, which allows attackers to spoof HMAC-based signatures and bypass authentication by specifying a truncation length with a small number of bits.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 27428b62b5ccd6ac2929bae4bea6f2dd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056019" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056020" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056021" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056022" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056023" comment="java-1_6_0-ibm less than 1.6.0_sr6-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 39e43680df27683c7e496d57e45f7060 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057184" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057185" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057186" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057187" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057188" comment="java-1_6_0-ibm less than 1.6.0_sr7.0-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090365" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0365</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0365" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0365" source="CVE"/>
	<description>
	nm-applet.conf in GNOME NetworkManager before 0.7.0.99 contains an incorrect deny setting, which allows local users to discover (1) network connection passwords and (2) pre-shared keys via calls to the GetSecrets method in the dbus request handler.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2ea93e592a2bf790a1f60781d2f5f480 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032226" comment="NetworkManager-glib less than 0.7.0.r4359-15.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032227" comment="NetworkManager less than 0.7.0.r4359-15.1"/>
		</criteria>
	</criteria>
	<!-- 370c86c183ea8f4fcc6f26ff78c1fda2 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032228" comment="NetworkManager-glib less than 0.7.0.r4359-15.9.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032229" comment="NetworkManager less than 0.7.0.r4359-15.9.2"/>
		</criteria>
	</criteria>
	<!-- 9f38610f6d41c74c097b899f66ccd986 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032230" comment="NetworkManager-gnome less than 0.7.0.r1053-11.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090368" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0368</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0368" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0368" source="CVE"/>
	<description>
	OpenSC before 0.11.7 allows physically proximate attackers to bypass intended PIN requirements and read private data objects via a (1) low level APDU command or (2) debugging tool, as demonstrated by reading the 4601 or 4701 file with the opensc-explorer or opensc-tool program.
	</description>
 </metadata>
<!-- f428517b5568622c232d45f50621c1f0 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032231" comment="libopensc2-32bit less than 0.11.6-5.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032232" comment="libopensc2-x86 less than 0.11.6-5.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032233" comment="libopensc2 less than 0.11.6-5.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032234" comment="opensc-32bit less than 0.11.6-5.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032235" comment="opensc-x86 less than 0.11.6-5.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032236" comment="opensc less than 0.11.6-5.25.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090547" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0547</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0547" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0547" source="CVE"/>
	<description>
	Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text within a signed-data blob, not the copy of the e-mail text displayed to the user, which allows remote attackers to spoof a signature by modifying the latter copy, a different vulnerability than CVE-2008-5077.
	</description>
 </metadata>
<!-- c7c8e33671ac7994fac1b1913560d9bd -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009058657" comment="evolution-data-server-32bit less than 2.24.1.1-11.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058658" comment="evolution-data-server-lang less than 2.24.1.1-11.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058659" comment="evolution-data-server-x86 less than 2.24.1.1-11.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058660" comment="evolution-data-server less than 2.24.1.1-11.12.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090578" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0578</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0578" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0578" source="CVE"/>
	<description>
	GNOME NetworkManager before 0.7.0.99 does not properly verify privileges for dbus (1) modify and (2) delete requests, which allows local users to change or remove the network connections of arbitrary users via unspecified vectors related to org.freedesktop.NetworkManagerUserSettings and at_console.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2ea93e592a2bf790a1f60781d2f5f480 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032226" comment="NetworkManager-glib less than 0.7.0.r4359-15.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032227" comment="NetworkManager less than 0.7.0.r4359-15.1"/>
		</criteria>
	</criteria>
	<!-- 370c86c183ea8f4fcc6f26ff78c1fda2 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032228" comment="NetworkManager-glib less than 0.7.0.r4359-15.9.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032229" comment="NetworkManager less than 0.7.0.r4359-15.9.2"/>
		</criteria>
	</criteria>
	<!-- 9f38610f6d41c74c097b899f66ccd986 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032230" comment="NetworkManager-gnome less than 0.7.0.r1053-11.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090581" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0581</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0581" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0581" source="CVE"/>
	<description>
	Memory leak in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allows context-dependent attackers to cause a denial of service (memory consumption and application crash) via a crafted image file.
	</description>
 </metadata>
<!-- ebee4d79b9b0e20a4c4571ee016948ba -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032237" comment="lcms less than 1.17-77.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032238" comment="liblcms1-32bit less than 1.17-77.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032239" comment="liblcms1-x86 less than 1.17-77.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032240" comment="liblcms1 less than 1.17-77.12.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090582" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0582</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0582" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0582" source="CVE"/>
	<description>
	The ntlm_challenge function in the NTLM SASL authentication mechanism in camel/camel-sasl-ntlm.c in Camel in Evolution Data Server (aka evolution-data-server) 2.24.5 and earlier, and 2.25.92 and earlier 2.25.x versions, does not validate whether a certain length value is consistent with the amount of data in a challenge packet, which allows remote mail servers to read information from the process memory of a client, or cause a denial of service (client crash), via an NTLM authentication type 2 packet with a length value that exceeds the amount of packet data.
	</description>
 </metadata>
<!-- fe91f45fff42c9cf641b26e271a0e279 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032241" comment="evolution-data-server-32bit less than 2.24.1.1-11.8.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032242" comment="evolution-data-server-lang less than 2.24.1.1-11.8.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032243" comment="evolution-data-server-x86 less than 2.24.1.1-11.8.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032244" comment="evolution-data-server less than 2.24.1.1-11.8.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032245" comment="gtkhtml2-lang less than 3.24.1.1-3.23.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032246" comment="gtkhtml2 less than 3.24.1.1-3.23.2"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090583" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0583</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0583" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0583" source="CVE"/>
	<description>
	Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.
	</description>
 </metadata>
<!-- cdf7326a6fdf5b963b028d581e2fa57a -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032247" comment="ghostscript-fonts-other less than 8.62-32.22.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032248" comment="ghostscript-fonts-rus less than 8.62-32.22.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032249" comment="ghostscript-fonts-std less than 8.62-32.22.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032250" comment="ghostscript-library less than 8.62-32.22.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032251" comment="ghostscript-omni less than 8.62-32.22.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032252" comment="ghostscript-x11 less than 8.62-32.22.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032253" comment="libgimpprint less than 4.2.7-32.22.2"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090584" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0584</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0584" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0584" source="CVE"/>
	<description>
	icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code by using a device file for processing a crafted image file associated with large integer values for certain sizes, related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.
	</description>
 </metadata>
<!-- cdf7326a6fdf5b963b028d581e2fa57a -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032247" comment="ghostscript-fonts-other less than 8.62-32.22.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032248" comment="ghostscript-fonts-rus less than 8.62-32.22.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032249" comment="ghostscript-fonts-std less than 8.62-32.22.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032250" comment="ghostscript-library less than 8.62-32.22.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032251" comment="ghostscript-omni less than 8.62-32.22.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032252" comment="ghostscript-x11 less than 8.62-32.22.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032253" comment="libgimpprint less than 4.2.7-32.22.2"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090586" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0586</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0586" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0586" source="CVE"/>
	<description>
	Integer overflow in the gst_vorbis_tag_add_coverart function (gst-libs/gst/tag/gstvorbistag.c) in vorbistag in gst-plugins-base (aka gstreamer-plugins-base) before 0.10.23 in GStreamer allows context-dependent attackers to execute arbitrary code via a crafted COVERART tag that is converted from a base64 representation, which triggers a heap-based buffer overflow.
	</description>
 </metadata>
<!-- 7f766637f1633ea89ce72f52ede1a845 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032254" comment="gstreamer-0_10-plugins-base-32bit less than 0.10.21-2.36.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032255" comment="gstreamer-0_10-plugins-base-doc less than 0.10.21-2.36.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032256" comment="gstreamer-0_10-plugins-base-lang less than 0.10.21-2.36.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032257" comment="gstreamer-0_10-plugins-base-x86 less than 0.10.21-2.36.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032258" comment="gstreamer-0_10-plugins-base less than 0.10.21-2.36.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032259" comment="libgstinterfaces-0_10-0-32bit less than 0.10.21-2.36.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032260" comment="libgstinterfaces-0_10-0-x86 less than 0.10.21-2.36.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032261" comment="libgstinterfaces-0_10-0 less than 0.10.21-2.36.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090587" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0587</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0587" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0587" source="CVE"/>
	<description>
	Multiple integer overflows in Evolution Data Server (aka evolution-data-server) before 2.24.5 allow context-dependent attackers to execute arbitrary code via a long string that is converted to a base64 representation in (1) addressbook/libebook/e-vcard.c in evc or (2) camel/camel-mime-utils.c in libcamel.
	</description>
 </metadata>
<!-- c7c8e33671ac7994fac1b1913560d9bd -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009058657" comment="evolution-data-server-32bit less than 2.24.1.1-11.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058658" comment="evolution-data-server-lang less than 2.24.1.1-11.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058659" comment="evolution-data-server-x86 less than 2.24.1.1-11.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058660" comment="evolution-data-server less than 2.24.1.1-11.12.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090590" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0590</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0590" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0590" source="CVE"/>
	<description>
	The ASN1_STRING_print_ex function in OpenSSL before 0.9.8k allows remote attackers to cause a denial of service (invalid memory access and application crash) via vectors that trigger printing of a (1) BMPString or (2) UniversalString with an invalid encoded length.
	</description>
 </metadata>
<!-- 2f80f91b648dcd2ec32e230ff4cf94b5 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032262" comment="libopenssl0_9_8-32bit less than 0.9.8h-30.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032263" comment="libopenssl0_9_8-x86 less than 0.9.8h-30.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032264" comment="libopenssl0_9_8 less than 0.9.8h-30.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032265" comment="openssl-doc less than 0.9.8h-30.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032266" comment="openssl less than 0.9.8h-30.12.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090591" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0591</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0591" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0591" source="CVE"/>
	<description>
	The CMS_verify function in OpenSSL 0.9.8h through 0.9.8j, when CMS is enabled, does not properly handle errors associated with malformed signed attributes, which allows remote attackers to repudiate a signature that originally appeared to be valid but was actually invalid.
	</description>
 </metadata>
<!-- 2f80f91b648dcd2ec32e230ff4cf94b5 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032262" comment="libopenssl0_9_8-32bit less than 0.9.8h-30.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032263" comment="libopenssl0_9_8-x86 less than 0.9.8h-30.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032264" comment="libopenssl0_9_8 less than 0.9.8h-30.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032265" comment="openssl-doc less than 0.9.8h-30.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032266" comment="openssl less than 0.9.8h-30.12.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090642" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0642</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0642" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0642" source="CVE"/>
	<description>
	ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check the return value from the OCSP_basic_verify function, which might allow remote attackers to successfully present an invalid X.509 certificate, possibly involving a revoked certificate.
	</description>
 </metadata>
<!-- c8369586b31bf86da2231acd00ad8f78 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053192" comment="ruby-doc-html less than 1.8.7.p72-5.22.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053193" comment="ruby-tk less than 1.8.7.p72-5.22.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053194" comment="ruby less than 1.8.7.p72-5.22.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090652" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0652</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0652" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0652" source="CVE"/>
	<description>
	The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird before 2.0.0.21; and SeaMonkey before 1.1.15 does not include box-drawing characters, which allows remote attackers to spoof URLs and conduct phishing attacks, as demonstrated by homoglyphs of the / (slash) and ? (question mark) characters in a subdomain of a .cn domain name, a different vulnerability than CVE-2005-0233.  NOTE: some third parties claim that 3.0.6 is not affected, but much older versions perhaps are affected.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8d58759fa070160f1f7d27df1de3a166 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032267" comment="MozillaFirefox-translations less than 3.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032268" comment="MozillaFirefox less than 3.0.9-0.1.1"/>
		</criteria>
	</criteria>
	<!-- fab01148f9c2f94e57e7070118a7818e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032269" comment="mozilla-xulrunner190-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032270" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032271" comment="mozilla-xulrunner190-translations less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032272" comment="mozilla-xulrunner190-x86 less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032273" comment="mozilla-xulrunner190 less than 1.9.0.9-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090676" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0676</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0676" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0676" source="CVE"/>
	<description>
	The sock_getsockopt function in net/core/sock.c in the Linux kernel before 2.6.28.6 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel memory via an SO_BSDCOMPAT getsockopt request.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 40623e2603f46ef0bf4615d7d469eb26 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032274" comment="ext4dev-kmp-default less than 0_2.6.27.21_0.1-7.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032275" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.21_0.1-7.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032276" comment="kernel-default-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032277" comment="kernel-default less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032278" comment="kernel-kdump less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032279" comment="kernel-ppc64-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032280" comment="kernel-ppc64 less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032281" comment="kernel-source less than 2.6.27.21-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032282" comment="kernel-syms less than 2.6.27.21-0.1.2"/>
		</criteria>
	</criteria>
	<!-- 811ee372cc49e0ad64c32f8cf2267192 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032274" comment="ext4dev-kmp-default less than 0_2.6.27.21_0.1-7.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032276" comment="kernel-default-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032277" comment="kernel-default less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032281" comment="kernel-source less than 2.6.27.21-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032282" comment="kernel-syms less than 2.6.27.21-0.1.2"/>
		</criteria>
	</criteria>
	<!-- 8987accc22406eeb83098eded271c9af -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032274" comment="ext4dev-kmp-default less than 0_2.6.27.21_0.1-7.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032276" comment="kernel-default-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032283" comment="kernel-default-man less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032277" comment="kernel-default less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032281" comment="kernel-source less than 2.6.27.21-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032282" comment="kernel-syms less than 2.6.27.21-0.1.2"/>
		</criteria>
	</criteria>
	<!-- 8b684f8048b88ef832b80e585ff96805 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032274" comment="ext4dev-kmp-default less than 0_2.6.27.21_0.1-7.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032284" comment="ext4dev-kmp-xen less than 0_2.6.27.21_0.1-7.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032276" comment="kernel-default-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032277" comment="kernel-default less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032281" comment="kernel-source less than 2.6.27.21-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032282" comment="kernel-syms less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032285" comment="kernel-xen-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032286" comment="kernel-xen less than 2.6.27.21-0.1.2"/>
		</criteria>
	</criteria>
	<!-- ab571c76de3bf9c7bafb83437a2d83aa -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032274" comment="ext4dev-kmp-default less than 0_2.6.27.21_0.1-7.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032287" comment="ext4dev-kmp-pae less than 0_2.6.27.21_0.1-7.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032288" comment="ext4dev-kmp-vmi less than 0_2.6.27.21_0.1-7.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032284" comment="ext4dev-kmp-xen less than 0_2.6.27.21_0.1-7.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032276" comment="kernel-default-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032277" comment="kernel-default less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032289" comment="kernel-pae-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032290" comment="kernel-pae less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032281" comment="kernel-source less than 2.6.27.21-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032282" comment="kernel-syms less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032291" comment="kernel-vmi-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032292" comment="kernel-vmi less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032285" comment="kernel-xen-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032286" comment="kernel-xen less than 2.6.27.21-0.1.2"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090688" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0688</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0688" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0688" source="CVE"/>
	<description>
	Multiple buffer overflows in the CMU Cyrus SASL library before 2.1.23 might allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via strings that are used as input to the sasl_encode64 function in lib/saslutil.c.
	</description>
 </metadata>
<!-- 381af186b7a4cd4e07f677ae4bb568f8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032293" comment="cyrus-sasl-32bit less than 2.1.22-182.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032294" comment="cyrus-sasl-crammd5-32bit less than 2.1.22-182.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032295" comment="cyrus-sasl-crammd5-x86 less than 2.1.22-182.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032296" comment="cyrus-sasl-crammd5 less than 2.1.22-182.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032297" comment="cyrus-sasl-digestmd5 less than 2.1.22-182.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032298" comment="cyrus-sasl-gssapi-32bit less than 2.1.22-182.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032299" comment="cyrus-sasl-gssapi-x86 less than 2.1.22-182.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032300" comment="cyrus-sasl-gssapi less than 2.1.22-182.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032301" comment="cyrus-sasl-otp-32bit less than 2.1.22-182.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032302" comment="cyrus-sasl-otp-x86 less than 2.1.22-182.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032303" comment="cyrus-sasl-otp less than 2.1.22-182.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032304" comment="cyrus-sasl-plain-32bit less than 2.1.22-182.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032305" comment="cyrus-sasl-plain-x86 less than 2.1.22-182.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032306" comment="cyrus-sasl-plain less than 2.1.22-182.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032307" comment="cyrus-sasl-x86 less than 2.1.22-182.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032308" comment="cyrus-sasl less than 2.1.22-182.20.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090689" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0689</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0689" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0689" source="CVE"/>
	<description>
	Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD 4.5, Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4, K-Meleon 1.5.3, SeaMonkey 1.1.8, and other products, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large precision value in the format argument to a printf function, which triggers incorrect memory allocation and a heap-based buffer overflow during conversion to a floating-point number.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04c6e38838a85fc92531b3e56904b052 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055940" comment="mozilla-xulrunner190-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055941" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055942" comment="mozilla-xulrunner190-translations less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055943" comment="mozilla-xulrunner190-x86 less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055944" comment="mozilla-xulrunner190 less than 1.9.0.15-0.1.2"/>
		</criteria>
	</criteria>
	<!-- 0bf04a4aa83105c91a9211d8cc21a404 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057158" comment="kdelibs4-core less than 4.1.3-8.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057159" comment="kdelibs4 less than 4.1.3-8.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057160" comment="libkde4-32bit less than 4.1.3-8.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057161" comment="libkde4-x86 less than 4.1.3-8.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057162" comment="libkde4 less than 4.1.3-8.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057163" comment="libkdecore4-32bit less than 4.1.3-8.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057164" comment="libkdecore4-x86 less than 4.1.3-8.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057165" comment="libkdecore4 less than 4.1.3-8.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057166" comment="utempter-32bit less than 0.5.5-106.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057167" comment="utempter-x86 less than 0.5.5-106.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057168" comment="utempter less than 0.5.5-106.18"/>
		</criteria>
	</criteria>
	<!-- 49179a9289fbe778bc2320690c17d088 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055945" comment="MozillaFirefox-translations less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055946" comment="MozillaFirefox less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055947" comment="mozilla-xulrunner191-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055948" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055949" comment="mozilla-xulrunner191-translations less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055950" comment="mozilla-xulrunner191-x86 less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055951" comment="mozilla-xulrunner191 less than 1.9.1.4-2.1.3"/>
		</criteria>
	</criteria>
	<!-- 5d7c99e519a95f9108d35c51b0c854c5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056564" comment="kdelibs3-32bit less than 3.5.10-23.27.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056565" comment="kdelibs3-default-style-32bit less than 3.5.10-23.27.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056566" comment="kdelibs3-default-style-x86 less than 3.5.10-23.27.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056567" comment="kdelibs3-default-style less than 3.5.10-23.27.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056568" comment="kdelibs3-x86 less than 3.5.10-23.27.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056569" comment="kdelibs3 less than 3.5.10-23.27.1"/>
		</criteria>
	</criteria>
	<!-- ea83feacee19ffa926f0205c68b1bb6b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056065" comment="mozilla-nspr-32bit less than 4.8.2-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056066" comment="mozilla-nspr-x86 less than 4.8.2-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056067" comment="mozilla-nspr less than 4.8.2-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090692" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0692</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0692" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0692" source="CVE"/>
	<description>
	Stack-based buffer overflow in the script_write_params method in client/dhclient.c in ISC DHCP dhclient 4.1 before 4.1.0p1, 4.0 before 4.0.1p1, 3.1 before 3.1.2p1, 3.0, and 2.0 allows remote DHCP servers to execute arbitrary code via a crafted subnet-mask option.
	</description>
 </metadata>
<!-- 8344cd148acb6a76268d2b1462cf9a03 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053395" comment="dhcp-client less than 3.1.1-7.13.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090696" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0696</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0696" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0696" source="CVE"/>
	<description>
	The dns_db_findrdataset function in db.c in named in ISC BIND 9.4 before 9.4.3-P3, 9.5 before 9.5.1-P3, and 9.6 before 9.6.1-P1, when configured as a master server, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an ANY record in the prerequisite section of a crafted dynamic update message, as exploited in the wild in July 2009.
	</description>
 </metadata>
<!-- 2effd341d6971e49515add75df350e14 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053620" comment="bind-chrootenv less than 9.5.0P2-20.3.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053621" comment="bind-doc less than 9.5.0P2-20.3.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053622" comment="bind-libs-32bit less than 9.5.0P2-20.3.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053623" comment="bind-libs-x86 less than 9.5.0P2-20.3.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053624" comment="bind-libs less than 9.5.0P2-20.3.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053625" comment="bind-utils less than 9.5.0P2-20.3.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053626" comment="bind less than 9.5.0P2-20.3.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090723" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0723</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0723" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0723" source="CVE"/>
	<description>
	Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow.  NOTE: some of these details are obtained from third party information.
	</description>
 </metadata>
<!-- ebee4d79b9b0e20a4c4571ee016948ba -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032237" comment="lcms less than 1.17-77.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032238" comment="liblcms1-32bit less than 1.17-77.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032239" comment="liblcms1-x86 less than 1.17-77.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032240" comment="liblcms1 less than 1.17-77.12.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090733" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0733</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0733" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0733" source="CVE"/>
	<description>
	Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file associated with a large integer value for the (1) input or (2) output channel, related to the ReadLUT_A2B and ReadLUT_B2A functions.
	</description>
 </metadata>
<!-- ebee4d79b9b0e20a4c4571ee016948ba -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032237" comment="lcms less than 1.17-77.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032238" comment="liblcms1-32bit less than 1.17-77.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032239" comment="liblcms1-x86 less than 1.17-77.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032240" comment="liblcms1 less than 1.17-77.12.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090754" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0754</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0754" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0754" source="CVE"/>
	<description>
	PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to other virtual hosts on the same server.
	</description>
 </metadata>
<!-- d121477dd9cc7bfeaa1d7d8a6d824fa0 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032146" comment="apache2-mod_php5 less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032147" comment="php5-bcmath less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032148" comment="php5-bz2 less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032149" comment="php5-calendar less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032150" comment="php5-ctype less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032151" comment="php5-curl less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032152" comment="php5-dba less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032153" comment="php5-dbase less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032154" comment="php5-dom less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032155" comment="php5-exif less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032156" comment="php5-fastcgi less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032157" comment="php5-ftp less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032158" comment="php5-gd less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032159" comment="php5-gettext less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032160" comment="php5-gmp less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032161" comment="php5-hash less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032162" comment="php5-iconv less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032163" comment="php5-json less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032164" comment="php5-ldap less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032165" comment="php5-mbstring less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032166" comment="php5-mcrypt less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032167" comment="php5-mysql less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032168" comment="php5-odbc less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032169" comment="php5-openssl less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032170" comment="php5-pcntl less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032171" comment="php5-pdo less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032172" comment="php5-pear less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032173" comment="php5-pgsql less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032174" comment="php5-pspell less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032175" comment="php5-shmop less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032176" comment="php5-snmp less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032177" comment="php5-soap less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032178" comment="php5-suhosin less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032179" comment="php5-sysvmsg less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032180" comment="php5-sysvsem less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032181" comment="php5-sysvshm less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032182" comment="php5-tokenizer less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032183" comment="php5-wddx less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032184" comment="php5-xmlreader less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032185" comment="php5-xmlrpc less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032186" comment="php5-xmlwriter less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032187" comment="php5-xsl less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032188" comment="php5-zip less than 5.2.6-50.18.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032189" comment="php5-zlib less than 5.2.6-50.18.3"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090755" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0755</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0755" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0755" source="CVE"/>
	<description>
	The FormWidgetChoice::loadDefaults function in Poppler before 0.10.4 allows remote attackers to cause a denial of service (crash) via a PDF file with an invalid Form Opt entry.
	</description>
 </metadata>
<!-- f27d99aa7f35ddbc6bc5e4ac681ee974 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032208" comment="libpoppler4 less than 0.10.1-1.30.5"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090756" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0756</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0756" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0756" source="CVE"/>
	<description>
	The JBIG2Stream::readSymbolDictSeg function in Poppler before 0.10.4 allows remote attackers to cause a denial of service (crash) via a PDF file that triggers a parsing error, which is not properly handled by JBIG2SymbolDict::~JBIG2SymbolDict and triggers an invalid memory dereference.
	</description>
 </metadata>
<!-- f27d99aa7f35ddbc6bc5e4ac681ee974 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032208" comment="libpoppler4 less than 0.10.1-1.30.5"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090758" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0758</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0758" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0758" source="CVE"/>
	<description>
	The originates_from_local_legacy_unicast_socket function in avahi-core/server.c in avahi-daemon 0.6.23 does not account for the network byte order of a port number when processing incoming multicast packets, which allows remote attackers to cause a denial of service (network bandwidth and CPU consumption) via a crafted legacy unicast mDNS query packet that triggers a multicast packet storm.
	</description>
 </metadata>
<!-- e62a04513f7f4a262e1c7a10a38b46e8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009057520" comment="avahi-lang less than 0.6.23-11.14.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057521" comment="avahi less than 0.6.23-11.14.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057522" comment="libavahi-client3-32bit less than 0.6.23-11.14.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057523" comment="libavahi-client3-x86 less than 0.6.23-11.14.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057524" comment="libavahi-client3 less than 0.6.23-11.14.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057525" comment="libavahi-common3-32bit less than 0.6.23-11.14.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057526" comment="libavahi-common3-x86 less than 0.6.23-11.14.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057527" comment="libavahi-common3 less than 0.6.23-11.14.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057528" comment="libavahi-core5 less than 0.6.23-11.14.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057529" comment="libdns_sd-32bit less than 0.6.23-11.14.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057530" comment="libdns_sd-x86 less than 0.6.23-11.14.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057531" comment="libdns_sd less than 0.6.23-11.14.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090771" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0771</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0771" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0771" source="CVE"/>
	<description>
	The layout engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain vectors that trigger memory corruption and assertion failures.
	</description>
 </metadata>
<!-- 64ea6139df28e916c5f627ff6f4b6b83 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032198" comment="MozillaFirefox-translations less than 3.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032199" comment="MozillaFirefox less than 3.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032200" comment="mozilla-xulrunner190-32bit less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032201" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032202" comment="mozilla-xulrunner190-translations less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032203" comment="mozilla-xulrunner190-x86 less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032204" comment="mozilla-xulrunner190 less than 1.9.0.7-1.1.4"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090772" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0772</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0772" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0772" source="CVE"/>
	<description>
	The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to nsCSSStyleSheet::GetOwnerNode, events, and garbage collection, which triggers memory corruption.
	</description>
 </metadata>
<!-- 64ea6139df28e916c5f627ff6f4b6b83 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032198" comment="MozillaFirefox-translations less than 3.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032199" comment="MozillaFirefox less than 3.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032200" comment="mozilla-xulrunner190-32bit less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032201" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032202" comment="mozilla-xulrunner190-translations less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032203" comment="mozilla-xulrunner190-x86 less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032204" comment="mozilla-xulrunner190 less than 1.9.0.7-1.1.4"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090773" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0773</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0773" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0773" source="CVE"/>
	<description>
	The JavaScript engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a splice of an array that contains "some non-set elements," which causes jsarray.cpp to pass an incorrect argument to the ResizeSlots function, which triggers memory corruption; (2) vectors related to js_DecompileValueGenerator, jsopcode.cpp, __defineSetter__, and watch, which triggers an assertion failure or a segmentation fault; and (3) vectors related to gczeal, __defineSetter__, and watch, which triggers a hang.
	</description>
 </metadata>
<!-- 64ea6139df28e916c5f627ff6f4b6b83 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032198" comment="MozillaFirefox-translations less than 3.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032199" comment="MozillaFirefox less than 3.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032200" comment="mozilla-xulrunner190-32bit less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032201" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032202" comment="mozilla-xulrunner190-translations less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032203" comment="mozilla-xulrunner190-x86 less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032204" comment="mozilla-xulrunner190 less than 1.9.0.7-1.1.4"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090774" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0774</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0774" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0774" source="CVE"/>
	<description>
	The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to gczeal, a different vulnerability than CVE-2009-0773.
	</description>
 </metadata>
<!-- 64ea6139df28e916c5f627ff6f4b6b83 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032198" comment="MozillaFirefox-translations less than 3.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032199" comment="MozillaFirefox less than 3.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032200" comment="mozilla-xulrunner190-32bit less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032201" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032202" comment="mozilla-xulrunner190-translations less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032203" comment="mozilla-xulrunner190-x86 less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032204" comment="mozilla-xulrunner190 less than 1.9.0.7-1.1.4"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090775" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0775</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0775" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0775" source="CVE"/>
	<description>
	Double free vulnerability in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to execute arbitrary code via "cloned XUL DOM elements which were linked as a parent and child," which are not properly handled during garbage collection.
	</description>
 </metadata>
<!-- 64ea6139df28e916c5f627ff6f4b6b83 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032198" comment="MozillaFirefox-translations less than 3.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032199" comment="MozillaFirefox less than 3.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032200" comment="mozilla-xulrunner190-32bit less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032201" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032202" comment="mozilla-xulrunner190-translations less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032203" comment="mozilla-xulrunner190-x86 less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032204" comment="mozilla-xulrunner190 less than 1.9.0.7-1.1.4"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090776" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0776</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0776" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0776" source="CVE"/>
	<description>
	nsIRDFService in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to bypass the same-origin policy and read XML data from another domain via a cross-domain redirect.
	</description>
 </metadata>
<!-- 64ea6139df28e916c5f627ff6f4b6b83 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032198" comment="MozillaFirefox-translations less than 3.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032199" comment="MozillaFirefox less than 3.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032200" comment="mozilla-xulrunner190-32bit less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032201" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032202" comment="mozilla-xulrunner190-translations less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032203" comment="mozilla-xulrunner190-x86 less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032204" comment="mozilla-xulrunner190 less than 1.9.0.7-1.1.4"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090777" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0777</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0777" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0777" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 decode invisible characters when they are displayed in the location bar, which causes an incorrect address to be displayed and makes it easier for remote attackers to spoof URLs and conduct phishing attacks.
	</description>
 </metadata>
<!-- 64ea6139df28e916c5f627ff6f4b6b83 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032198" comment="MozillaFirefox-translations less than 3.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032199" comment="MozillaFirefox less than 3.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032200" comment="mozilla-xulrunner190-32bit less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032201" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032202" comment="mozilla-xulrunner190-translations less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032203" comment="mozilla-xulrunner190-x86 less than 1.9.0.7-1.1.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032204" comment="mozilla-xulrunner190 less than 1.9.0.7-1.1.4"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090781" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0781</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0781" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0781" source="CVE"/>
	<description>
	Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 allows remote attackers to inject arbitrary web script or HTML via the time parameter, related to "invalid HTML."
	</description>
 </metadata>
<!-- 1e030cf1aa564a63a9739f4894501a93 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053169" comment="websphere-as_ce less than 2.1.1.2-2.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053170" comment="websphere-as_ce less than 2.1.1.2-2.2"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090789" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0789</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0789" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0789" source="CVE"/>
	<description>
	OpenSSL before 0.9.8k on WIN64 and certain other platforms does not properly handle a malformed ASN.1 structure, which allows remote attackers to cause a denial of service (invalid memory access and application crash) by placing this structure in the public key of a certificate, as demonstrated by an RSA public key.
	</description>
 </metadata>
<!-- 2f80f91b648dcd2ec32e230ff4cf94b5 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032262" comment="libopenssl0_9_8-32bit less than 0.9.8h-30.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032263" comment="libopenssl0_9_8-x86 less than 0.9.8h-30.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032264" comment="libopenssl0_9_8 less than 0.9.8h-30.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032265" comment="openssl-doc less than 0.9.8h-30.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032266" comment="openssl less than 0.9.8h-30.12.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090790" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0790</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0790" source="CVE"/>
	<description>
	The pluto IKE daemon in Openswan and Strongswan IPsec 2.6 before 2.6.21 and 2.4 before 2.4.14, and Strongswan 4.2 before 4.2.14 and 2.8 before 2.8.9, allows remote attackers to cause a denial of service (daemon crash and restart) via a crafted (1) R_U_THERE or (2) R_U_THERE_ACK Dead Peer Detection (DPD) IPsec IKE Notification message that triggers a NULL pointer dereference related to inconsistent ISAKMP state and the lack of a phase2 state association in DPD.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1eeddb594241891837f28e6a7ee5c80a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032309" comment="openswan-doc less than 2.6.16-1.32.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032310" comment="openswan less than 2.6.16-1.32.1"/>
		</criteria>
	</criteria>
	<!-- ffe70bfa8e56c5826cb371dabddec302 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032311" comment="strongswan-doc less than 4.2.8-1.22.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032312" comment="strongswan less than 4.2.8-1.22.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090791" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0791</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0791" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0791" source="CVE"/>
	<description>
	Multiple integer overflows in Xpdf 2.x and 3.x and Poppler 0.x, as used in the pdftops filter in CUPS 1.1.17, 1.1.22, and 1.3.7, GPdf, and kdegraphics KPDF, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF file that triggers a heap-based buffer overflow, possibly related to (1) Decrypt.cxx, (2) FoFiTrueType.cxx, (3) gmem.c, (4) JBIG2Stream.cxx, and (5) PSOutputDev.cxx in pdftops/. NOTE: the JBIG2Stream.cxx vector may overlap CVE-2009-1179.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 3e6bf6b6d5045a1a9a76d6199d51adab -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054103" comment="xpdf-tools less than 3.02-138.26.1"/>
	</criteria>
	<!-- bde2b755a6dc83d88dd11394793d4482 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057042" comment="libpoppler-glib4 less than 0.10.1-1.31.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057043" comment="libpoppler-qt4-3 less than 0.10.1-1.31.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057044" comment="libpoppler4 less than 0.10.1-1.31.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057045" comment="poppler-tools less than 0.10.1-1.31.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090792" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0792</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0792" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0792" source="CVE"/>
	<description>
	Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.  NOTE: this issue exists because of an incomplete fix for CVE-2009-0583.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 821fdfa281de6b75cdc24c1e4f935e7e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032219" comment="ghostscript-fonts-other less than 8.62-32.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032220" comment="ghostscript-fonts-rus less than 8.62-32.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032221" comment="ghostscript-fonts-std less than 8.62-32.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032222" comment="ghostscript-library less than 8.62-32.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032223" comment="ghostscript-omni less than 8.62-32.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032224" comment="ghostscript-x11 less than 8.62-32.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032225" comment="libgimpprint less than 4.2.7-32.23.1"/>
		</criteria>
	</criteria>
	<!-- ab7a3ecdd7f2b22db74d66fd6e23832b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032106" comment="ghostscript-fonts-other less than 8.62-32.25.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032107" comment="ghostscript-fonts-rus less than 8.62-32.25.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032108" comment="ghostscript-fonts-std less than 8.62-32.25.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032109" comment="ghostscript-library less than 8.62-32.25.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032110" comment="ghostscript-omni less than 8.62-32.25.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032111" comment="ghostscript-x11 less than 8.62-32.25.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032112" comment="libgimpprint less than 4.2.7-32.25.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090799" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0799</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0799" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0799" source="CVE"/>
	<description>
	The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers an out-of-bounds read.
	</description>
 </metadata>
<!-- f27d99aa7f35ddbc6bc5e4ac681ee974 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032208" comment="libpoppler4 less than 0.10.1-1.30.5"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090800" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0800</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0800" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0800" source="CVE"/>
	<description>
	Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file.
	</description>
 </metadata>
<!-- f27d99aa7f35ddbc6bc5e4ac681ee974 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032208" comment="libpoppler4 less than 0.10.1-1.30.5"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090835" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0835</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0835" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0835" source="CVE"/>
	<description>
	The __secure_computing function in kernel/seccomp.c in the seccomp subsystem in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform, when CONFIG_SECCOMP is enabled, does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass intended access restrictions via crafted syscalls that are misinterpreted as (a) stat or (b) chmod, a related issue to CVE-2009-0342 and CVE-2009-0343.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 40623e2603f46ef0bf4615d7d469eb26 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032274" comment="ext4dev-kmp-default less than 0_2.6.27.21_0.1-7.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032275" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.21_0.1-7.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032276" comment="kernel-default-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032277" comment="kernel-default less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032278" comment="kernel-kdump less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032279" comment="kernel-ppc64-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032280" comment="kernel-ppc64 less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032281" comment="kernel-source less than 2.6.27.21-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032282" comment="kernel-syms less than 2.6.27.21-0.1.2"/>
		</criteria>
	</criteria>
	<!-- 811ee372cc49e0ad64c32f8cf2267192 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032274" comment="ext4dev-kmp-default less than 0_2.6.27.21_0.1-7.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032276" comment="kernel-default-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032277" comment="kernel-default less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032281" comment="kernel-source less than 2.6.27.21-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032282" comment="kernel-syms less than 2.6.27.21-0.1.2"/>
		</criteria>
	</criteria>
	<!-- 8987accc22406eeb83098eded271c9af -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032274" comment="ext4dev-kmp-default less than 0_2.6.27.21_0.1-7.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032276" comment="kernel-default-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032283" comment="kernel-default-man less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032277" comment="kernel-default less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032281" comment="kernel-source less than 2.6.27.21-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032282" comment="kernel-syms less than 2.6.27.21-0.1.2"/>
		</criteria>
	</criteria>
	<!-- 8b684f8048b88ef832b80e585ff96805 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032274" comment="ext4dev-kmp-default less than 0_2.6.27.21_0.1-7.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032284" comment="ext4dev-kmp-xen less than 0_2.6.27.21_0.1-7.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032276" comment="kernel-default-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032277" comment="kernel-default less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032281" comment="kernel-source less than 2.6.27.21-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032282" comment="kernel-syms less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032285" comment="kernel-xen-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032286" comment="kernel-xen less than 2.6.27.21-0.1.2"/>
		</criteria>
	</criteria>
	<!-- ab571c76de3bf9c7bafb83437a2d83aa -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032274" comment="ext4dev-kmp-default less than 0_2.6.27.21_0.1-7.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032287" comment="ext4dev-kmp-pae less than 0_2.6.27.21_0.1-7.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032288" comment="ext4dev-kmp-vmi less than 0_2.6.27.21_0.1-7.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032284" comment="ext4dev-kmp-xen less than 0_2.6.27.21_0.1-7.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032276" comment="kernel-default-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032277" comment="kernel-default less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032289" comment="kernel-pae-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032290" comment="kernel-pae less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032281" comment="kernel-source less than 2.6.27.21-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032282" comment="kernel-syms less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032291" comment="kernel-vmi-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032292" comment="kernel-vmi less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032285" comment="kernel-xen-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032286" comment="kernel-xen less than 2.6.27.21-0.1.2"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090844" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0844</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0844" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0844" source="CVE"/>
	<description>
	The get_input_token function in the SPNEGO implementation in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote attackers to cause a denial of service (daemon crash) and possibly obtain sensitive information via a crafted length value that triggers a buffer over-read.
	</description>
 </metadata>
<!-- 077b202d02c16bdd595a5ac0beb7479b -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032313" comment="krb5-32bit less than 1.6.3-133.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032314" comment="krb5-apps-clients less than 1.6.3-133.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032315" comment="krb5-apps-servers less than 1.6.3-133.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032316" comment="krb5-client less than 1.6.3-133.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032317" comment="krb5-server less than 1.6.3-133.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032318" comment="krb5-x86 less than 1.6.3-133.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032319" comment="krb5 less than 1.6.3-133.25.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090845" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0845</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0845" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0845" source="CVE"/>
	<description>
	The spnego_gss_accept_sec_context function in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3, when SPNEGO is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via invalid ContextFlags data in the reqFlags field in a negTokenInit token.
	</description>
 </metadata>
<!-- 077b202d02c16bdd595a5ac0beb7479b -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032313" comment="krb5-32bit less than 1.6.3-133.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032314" comment="krb5-apps-clients less than 1.6.3-133.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032315" comment="krb5-apps-servers less than 1.6.3-133.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032316" comment="krb5-client less than 1.6.3-133.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032317" comment="krb5-server less than 1.6.3-133.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032318" comment="krb5-x86 less than 1.6.3-133.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032319" comment="krb5 less than 1.6.3-133.25.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090846" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0846</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0846" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0846" source="CVE"/>
	<description>
	The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via vectors involving an invalid DER encoding that triggers a free of an uninitialized pointer.
	</description>
 </metadata>
<!-- 077b202d02c16bdd595a5ac0beb7479b -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032313" comment="krb5-32bit less than 1.6.3-133.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032314" comment="krb5-apps-clients less than 1.6.3-133.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032315" comment="krb5-apps-servers less than 1.6.3-133.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032316" comment="krb5-client less than 1.6.3-133.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032317" comment="krb5-server less than 1.6.3-133.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032318" comment="krb5-x86 less than 1.6.3-133.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032319" comment="krb5 less than 1.6.3-133.25.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090847" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0847</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0847" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0847" source="CVE"/>
	<description>
	The asn1buf_imbed function in the ASN.1 decoder in MIT Kerberos 5 (aka krb5) 1.6.3, when PK-INIT is used, allows remote attackers to cause a denial of service (application crash) via a crafted length value that triggers an erroneous malloc call, related to incorrect calculations with pointer arithmetic.
	</description>
 </metadata>
<!-- 077b202d02c16bdd595a5ac0beb7479b -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032313" comment="krb5-32bit less than 1.6.3-133.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032314" comment="krb5-apps-clients less than 1.6.3-133.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032315" comment="krb5-apps-servers less than 1.6.3-133.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032316" comment="krb5-client less than 1.6.3-133.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032317" comment="krb5-server less than 1.6.3-133.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032318" comment="krb5-x86 less than 1.6.3-133.25.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032319" comment="krb5 less than 1.6.3-133.25.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090922" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0922</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0922" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0922" source="CVE"/>
	<description>
	PostgreSQL before 8.3.7, 8.2.13, 8.1.17, 8.0.21, and 7.4.25 allows remote authenticated users to cause a denial of service (stack consumption and crash) by triggering a failure in the conversion of a localized error message to a client-specified encoding, as demonstrated using mismatched encoding conversion requests.
	</description>
 </metadata>
<!-- f8418e967ead7b81dedf9dca5a5fd222 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032320" comment="postgresql-contrib less than 8.3.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032321" comment="postgresql-docs less than 8.3.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032322" comment="postgresql-libs-32bit less than 8.3.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032323" comment="postgresql-libs-x86 less than 8.3.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032324" comment="postgresql-libs less than 8.3.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032325" comment="postgresql-server less than 8.3.7-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032326" comment="postgresql less than 8.3.7-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090945" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0945</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0945" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0945" source="CVE"/>
	<description>
	Array index error in the insertItemBefore method in WebKit, as used in Apple Safari before 3.2.3 and 4 Public Beta, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Google Chrome Stable before 1.0.154.65, and possibly other products allows remote attackers to execute arbitrary code via a document with a SVGPathList data structure containing a negative index in the (1) SVGTransformList, (2) SVGStringList, (3) SVGNumberList, (4) SVGPathSegList, (5) SVGPointList, or (6) SVGLengthList SVGList object, which triggers memory corruption.
	</description>
 </metadata>
<!-- c980cdd57955d1f78a74976fd2c23c32 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056137" comment="libqt4-32bit less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056138" comment="libqt4-qt3support-32bit less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056139" comment="libqt4-qt3support-x86 less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056140" comment="libqt4-qt3support less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056141" comment="libqt4-sql-32bit less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056142" comment="libqt4-sql-sqlite less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056143" comment="libqt4-sql-x86 less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056144" comment="libqt4-sql less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056145" comment="libqt4-x11-32bit less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056146" comment="libqt4-x11-x86 less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056147" comment="libqt4-x11 less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056148" comment="libqt4-x86 less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056149" comment="libqt4 less than 4.4.3-12.11.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090946" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-0946</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-0946" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0946" source="CVE"/>
	<description>
	Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.
	</description>
 </metadata>
<!-- 12988c12cb970710f31eeb8ab8363bee -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032327" comment="freetype2-32bit less than 2.3.7-25.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032328" comment="freetype2-x86 less than 2.3.7-25.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032329" comment="freetype2 less than 2.3.7-25.9.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091044" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1044</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1044" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1044" source="CVE"/>
	<description>
	Mozilla Firefox 3.0.7 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors related to the _moveToEdgeShift XUL tree method, which triggers garbage collection on objects that are still in use, as demonstrated by Nils during a PWN2OWN competition at CanSecWest 2009.
	</description>
 </metadata>
<!-- 272bd7f6089e8316b21585826776f472 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032330" comment="MozillaFirefox-translations less than 3.0.8-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032331" comment="MozillaFirefox less than 3.0.8-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032332" comment="mozilla-xulrunner190-32bit less than 1.9.0.8-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032333" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.8-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032334" comment="mozilla-xulrunner190-translations less than 1.9.0.8-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032335" comment="mozilla-xulrunner190-x86 less than 1.9.0.8-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032336" comment="mozilla-xulrunner190 less than 1.9.0.8-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091072" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1072</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1072" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1072" source="CVE"/>
	<description>
	nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash option.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 40623e2603f46ef0bf4615d7d469eb26 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032274" comment="ext4dev-kmp-default less than 0_2.6.27.21_0.1-7.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032275" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.21_0.1-7.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032276" comment="kernel-default-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032277" comment="kernel-default less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032278" comment="kernel-kdump less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032279" comment="kernel-ppc64-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032280" comment="kernel-ppc64 less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032281" comment="kernel-source less than 2.6.27.21-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032282" comment="kernel-syms less than 2.6.27.21-0.1.2"/>
		</criteria>
	</criteria>
	<!-- 811ee372cc49e0ad64c32f8cf2267192 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032274" comment="ext4dev-kmp-default less than 0_2.6.27.21_0.1-7.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032276" comment="kernel-default-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032277" comment="kernel-default less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032281" comment="kernel-source less than 2.6.27.21-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032282" comment="kernel-syms less than 2.6.27.21-0.1.2"/>
		</criteria>
	</criteria>
	<!-- 8987accc22406eeb83098eded271c9af -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032274" comment="ext4dev-kmp-default less than 0_2.6.27.21_0.1-7.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032276" comment="kernel-default-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032283" comment="kernel-default-man less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032277" comment="kernel-default less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032281" comment="kernel-source less than 2.6.27.21-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032282" comment="kernel-syms less than 2.6.27.21-0.1.2"/>
		</criteria>
	</criteria>
	<!-- 8b684f8048b88ef832b80e585ff96805 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032274" comment="ext4dev-kmp-default less than 0_2.6.27.21_0.1-7.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032284" comment="ext4dev-kmp-xen less than 0_2.6.27.21_0.1-7.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032276" comment="kernel-default-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032277" comment="kernel-default less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032281" comment="kernel-source less than 2.6.27.21-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032282" comment="kernel-syms less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032285" comment="kernel-xen-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032286" comment="kernel-xen less than 2.6.27.21-0.1.2"/>
		</criteria>
	</criteria>
	<!-- ab571c76de3bf9c7bafb83437a2d83aa -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032274" comment="ext4dev-kmp-default less than 0_2.6.27.21_0.1-7.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032287" comment="ext4dev-kmp-pae less than 0_2.6.27.21_0.1-7.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032288" comment="ext4dev-kmp-vmi less than 0_2.6.27.21_0.1-7.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032284" comment="ext4dev-kmp-xen less than 0_2.6.27.21_0.1-7.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032276" comment="kernel-default-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032277" comment="kernel-default less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032289" comment="kernel-pae-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032290" comment="kernel-pae less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032281" comment="kernel-source less than 2.6.27.21-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032282" comment="kernel-syms less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032291" comment="kernel-vmi-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032292" comment="kernel-vmi less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032285" comment="kernel-xen-base less than 2.6.27.21-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032286" comment="kernel-xen less than 2.6.27.21-0.1.2"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091093" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1093</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1093" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1093" source="CVE"/>
	<description>
	LdapCtx in the LDAP service in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; SDK and JRE 1.3.1_24 and earlier; and 1.4.2_19 and earlier does not close the connection when initialization fails, which allows remote attackers to cause a denial of service (LDAP service hang).
	</description>
 </metadata>
<!-- 706f811c965148739c35d07d3653b91c -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053022" comment="java-1_6_0-ibm-alsa-x86 less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053023" comment="java-1_6_0-ibm-alsa less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053024" comment="java-1_6_0-ibm-fonts less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053025" comment="java-1_6_0-ibm-jdbc less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053026" comment="java-1_6_0-ibm-plugin less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053027" comment="java-1_6_0-ibm-x86 less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053028" comment="java-1_6_0-ibm less than 1.6.0-124.7.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091094" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1094</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1094" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1094" source="CVE"/>
	<description>
	Unspecified vulnerability in the LDAP implementation in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; SDK and JRE 1.3.1_24 and earlier; and 1.4.2_19 and earlier allows remote LDAP servers to execute arbitrary code via unknown vectors related to serialized data.
	</description>
 </metadata>
<!-- 706f811c965148739c35d07d3653b91c -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053022" comment="java-1_6_0-ibm-alsa-x86 less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053023" comment="java-1_6_0-ibm-alsa less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053024" comment="java-1_6_0-ibm-fonts less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053025" comment="java-1_6_0-ibm-jdbc less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053026" comment="java-1_6_0-ibm-plugin less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053027" comment="java-1_6_0-ibm-x86 less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053028" comment="java-1_6_0-ibm less than 1.6.0-124.7.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091095" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1095</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1095" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1095" source="CVE"/>
	<description>
	Integer overflow in unpack200 in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via a JAR file with crafted Pack200 headers.
	</description>
 </metadata>
<!-- 706f811c965148739c35d07d3653b91c -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053022" comment="java-1_6_0-ibm-alsa-x86 less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053023" comment="java-1_6_0-ibm-alsa less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053024" comment="java-1_6_0-ibm-fonts less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053025" comment="java-1_6_0-ibm-jdbc less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053026" comment="java-1_6_0-ibm-plugin less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053027" comment="java-1_6_0-ibm-x86 less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053028" comment="java-1_6_0-ibm less than 1.6.0-124.7.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091096" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1096</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1096" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1096" source="CVE"/>
	<description>
	Buffer overflow in unpack200 in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via a JAR file with crafted Pack200 headers.
	</description>
 </metadata>
<!-- 706f811c965148739c35d07d3653b91c -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053022" comment="java-1_6_0-ibm-alsa-x86 less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053023" comment="java-1_6_0-ibm-alsa less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053024" comment="java-1_6_0-ibm-fonts less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053025" comment="java-1_6_0-ibm-jdbc less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053026" comment="java-1_6_0-ibm-plugin less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053027" comment="java-1_6_0-ibm-x86 less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053028" comment="java-1_6_0-ibm less than 1.6.0-124.7.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091097" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1097</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1097" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1097" source="CVE"/>
	<description>
	Multiple buffer overflows in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allow remote attackers to access files or execute arbitrary code via (1) a crafted PNG image that triggers an integer overflow during memory allocation for display on the splash screen, aka CR 6804996; and (2) a crafted GIF image from which unspecified values are used in calculation of offsets, leading to object-pointer corruption, aka CR 6804997.
	</description>
 </metadata>
<!-- 706f811c965148739c35d07d3653b91c -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053022" comment="java-1_6_0-ibm-alsa-x86 less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053023" comment="java-1_6_0-ibm-alsa less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053024" comment="java-1_6_0-ibm-fonts less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053025" comment="java-1_6_0-ibm-jdbc less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053026" comment="java-1_6_0-ibm-plugin less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053027" comment="java-1_6_0-ibm-x86 less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053028" comment="java-1_6_0-ibm less than 1.6.0-124.7.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091098" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1098</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1098" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1098" source="CVE"/>
	<description>
	Buffer overflow in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; 1.4.2_19 and earlier; and 1.3.1_24 and earlier allows remote attackers to access files or execute arbitrary code via a crafted GIF image, aka CR 6804998.
	</description>
 </metadata>
<!-- 706f811c965148739c35d07d3653b91c -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053022" comment="java-1_6_0-ibm-alsa-x86 less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053023" comment="java-1_6_0-ibm-alsa less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053024" comment="java-1_6_0-ibm-fonts less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053025" comment="java-1_6_0-ibm-jdbc less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053026" comment="java-1_6_0-ibm-plugin less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053027" comment="java-1_6_0-ibm-x86 less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053028" comment="java-1_6_0-ibm less than 1.6.0-124.7.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091099" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1099</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1099" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1099" source="CVE"/>
	<description>
	Integer signedness error in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via crafted glyph descriptions in a Type1 font, which bypasses a signed comparison and triggers a buffer overflow.
	</description>
 </metadata>
<!-- 706f811c965148739c35d07d3653b91c -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053022" comment="java-1_6_0-ibm-alsa-x86 less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053023" comment="java-1_6_0-ibm-alsa less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053024" comment="java-1_6_0-ibm-fonts less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053025" comment="java-1_6_0-ibm-jdbc less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053026" comment="java-1_6_0-ibm-plugin less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053027" comment="java-1_6_0-ibm-x86 less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053028" comment="java-1_6_0-ibm less than 1.6.0-124.7.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091100" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1100</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1100" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1100" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allow remote attackers to cause a denial of service (disk consumption) via vectors related to temporary font files and (1) "limits on Font creation," aka CR 6522586, and (2) another unspecified vector, aka CR 6632886.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 078e3d197ce1488682c8fe5574f20e9b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056369" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056370" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056371" comment="java-1_4_2-ibm less than 1.4.2_sr13.2-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 706f811c965148739c35d07d3653b91c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053022" comment="java-1_6_0-ibm-alsa-x86 less than 1.6.0-124.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053023" comment="java-1_6_0-ibm-alsa less than 1.6.0-124.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053024" comment="java-1_6_0-ibm-fonts less than 1.6.0-124.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053025" comment="java-1_6_0-ibm-jdbc less than 1.6.0-124.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053026" comment="java-1_6_0-ibm-plugin less than 1.6.0-124.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053027" comment="java-1_6_0-ibm-x86 less than 1.6.0-124.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053028" comment="java-1_6_0-ibm less than 1.6.0-124.7.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091101" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1101</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1101" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1101" source="CVE"/>
	<description>
	Unspecified vulnerability in the lightweight HTTP server implementation in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allows remote attackers to cause a denial of service (probably resource consumption) for a JAX-WS service endpoint via a connection without any data, which triggers a file descriptor "leak."
	</description>
 </metadata>
<!-- 706f811c965148739c35d07d3653b91c -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053022" comment="java-1_6_0-ibm-alsa-x86 less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053023" comment="java-1_6_0-ibm-alsa less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053024" comment="java-1_6_0-ibm-fonts less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053025" comment="java-1_6_0-ibm-jdbc less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053026" comment="java-1_6_0-ibm-plugin less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053027" comment="java-1_6_0-ibm-x86 less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053028" comment="java-1_6_0-ibm less than 1.6.0-124.7.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091103" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1103</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1103" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1103" source="CVE"/>
	<description>
	Unspecified vulnerability in the Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; 1.4.2_19 and earlier; and 1.3.1_24 and earlier allows remote attackers to access files and execute arbitrary code via unknown vectors related to "deserializing applets," aka CR 6646860.
	</description>
 </metadata>
<!-- 706f811c965148739c35d07d3653b91c -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053022" comment="java-1_6_0-ibm-alsa-x86 less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053023" comment="java-1_6_0-ibm-alsa less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053024" comment="java-1_6_0-ibm-fonts less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053025" comment="java-1_6_0-ibm-jdbc less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053026" comment="java-1_6_0-ibm-plugin less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053027" comment="java-1_6_0-ibm-x86 less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053028" comment="java-1_6_0-ibm less than 1.6.0-124.7.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091104" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1104</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1104" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1104" source="CVE"/>
	<description>
	The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; and 1.4.2_19 and earlier does not prevent Javascript that is loaded from the localhost from connecting to other ports on the system, which allows user-assisted attackers to bypass intended access restrictions via LiveConnect, aka CR 6724331.  NOTE: this vulnerability can be leveraged with separate cross-site scripting (XSS) vulnerabilities for remote attack vectors.
	</description>
 </metadata>
<!-- 706f811c965148739c35d07d3653b91c -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053022" comment="java-1_6_0-ibm-alsa-x86 less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053023" comment="java-1_6_0-ibm-alsa less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053024" comment="java-1_6_0-ibm-fonts less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053025" comment="java-1_6_0-ibm-jdbc less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053026" comment="java-1_6_0-ibm-plugin less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053027" comment="java-1_6_0-ibm-x86 less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053028" comment="java-1_6_0-ibm less than 1.6.0-124.7.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091105" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1105</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1105" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1105" source="CVE"/>
	<description>
	The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12, 11, and 10 allows user-assisted remote attackers to cause a trusted applet to run in an older JRE version, which can be used to exploit vulnerabilities in that older version, aka CR 6706490.
	</description>
 </metadata>
<!-- 706f811c965148739c35d07d3653b91c -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053022" comment="java-1_6_0-ibm-alsa-x86 less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053023" comment="java-1_6_0-ibm-alsa less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053024" comment="java-1_6_0-ibm-fonts less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053025" comment="java-1_6_0-ibm-jdbc less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053026" comment="java-1_6_0-ibm-plugin less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053027" comment="java-1_6_0-ibm-x86 less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053028" comment="java-1_6_0-ibm less than 1.6.0-124.7.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091106" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1106</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1106" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1106" source="CVE"/>
	<description>
	The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12, 11, and 10 does not properly parse crossdomain.xml files, which allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unknown vectors, aka CR 6798948.
	</description>
 </metadata>
<!-- 706f811c965148739c35d07d3653b91c -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053022" comment="java-1_6_0-ibm-alsa-x86 less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053023" comment="java-1_6_0-ibm-alsa less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053024" comment="java-1_6_0-ibm-fonts less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053025" comment="java-1_6_0-ibm-jdbc less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053026" comment="java-1_6_0-ibm-plugin less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053027" comment="java-1_6_0-ibm-x86 less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053028" comment="java-1_6_0-ibm less than 1.6.0-124.7.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091107" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1107</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1107" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1107" source="CVE"/>
	<description>
	The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier, and 5.0 Update 17 and earlier, allows remote attackers to trick a user into trusting a signed applet via unknown vectors that misrepresent the security warning dialog, related to a "Swing JLabel HTML parsing vulnerability," aka CR 6782871.
	</description>
 </metadata>
<!-- 706f811c965148739c35d07d3653b91c -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053022" comment="java-1_6_0-ibm-alsa-x86 less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053023" comment="java-1_6_0-ibm-alsa less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053024" comment="java-1_6_0-ibm-fonts less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053025" comment="java-1_6_0-ibm-jdbc less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053026" comment="java-1_6_0-ibm-plugin less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053027" comment="java-1_6_0-ibm-x86 less than 1.6.0-124.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053028" comment="java-1_6_0-ibm less than 1.6.0-124.7.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091169" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1169</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1169" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1169" source="CVE"/>
	<description>
	The txMozillaXSLTProcessor::TransformToDoc function in Mozilla Firefox before 3.0.8 and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XML file with a crafted XSLT transform.
	</description>
 </metadata>
<!-- 272bd7f6089e8316b21585826776f472 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032330" comment="MozillaFirefox-translations less than 3.0.8-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032331" comment="MozillaFirefox less than 3.0.8-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032332" comment="mozilla-xulrunner190-32bit less than 1.9.0.8-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032333" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.8-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032334" comment="mozilla-xulrunner190-translations less than 1.9.0.8-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032335" comment="mozilla-xulrunner190-x86 less than 1.9.0.8-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032336" comment="mozilla-xulrunner190 less than 1.9.0.8-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091179" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1179</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1179" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1179" source="CVE"/>
	<description>
	Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file.
	</description>
 </metadata>
<!-- f27d99aa7f35ddbc6bc5e4ac681ee974 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032208" comment="libpoppler4 less than 0.10.1-1.30.5"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091180" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1180</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1180" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1180" source="CVE"/>
	<description>
	The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file that triggers a free of invalid data.
	</description>
 </metadata>
<!-- f27d99aa7f35ddbc6bc5e4ac681ee974 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032208" comment="libpoppler4 less than 0.10.1-1.30.5"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091181" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1181</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1181" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1181" source="CVE"/>
	<description>
	The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a NULL pointer dereference.
	</description>
 </metadata>
<!-- f27d99aa7f35ddbc6bc5e4ac681ee974 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032208" comment="libpoppler4 less than 0.10.1-1.30.5"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091182" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1182</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1182" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1182" source="CVE"/>
	<description>
	Multiple buffer overflows in the JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file.
	</description>
 </metadata>
<!-- f27d99aa7f35ddbc6bc5e4ac681ee974 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032208" comment="libpoppler4 less than 0.10.1-1.30.5"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091183" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1183</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1183" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1183" source="CVE"/>
	<description>
	The JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted PDF file.
	</description>
 </metadata>
<!-- f27d99aa7f35ddbc6bc5e4ac681ee974 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032208" comment="libpoppler4 less than 0.10.1-1.30.5"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091185" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1185</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1185" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1185" source="CVE"/>
	<description>
	udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.
	</description>
 </metadata>
<!-- f2a20a677f8f07b34c3543e781db446f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032337" comment="libvolume_id1 less than 128-13.2.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032338" comment="udev less than 128-13.2.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091189" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1189</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2009-1189" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1189" source="CVE"/>
	<description>
	The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) in D-Bus (aka DBus) before 1.2.14 uses incorrect logic to validate a basic type, which allows remote attackers to spoof a signature via a crafted key.  NOTE: this is due to an incorrect fix for CVE-2008-3834.
	</description>
 </metadata>
<!-- 54eee4e87a0d78b170de796964bdfc46 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009067850" comment="dbus-1-32bit less than 1.2.10-3.17.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009067851" comment="dbus-1-x11 less than 1.2.10-3.17.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009067852" comment="dbus-1-x86 less than 1.2.10-3.17.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009067853" comment="dbus-1 less than 1.2.10-3.17.1"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009067850" comment="dbus-1-32bit less than 1.2.10-3.17.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009067851" comment="dbus-1-x11 less than 1.2.10-3.17.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009067853" comment="dbus-1 less than 1.2.10-3.17.1"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091192" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1192</title>
	<affected family="unix">
		<platform>SLE 11 SERVER Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1192" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1192" source="CVE"/>
	<description>
	The (1) agp_generic_alloc_page and (2) agp_generic_alloc_pages functions in drivers/char/agp/generic.c in the agp subsystem in the Linux kernel before 2.6.30-rc3 do not zero out pages that may later be available to a user-space process, which allows local users to obtain sensitive information by reading these pages.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 25ff738fb8fdfec997736b4640fc8077 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
	</criteria>
	<!-- 2773c03ae3c3dd82f505e14be9163826 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032340" comment="kernel-ppc64-extra less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 3adeb6b3cad3a08bfe6e510b3aa6d567 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032341" comment="kernel-pae-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032342" comment="kernel-xen-extra less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 43382bb2967feb0b60a732109cd020e6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032343" comment="ext4dev-kmp-default less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032344" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032347" comment="kernel-kdump less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032348" comment="kernel-ppc64-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032349" comment="kernel-ppc64 less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 7fbbc2ef69ed11f4e8ad69ed4e13c58e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032343" comment="ext4dev-kmp-default less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032352" comment="kernel-default-man less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 80db93c687bbdeb62c79f877c742f4bb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032343" comment="ext4dev-kmp-default less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032353" comment="ext4dev-kmp-pae less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032354" comment="ext4dev-kmp-vmi less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032355" comment="ext4dev-kmp-xen less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032356" comment="kernel-pae-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032357" comment="kernel-pae less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032358" comment="kernel-vmi-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032359" comment="kernel-vmi less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032360" comment="kernel-xen-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032361" comment="kernel-xen less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 9e40eecb7327c57e210599e2f65e0e81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032343" comment="ext4dev-kmp-default less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032355" comment="ext4dev-kmp-xen less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032360" comment="kernel-xen-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032361" comment="kernel-xen less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- bcf17eb6efd35f9093611e2f283ebcb4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032342" comment="kernel-xen-extra less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- bd9317f09213b352461836898559ddf6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032343" comment="ext4dev-kmp-default less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- d73c0f4846d6cc042e6cc14b4d0c152f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091194" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1194</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1194" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1194" source="CVE"/>
	<description>
	Integer overflow in the pango_glyph_string_set_size function in pango/glyphstring.c in Pango before 1.24 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long glyph string that triggers a heap-based buffer overflow, as demonstrated by a long document.location value in Firefox.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- a9f9ebf1fe153fd04f53f3b5b237c97d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032362" comment="pango-32bit less than 1.22.1-3.17.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032363" comment="pango-doc less than 1.22.1-3.17.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032364" comment="pango-x86 less than 1.22.1-3.17.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032365" comment="pango less than 1.22.1-3.17.3"/>
		</criteria>
	</criteria>
	<!-- cdb08e2f6996992396d9c5cfd1a06c5d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057910" comment="pango-32bit less than 1.22.1-3.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057911" comment="pango-doc less than 1.22.1-3.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057912" comment="pango-x86 less than 1.22.1-3.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057913" comment="pango less than 1.22.1-3.18.1"/>
		</criteria>
	</criteria>
	<!-- d3be5c712e2e2706b7b11ecd08d9e22f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053589" comment="MozillaFirefox-translations less than 3.0.12-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053590" comment="MozillaFirefox less than 3.0.12-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053591" comment="mozilla-xulrunner190-32bit less than 1.9.0.12-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053592" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.12-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053593" comment="mozilla-xulrunner190-translations less than 1.9.0.12-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053594" comment="mozilla-xulrunner190-x86 less than 1.9.0.12-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053595" comment="mozilla-xulrunner190 less than 1.9.0.12-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091195" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1195</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1195" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1195" source="CVE"/>
	<description>
	The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEXEC in the AllowOverride directive, which allows local users to gain privileges by configuring (1) Options Includes, (2) Options +Includes, or (3) Options +IncludesNOEXEC in a .htaccess file, and then inserting an exec element in a .shtml file.
	</description>
 </metadata>
<!-- ca7f5abf8025ba6ef69af14cd6570458 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009055706" comment="apache2-doc less than 2.2.10-2.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055707" comment="apache2-example-pages less than 2.2.10-2.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055708" comment="apache2-prefork less than 2.2.10-2.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055709" comment="apache2-utils less than 2.2.10-2.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055710" comment="apache2-worker less than 2.2.10-2.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055711" comment="apache2 less than 2.2.10-2.21.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091210" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1210</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1210" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1210" source="CVE"/>
	<description>
	Format string vulnerability in the PROFINET/DCP (PN-DCP) dissector in Wireshark 1.0.6 and earlier allows remote attackers to execute arbitrary code via a PN-DCP packet with format string specifiers in the station name.  NOTE: some of these details are obtained from third party information.
	</description>
 </metadata>
<!-- 9af723e66556cd28d89b219f9e202d7e -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032366" comment="wireshark less than 1.0.5-1.26.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091241" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1241</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1241" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1241" source="CVE"/>
	<description>
	Unspecified vulnerability in ClamAV before 0.95 allows remote attackers to bypass detection of malware via a modified RAR archive.
	</description>
 </metadata>
<!-- e036f8c1ee8c76653c4e246982056c02 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032190" comment="clamav less than 0.95-0.2.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091242" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1242</title>
	<affected family="unix">
		<platform>SLE 11 SERVER Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1242" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1242" source="CVE"/>
	<description>
	The vmx_set_msr function in arch/x86/kvm/vmx.c in the VMX implementation in the KVM subsystem in the Linux kernel before 2.6.29.1 on the i386 platform allows guest OS users to cause a denial of service (OOPS) by setting the EFER_LME (aka "Long mode enable") bit in the Extended Feature Enable Register (EFER) model-specific register, which is specific to the x86_64 platform.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 25ff738fb8fdfec997736b4640fc8077 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
	</criteria>
	<!-- 2773c03ae3c3dd82f505e14be9163826 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032340" comment="kernel-ppc64-extra less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 3adeb6b3cad3a08bfe6e510b3aa6d567 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032341" comment="kernel-pae-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032342" comment="kernel-xen-extra less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 43382bb2967feb0b60a732109cd020e6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032343" comment="ext4dev-kmp-default less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032344" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032347" comment="kernel-kdump less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032348" comment="kernel-ppc64-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032349" comment="kernel-ppc64 less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 7fbbc2ef69ed11f4e8ad69ed4e13c58e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032343" comment="ext4dev-kmp-default less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032352" comment="kernel-default-man less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 80db93c687bbdeb62c79f877c742f4bb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032343" comment="ext4dev-kmp-default less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032353" comment="ext4dev-kmp-pae less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032354" comment="ext4dev-kmp-vmi less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032355" comment="ext4dev-kmp-xen less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032356" comment="kernel-pae-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032357" comment="kernel-pae less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032358" comment="kernel-vmi-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032359" comment="kernel-vmi less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032360" comment="kernel-xen-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032361" comment="kernel-xen less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 9e40eecb7327c57e210599e2f65e0e81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032343" comment="ext4dev-kmp-default less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032355" comment="ext4dev-kmp-xen less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032360" comment="kernel-xen-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032361" comment="kernel-xen less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- bcf17eb6efd35f9093611e2f283ebcb4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032342" comment="kernel-xen-extra less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- bd9317f09213b352461836898559ddf6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032343" comment="ext4dev-kmp-default less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- d73c0f4846d6cc042e6cc14b4d0c152f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091252" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1252</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1252" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1252" source="CVE"/>
	<description>
	Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd in NTP before 4.2.4p7 and 4.2.5 before 4.2.5p74, when OpenSSL and autokey are enabled, allows remote attackers to execute arbitrary code via a crafted packet containing an extension field.
	</description>
 </metadata>
<!-- d95ed4c45d984fda65f18722242769a5 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032209" comment="ntp-doc less than 4.2.4p6-1.17.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032210" comment="ntp less than 4.2.4p6-1.17.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091265" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1265</title>
	<affected family="unix">
		<platform>SLE 11 SERVER Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1265" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1265" source="CVE"/>
	<description>
	Integer overflow in rose_sendmsg (sys/net/af_rose.c) in the Linux kernel 2.6.24.4, and other versions before 2.6.30-rc1, might allow remote attackers to obtain sensitive information via a large length value, which causes "garbage" memory to be sent.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 25ff738fb8fdfec997736b4640fc8077 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
	</criteria>
	<!-- 2773c03ae3c3dd82f505e14be9163826 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032340" comment="kernel-ppc64-extra less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 3adeb6b3cad3a08bfe6e510b3aa6d567 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032341" comment="kernel-pae-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032342" comment="kernel-xen-extra less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 43382bb2967feb0b60a732109cd020e6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032343" comment="ext4dev-kmp-default less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032344" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032347" comment="kernel-kdump less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032348" comment="kernel-ppc64-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032349" comment="kernel-ppc64 less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 7fbbc2ef69ed11f4e8ad69ed4e13c58e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032343" comment="ext4dev-kmp-default less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032352" comment="kernel-default-man less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 80db93c687bbdeb62c79f877c742f4bb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032343" comment="ext4dev-kmp-default less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032353" comment="ext4dev-kmp-pae less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032354" comment="ext4dev-kmp-vmi less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032355" comment="ext4dev-kmp-xen less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032356" comment="kernel-pae-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032357" comment="kernel-pae less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032358" comment="kernel-vmi-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032359" comment="kernel-vmi less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032360" comment="kernel-xen-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032361" comment="kernel-xen less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 9e40eecb7327c57e210599e2f65e0e81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032343" comment="ext4dev-kmp-default less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032355" comment="ext4dev-kmp-xen less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032360" comment="kernel-xen-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032361" comment="kernel-xen less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- bcf17eb6efd35f9093611e2f283ebcb4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032342" comment="kernel-xen-extra less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- bd9317f09213b352461836898559ddf6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032343" comment="ext4dev-kmp-default less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- d73c0f4846d6cc042e6cc14b4d0c152f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091266" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1266</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1266" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1266" source="CVE"/>
	<description>
	Unspecified vulnerability in Wireshark before 1.0.7-0.1-1 has unknown impact and attack vectors.
	</description>
 </metadata>
<!-- 9af723e66556cd28d89b219f9e202d7e -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032366" comment="wireshark less than 1.0.5-1.26.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091267" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1267</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1267" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1267" source="CVE"/>
	<description>
	Unspecified vulnerability in the LDAP dissector in Wireshark 0.99.2 through 1.0.6, when running on Windows, allows remote attackers to cause a denial of service (crash) via unknown attack vectors.
	</description>
 </metadata>
<!-- 9af723e66556cd28d89b219f9e202d7e -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032366" comment="wireshark less than 1.0.5-1.26.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091268" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1268</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1268" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1268" source="CVE"/>
	<description>
	The Check Point High-Availability Protocol (CPHAP) dissector in Wireshark 0.9.6 through 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted FWHA_MY_STATE packet.
	</description>
 </metadata>
<!-- 9af723e66556cd28d89b219f9e202d7e -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032366" comment="wireshark less than 1.0.5-1.26.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091269" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1269</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1269" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1269" source="CVE"/>
	<description>
	Unspecified vulnerability in Wireshark 0.99.6 through 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted Tektronix .rf5 file.
	</description>
 </metadata>
<!-- 9af723e66556cd28d89b219f9e202d7e -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032366" comment="wireshark less than 1.0.5-1.26.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091270" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1270</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1270" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1270" source="CVE"/>
	<description>
	libclamav/untar.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (infinite loop) via a crafted TAR file that causes (1) clamd and (2) clamscan to hang.
	</description>
 </metadata>
<!-- e036f8c1ee8c76653c4e246982056c02 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032190" comment="clamav less than 0.95-0.2.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091271" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1271</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1271" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1271" source="CVE"/>
	<description>
	The JSON_parser function (ext/json/JSON_parser.c) in PHP 5.2.x before 5.2.9 allows remote attackers to cause a denial of service (segmentation fault) via a malformed string to the json_decode API function.
	</description>
 </metadata>
<!-- 7027da9a2f33eec36d4b58d8b24d5b35 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053035" comment="apache2-mod_php5 less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053036" comment="php5-bcmath less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053037" comment="php5-bz2 less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053038" comment="php5-calendar less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053039" comment="php5-ctype less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053040" comment="php5-curl less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053041" comment="php5-dba less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053042" comment="php5-dbase less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053043" comment="php5-dom less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053044" comment="php5-exif less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053045" comment="php5-fastcgi less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053046" comment="php5-ftp less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053047" comment="php5-gd less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053048" comment="php5-gettext less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053049" comment="php5-gmp less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053050" comment="php5-hash less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053051" comment="php5-iconv less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053052" comment="php5-json less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053053" comment="php5-ldap less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053054" comment="php5-mbstring less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053055" comment="php5-mcrypt less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053056" comment="php5-mysql less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053057" comment="php5-odbc less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053058" comment="php5-openssl less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053059" comment="php5-pcntl less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053060" comment="php5-pdo less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053061" comment="php5-pear less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053062" comment="php5-pgsql less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053063" comment="php5-pspell less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053064" comment="php5-shmop less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053065" comment="php5-snmp less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053066" comment="php5-soap less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053067" comment="php5-suhosin less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053068" comment="php5-sysvmsg less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053069" comment="php5-sysvsem less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053070" comment="php5-sysvshm less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053071" comment="php5-tokenizer less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053072" comment="php5-wddx less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053073" comment="php5-xmlreader less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053074" comment="php5-xmlrpc less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053075" comment="php5-xmlwriter less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053076" comment="php5-xsl less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053077" comment="php5-zip less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053078" comment="php5-zlib less than 5.2.6-50.19.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091272" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1272</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1272" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1272" source="CVE"/>
	<description>
	The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x before 5.2.9 allows context-dependent attackers to cause a denial of service (crash) via a ZIP file that contains filenames with relative paths, which is not properly handled during extraction.
	</description>
 </metadata>
<!-- 7027da9a2f33eec36d4b58d8b24d5b35 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053035" comment="apache2-mod_php5 less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053036" comment="php5-bcmath less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053037" comment="php5-bz2 less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053038" comment="php5-calendar less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053039" comment="php5-ctype less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053040" comment="php5-curl less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053041" comment="php5-dba less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053042" comment="php5-dbase less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053043" comment="php5-dom less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053044" comment="php5-exif less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053045" comment="php5-fastcgi less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053046" comment="php5-ftp less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053047" comment="php5-gd less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053048" comment="php5-gettext less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053049" comment="php5-gmp less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053050" comment="php5-hash less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053051" comment="php5-iconv less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053052" comment="php5-json less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053053" comment="php5-ldap less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053054" comment="php5-mbstring less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053055" comment="php5-mcrypt less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053056" comment="php5-mysql less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053057" comment="php5-odbc less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053058" comment="php5-openssl less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053059" comment="php5-pcntl less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053060" comment="php5-pdo less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053061" comment="php5-pear less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053062" comment="php5-pgsql less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053063" comment="php5-pspell less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053064" comment="php5-shmop less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053065" comment="php5-snmp less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053066" comment="php5-soap less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053067" comment="php5-suhosin less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053068" comment="php5-sysvmsg less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053069" comment="php5-sysvsem less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053070" comment="php5-sysvshm less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053071" comment="php5-tokenizer less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053072" comment="php5-wddx less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053073" comment="php5-xmlreader less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053074" comment="php5-xmlrpc less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053075" comment="php5-xmlwriter less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053076" comment="php5-xsl less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053077" comment="php5-zip less than 5.2.6-50.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053078" comment="php5-zlib less than 5.2.6-50.19.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091297" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1297</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1297" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1297" source="CVE"/>
	<description>
	iscsi_discovery in open-iscsi in SUSE openSUSE 10.3 through 11.1 and SUSE Linux Enterprise (SLE) 10 SP2 and 11 allows local users to overwrite arbitrary files via a symlink attack on an unspecified temporary file that has a predictable name.
	</description>
 </metadata>
<!-- fbcc4c51379d17385396bb257e2bd261 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054839" comment="open-iscsi less than 2.0.870-26.6.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091302" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1302</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1302" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1302" source="CVE"/>
	<description>
	The browser engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to (1) nsAsyncInstantiateEvent::Run, (2) nsStyleContext::Destroy, (3) nsComputedDOMStyle::GetWidth, (4) the xslt_attributeset_ImportSameName.html test case for the XSLT stylesheet compiler, (5) nsXULDocument::SynchronizeBroadcastListener, (6) IsBindingAncestor, (7) PL_DHashTableOperate and nsEditor::EndUpdateViewBatch, and (8) gfxSkipCharsIterator::SetOffsets, and other vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8d58759fa070160f1f7d27df1de3a166 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032267" comment="MozillaFirefox-translations less than 3.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032268" comment="MozillaFirefox less than 3.0.9-0.1.1"/>
		</criteria>
	</criteria>
	<!-- fab01148f9c2f94e57e7070118a7818e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032269" comment="mozilla-xulrunner190-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032270" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032271" comment="mozilla-xulrunner190-translations less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032272" comment="mozilla-xulrunner190-x86 less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032273" comment="mozilla-xulrunner190 less than 1.9.0.9-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091303" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1303</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1303" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1303" source="CVE"/>
	<description>
	The browser engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to nsSVGElement::BindToTree.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8d58759fa070160f1f7d27df1de3a166 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032267" comment="MozillaFirefox-translations less than 3.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032268" comment="MozillaFirefox less than 3.0.9-0.1.1"/>
		</criteria>
	</criteria>
	<!-- fab01148f9c2f94e57e7070118a7818e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032269" comment="mozilla-xulrunner190-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032270" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032271" comment="mozilla-xulrunner190-translations less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032272" comment="mozilla-xulrunner190-x86 less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032273" comment="mozilla-xulrunner190 less than 1.9.0.9-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091304" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1304</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1304" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1304" source="CVE"/>
	<description>
	The JavaScript engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors involving (1) js_FindPropertyHelper, related to the definitions of Math and Date; and (2) js_CheckRedeclaration.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8d58759fa070160f1f7d27df1de3a166 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032267" comment="MozillaFirefox-translations less than 3.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032268" comment="MozillaFirefox less than 3.0.9-0.1.1"/>
		</criteria>
	</criteria>
	<!-- fab01148f9c2f94e57e7070118a7818e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032269" comment="mozilla-xulrunner190-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032270" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032271" comment="mozilla-xulrunner190-translations less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032272" comment="mozilla-xulrunner190-x86 less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032273" comment="mozilla-xulrunner190 less than 1.9.0.9-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091305" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1305</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1305" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1305" source="CVE"/>
	<description>
	The JavaScript engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors involving JSOP_DEFVAR and properties that lack the JSPROP_PERMANENT attribute.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8d58759fa070160f1f7d27df1de3a166 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032267" comment="MozillaFirefox-translations less than 3.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032268" comment="MozillaFirefox less than 3.0.9-0.1.1"/>
		</criteria>
	</criteria>
	<!-- fab01148f9c2f94e57e7070118a7818e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032269" comment="mozilla-xulrunner190-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032270" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032271" comment="mozilla-xulrunner190-translations less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032272" comment="mozilla-xulrunner190-x86 less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032273" comment="mozilla-xulrunner190 less than 1.9.0.9-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091306" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1306</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1306" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1306" source="CVE"/>
	<description>
	The jar: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not follow the Content-Disposition header of the inner URI, which allows remote attackers to conduct cross-site scripting (XSS) attacks and possibly other attacks via an uploaded .jar file with a "Content-Disposition: attachment" designation.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8d58759fa070160f1f7d27df1de3a166 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032267" comment="MozillaFirefox-translations less than 3.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032268" comment="MozillaFirefox less than 3.0.9-0.1.1"/>
		</criteria>
	</criteria>
	<!-- fab01148f9c2f94e57e7070118a7818e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032269" comment="mozilla-xulrunner190-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032270" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032271" comment="mozilla-xulrunner190-translations less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032272" comment="mozilla-xulrunner190-x86 less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032273" comment="mozilla-xulrunner190 less than 1.9.0.9-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091307" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1307</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1307" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1307" source="CVE"/>
	<description>
	The view-source: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not properly implement the Same Origin Policy, which allows remote attackers to (1) bypass crossdomain.xml restrictions and connect to arbitrary web sites via a Flash file; (2) read, create, or modify Local Shared Objects via a Flash file; or (3) bypass unspecified restrictions and render content via vectors involving a jar: URI.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8d58759fa070160f1f7d27df1de3a166 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032267" comment="MozillaFirefox-translations less than 3.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032268" comment="MozillaFirefox less than 3.0.9-0.1.1"/>
		</criteria>
	</criteria>
	<!-- fab01148f9c2f94e57e7070118a7818e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032269" comment="mozilla-xulrunner190-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032270" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032271" comment="mozilla-xulrunner190-translations less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032272" comment="mozilla-xulrunner190-x86 less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032273" comment="mozilla-xulrunner190 less than 1.9.0.9-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091308" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1308</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1308" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1308" source="CVE"/>
	<description>
	Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey allows remote attackers to inject arbitrary web script or HTML via vectors involving XBL JavaScript bindings and remote stylesheets, as exploited in the wild by a March 2009 eBay listing.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8d58759fa070160f1f7d27df1de3a166 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032267" comment="MozillaFirefox-translations less than 3.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032268" comment="MozillaFirefox less than 3.0.9-0.1.1"/>
		</criteria>
	</criteria>
	<!-- fab01148f9c2f94e57e7070118a7818e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032269" comment="mozilla-xulrunner190-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032270" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032271" comment="mozilla-xulrunner190-translations less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032272" comment="mozilla-xulrunner190-x86 less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032273" comment="mozilla-xulrunner190 less than 1.9.0.9-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091309" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1309</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1309" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1309" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey do not properly implement the Same Origin Policy for (1) XMLHttpRequest, involving a mismatch for a document's principal, and (2) XPCNativeWrapper.toString, involving an incorrect __proto__ scope, which allows remote attackers to conduct cross-site scripting (XSS) attacks and possibly other attacks via a crafted document.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8d58759fa070160f1f7d27df1de3a166 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032267" comment="MozillaFirefox-translations less than 3.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032268" comment="MozillaFirefox less than 3.0.9-0.1.1"/>
		</criteria>
	</criteria>
	<!-- fab01148f9c2f94e57e7070118a7818e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032269" comment="mozilla-xulrunner190-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032270" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032271" comment="mozilla-xulrunner190-translations less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032272" comment="mozilla-xulrunner190-x86 less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032273" comment="mozilla-xulrunner190 less than 1.9.0.9-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091310" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1310</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1310" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1310" source="CVE"/>
	<description>
	Cross-site scripting (XSS) vulnerability in the MozSearch plugin implementation in Mozilla Firefox before 3.0.9 allows user-assisted remote attackers to inject arbitrary web script or HTML via a javascript: URI in the SearchForm element.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8d58759fa070160f1f7d27df1de3a166 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032267" comment="MozillaFirefox-translations less than 3.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032268" comment="MozillaFirefox less than 3.0.9-0.1.1"/>
		</criteria>
	</criteria>
	<!-- fab01148f9c2f94e57e7070118a7818e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032269" comment="mozilla-xulrunner190-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032270" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032271" comment="mozilla-xulrunner190-translations less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032272" comment="mozilla-xulrunner190-x86 less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032273" comment="mozilla-xulrunner190 less than 1.9.0.9-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091311" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1311</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1311" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1311" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.9 and SeaMonkey before 1.1.17 allow user-assisted remote attackers to obtain sensitive information via a web page with an embedded frame, which causes POST data from an outer page to be sent to the inner frame's URL during a SAVEMODE_FILEONLY save of the inner frame.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8d58759fa070160f1f7d27df1de3a166 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032267" comment="MozillaFirefox-translations less than 3.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032268" comment="MozillaFirefox less than 3.0.9-0.1.1"/>
		</criteria>
	</criteria>
	<!-- fab01148f9c2f94e57e7070118a7818e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032269" comment="mozilla-xulrunner190-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032270" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032271" comment="mozilla-xulrunner190-translations less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032272" comment="mozilla-xulrunner190-x86 less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032273" comment="mozilla-xulrunner190 less than 1.9.0.9-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091312" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1312</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1312" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1312" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.9 and SeaMonkey 1.1.17 do not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header. NOTE: it was later reported that Firefox 3.6 a1 pre and Mozilla 1.7.x and earlier are also affected.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8d58759fa070160f1f7d27df1de3a166 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032267" comment="MozillaFirefox-translations less than 3.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032268" comment="MozillaFirefox less than 3.0.9-0.1.1"/>
		</criteria>
	</criteria>
	<!-- fab01148f9c2f94e57e7070118a7818e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032269" comment="mozilla-xulrunner190-32bit less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032270" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032271" comment="mozilla-xulrunner190-translations less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032272" comment="mozilla-xulrunner190-x86 less than 1.9.0.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032273" comment="mozilla-xulrunner190 less than 1.9.0.9-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091313" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1313</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1313" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1313" source="CVE"/>
	<description>
	The nsTextFrame::ClearTextRun function in layout/generic/nsTextFrameThebes.cpp in Mozilla Firefox 3.0.9 allows remote attackers to cause a denial of service (memory corruption) and probably execute arbitrary code via unspecified vectors.  NOTE: this vulnerability reportedly exists because of an incorrect fix for CVE-2009-1302.
	</description>
 </metadata>
<!-- c36aac5ba4baab1921d49192891f9295 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032367" comment="MozillaFirefox-translations less than 3.0.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032368" comment="MozillaFirefox less than 3.0.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032369" comment="mozilla-xulrunner190-32bit less than 1.9.0.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032370" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032371" comment="mozilla-xulrunner190-translations less than 1.9.0.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032372" comment="mozilla-xulrunner190-x86 less than 1.9.0.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032373" comment="mozilla-xulrunner190 less than 1.9.0.10-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091337" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1337</title>
	<affected family="unix">
		<platform>SLE 11 SERVER Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1337" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1337" source="CVE"/>
	<description>
	The exit_notify function in kernel/exit.c in the Linux kernel before 2.6.30-rc1 does not restrict exit signals when the CAP_KILL capability is held, which allows local users to send an arbitrary signal to a process by running a program that modifies the exit_signal field and then uses an exec system call to launch a setuid application.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 25ff738fb8fdfec997736b4640fc8077 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
	</criteria>
	<!-- 2773c03ae3c3dd82f505e14be9163826 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032340" comment="kernel-ppc64-extra less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 3adeb6b3cad3a08bfe6e510b3aa6d567 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032341" comment="kernel-pae-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032342" comment="kernel-xen-extra less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 43382bb2967feb0b60a732109cd020e6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032343" comment="ext4dev-kmp-default less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032344" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032347" comment="kernel-kdump less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032348" comment="kernel-ppc64-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032349" comment="kernel-ppc64 less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 7fbbc2ef69ed11f4e8ad69ed4e13c58e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032343" comment="ext4dev-kmp-default less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032352" comment="kernel-default-man less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 80db93c687bbdeb62c79f877c742f4bb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032343" comment="ext4dev-kmp-default less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032353" comment="ext4dev-kmp-pae less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032354" comment="ext4dev-kmp-vmi less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032355" comment="ext4dev-kmp-xen less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032356" comment="kernel-pae-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032357" comment="kernel-pae less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032358" comment="kernel-vmi-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032359" comment="kernel-vmi less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032360" comment="kernel-xen-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032361" comment="kernel-xen less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 9e40eecb7327c57e210599e2f65e0e81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032343" comment="ext4dev-kmp-default less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032355" comment="ext4dev-kmp-xen less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032360" comment="kernel-xen-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032361" comment="kernel-xen less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- bcf17eb6efd35f9093611e2f283ebcb4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032342" comment="kernel-xen-extra less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- bd9317f09213b352461836898559ddf6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032343" comment="ext4dev-kmp-default less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- d73c0f4846d6cc042e6cc14b4d0c152f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091360" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1360</title>
	<affected family="unix">
		<platform>SLE 11 SERVER Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1360" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1360" source="CVE"/>
	<description>
	The __inet6_check_established function in net/ipv6/inet6_hashtables.c in the Linux kernel before 2.6.29, when Network Namespace Support (aka NET_NS) is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via vectors involving IPv6 packets.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 25ff738fb8fdfec997736b4640fc8077 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
	</criteria>
	<!-- 2773c03ae3c3dd82f505e14be9163826 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032340" comment="kernel-ppc64-extra less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 3adeb6b3cad3a08bfe6e510b3aa6d567 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032341" comment="kernel-pae-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032342" comment="kernel-xen-extra less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 43382bb2967feb0b60a732109cd020e6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032343" comment="ext4dev-kmp-default less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032344" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032347" comment="kernel-kdump less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032348" comment="kernel-ppc64-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032349" comment="kernel-ppc64 less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 7fbbc2ef69ed11f4e8ad69ed4e13c58e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032343" comment="ext4dev-kmp-default less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032352" comment="kernel-default-man less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 80db93c687bbdeb62c79f877c742f4bb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032343" comment="ext4dev-kmp-default less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032353" comment="ext4dev-kmp-pae less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032354" comment="ext4dev-kmp-vmi less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032355" comment="ext4dev-kmp-xen less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032356" comment="kernel-pae-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032357" comment="kernel-pae less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032358" comment="kernel-vmi-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032359" comment="kernel-vmi less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032360" comment="kernel-xen-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032361" comment="kernel-xen less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 9e40eecb7327c57e210599e2f65e0e81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032343" comment="ext4dev-kmp-default less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032355" comment="ext4dev-kmp-xen less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032360" comment="kernel-xen-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032361" comment="kernel-xen less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- bcf17eb6efd35f9093611e2f283ebcb4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032342" comment="kernel-xen-extra less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- bd9317f09213b352461836898559ddf6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032343" comment="ext4dev-kmp-default less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- d73c0f4846d6cc042e6cc14b4d0c152f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091377" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1377</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1377" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1377" source="CVE"/>
	<description>
	The dtls1_buffer_record function in ssl/d1_pkt.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allows remote attackers to cause a denial of service (memory consumption) via a large series of "future epoch" DTLS records that are buffered in a queue, aka "DTLS record buffer limitation bug."
	</description>
 </metadata>
<!-- d4ddbfaf8e97ad6cc1b69035fcaf1610 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032374" comment="libopenssl0_9_8-32bit less than 0.9.8h-30.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032375" comment="libopenssl0_9_8-x86 less than 0.9.8h-30.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032376" comment="libopenssl0_9_8 less than 0.9.8h-30.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032377" comment="openssl-doc less than 0.9.8h-30.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032378" comment="openssl less than 0.9.8h-30.13.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091378" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1378</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1378" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1378" source="CVE"/>
	<description>
	Multiple memory leaks in the dtls1_process_out_of_seq_message function in ssl/d1_both.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allow remote attackers to cause a denial of service (memory consumption) via DTLS records that (1) are duplicates or (2) have sequence numbers much greater than current sequence numbers, aka "DTLS fragment handling memory leak."
	</description>
 </metadata>
<!-- d4ddbfaf8e97ad6cc1b69035fcaf1610 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032374" comment="libopenssl0_9_8-32bit less than 0.9.8h-30.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032375" comment="libopenssl0_9_8-x86 less than 0.9.8h-30.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032376" comment="libopenssl0_9_8 less than 0.9.8h-30.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032377" comment="openssl-doc less than 0.9.8h-30.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032378" comment="openssl less than 0.9.8h-30.13.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091379" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1379</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1379" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1379" source="CVE"/>
	<description>
	Use-after-free vulnerability in the dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL 1.0.0 Beta 2 allows remote attackers to cause a denial of service (openssl s_client crash) and possibly have unspecified other impact via a DTLS packet, as demonstrated by a packet from a server that uses a crafted server certificate.
	</description>
 </metadata>
<!-- d4ddbfaf8e97ad6cc1b69035fcaf1610 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032374" comment="libopenssl0_9_8-32bit less than 0.9.8h-30.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032375" comment="libopenssl0_9_8-x86 less than 0.9.8h-30.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032376" comment="libopenssl0_9_8 less than 0.9.8h-30.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032377" comment="openssl-doc less than 0.9.8h-30.13.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032378" comment="openssl less than 0.9.8h-30.13.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091385" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1385</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1385" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1385" source="CVE"/>
	<description>
	Integer underflow in the e1000_clean_rx_irq function in drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel before 2.6.30-rc8, the e1000e driver in the Linux kernel, and Intel Wired Ethernet (aka e1000) before 7.5.5 allows remote attackers to cause a denial of service (panic) via a crafted frame size.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 23bbed017e105329dd9057458aa97ecc -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053521" comment="ext4dev-kmp-default less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053522" comment="ext4dev-kmp-xen less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053523" comment="kernel-default-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053524" comment="kernel-default less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053525" comment="kernel-source less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053526" comment="kernel-syms less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053527" comment="kernel-xen-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053528" comment="kernel-xen less than 2.6.27.25-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 4b3276123e80cc0c5cc8cb8df0692921 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053521" comment="ext4dev-kmp-default less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053523" comment="kernel-default-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053524" comment="kernel-default less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053525" comment="kernel-source less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053526" comment="kernel-syms less than 2.6.27.25-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 6c01bf54efa63ecdbae0f446ff833e0a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053521" comment="ext4dev-kmp-default less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053523" comment="kernel-default-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053529" comment="kernel-default-man less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053524" comment="kernel-default less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053525" comment="kernel-source less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053526" comment="kernel-syms less than 2.6.27.25-0.1.1"/>
		</criteria>
	</criteria>
	<!-- cc0c4c5f1aaa38e41b3de12e49e991e3 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053521" comment="ext4dev-kmp-default less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053530" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053523" comment="kernel-default-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053524" comment="kernel-default less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053531" comment="kernel-kdump less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053532" comment="kernel-ppc64-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053533" comment="kernel-ppc64 less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053525" comment="kernel-source less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053526" comment="kernel-syms less than 2.6.27.25-0.1.1"/>
		</criteria>
	</criteria>
	<!-- efe472a6c3ff8e53697cca9b64ed6db5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053521" comment="ext4dev-kmp-default less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053534" comment="ext4dev-kmp-pae less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053535" comment="ext4dev-kmp-vmi less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053522" comment="ext4dev-kmp-xen less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053523" comment="kernel-default-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053524" comment="kernel-default less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053536" comment="kernel-pae-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053537" comment="kernel-pae less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053525" comment="kernel-source less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053526" comment="kernel-syms less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053538" comment="kernel-vmi-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053539" comment="kernel-vmi less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053527" comment="kernel-xen-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053528" comment="kernel-xen less than 2.6.27.25-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091386" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1386</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1386" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1386" source="CVE"/>
	<description>
	ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS ChangeCipherSpec packet that occurs before ClientHello.
	</description>
 </metadata>
<!-- 3d101627652fdb3b5c37983fb7f4ab19 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032379" comment="libopenssl0_9_8-32bit less than 0.9.8h-30.14.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032380" comment="libopenssl0_9_8-x86 less than 0.9.8h-30.14.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032381" comment="libopenssl0_9_8 less than 0.9.8h-30.14.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032382" comment="openssl-doc less than 0.9.8h-30.14.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032383" comment="openssl less than 0.9.8h-30.14.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091387" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1387</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1387" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1387" source="CVE"/>
	<description>
	The dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL before 1.0.0 Beta 2 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence DTLS handshake message, related to a "fragment bug."
	</description>
 </metadata>
<!-- 3d101627652fdb3b5c37983fb7f4ab19 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032379" comment="libopenssl0_9_8-32bit less than 0.9.8h-30.14.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032380" comment="libopenssl0_9_8-x86 less than 0.9.8h-30.14.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032381" comment="libopenssl0_9_8 less than 0.9.8h-30.14.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032382" comment="openssl-doc less than 0.9.8h-30.14.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032383" comment="openssl less than 0.9.8h-30.14.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091389" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1389</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1389" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1389" source="CVE"/>
	<description>
	Buffer overflow in the RTL8169 NIC driver (drivers/net/r8169.c) in the Linux kernel before 2.6.30 allows remote attackers to cause a denial of service (kernel memory corruption and crash) via a long packet.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0522f4d2681968d0e344aad24e0e341b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054104" comment="ext4dev-kmp-default less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054105" comment="ext4dev-kmp-pae less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054106" comment="ext4dev-kmp-vmi less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054107" comment="ext4dev-kmp-xen less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054108" comment="kernel-default-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054109" comment="kernel-default less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054110" comment="kernel-pae-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054111" comment="kernel-pae less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054112" comment="kernel-source less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054113" comment="kernel-syms less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054114" comment="kernel-vmi-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054115" comment="kernel-vmi less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054116" comment="kernel-xen-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054117" comment="kernel-xen less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 125c8b5a7b30fdb1de7b2255eb1649a7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054104" comment="ext4dev-kmp-default less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054107" comment="ext4dev-kmp-xen less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054108" comment="kernel-default-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054109" comment="kernel-default less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054112" comment="kernel-source less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054113" comment="kernel-syms less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054116" comment="kernel-xen-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054117" comment="kernel-xen less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 23bbed017e105329dd9057458aa97ecc -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053521" comment="ext4dev-kmp-default less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053522" comment="ext4dev-kmp-xen less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053523" comment="kernel-default-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053524" comment="kernel-default less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053525" comment="kernel-source less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053526" comment="kernel-syms less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053527" comment="kernel-xen-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053528" comment="kernel-xen less than 2.6.27.25-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 2959a2080579b86be5f71889c23098f9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061702" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061678" comment="kernel-kdump less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061682" comment="kernel-ppc64-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061684" comment="kernel-ppc64 less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 4b3276123e80cc0c5cc8cb8df0692921 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053521" comment="ext4dev-kmp-default less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053523" comment="kernel-default-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053524" comment="kernel-default less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053525" comment="kernel-source less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053526" comment="kernel-syms less than 2.6.27.25-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 66504af0afe753b5175112b44bc8827d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061703" comment="ext4dev-kmp-pae less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061704" comment="ext4dev-kmp-vmi less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061705" comment="ext4dev-kmp-xen less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061679" comment="kernel-pae-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061681" comment="kernel-pae less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061706" comment="kernel-vmi-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061707" comment="kernel-vmi less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 6c01bf54efa63ecdbae0f446ff833e0a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053521" comment="ext4dev-kmp-default less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053523" comment="kernel-default-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053529" comment="kernel-default-man less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053524" comment="kernel-default less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053525" comment="kernel-source less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053526" comment="kernel-syms less than 2.6.27.25-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 99ed0d9e003dfe8866db7105d4850a09 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- c8a29eec659b0b2b3e85c610b67beacd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061705" comment="ext4dev-kmp-xen less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- cc0c4c5f1aaa38e41b3de12e49e991e3 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053521" comment="ext4dev-kmp-default less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053530" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053523" comment="kernel-default-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053524" comment="kernel-default less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053531" comment="kernel-kdump less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053532" comment="kernel-ppc64-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053533" comment="kernel-ppc64 less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053525" comment="kernel-source less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053526" comment="kernel-syms less than 2.6.27.25-0.1.1"/>
		</criteria>
	</criteria>
	<!-- db255a76ea8ba6e688475154d00e78ae -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054104" comment="ext4dev-kmp-default less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054108" comment="kernel-default-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054109" comment="kernel-default less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054112" comment="kernel-source less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054113" comment="kernel-syms less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
	<!-- dfbea602689b882f72228d86a5d32316 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054104" comment="ext4dev-kmp-default less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054118" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054108" comment="kernel-default-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054109" comment="kernel-default less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054119" comment="kernel-kdump less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054120" comment="kernel-ppc64-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054121" comment="kernel-ppc64 less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054112" comment="kernel-source less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054113" comment="kernel-syms less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e37bbd585e257a0da7b25b00ac9c72ef -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054104" comment="ext4dev-kmp-default less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054108" comment="kernel-default-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054122" comment="kernel-default-man less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054109" comment="kernel-default less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054112" comment="kernel-source less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054113" comment="kernel-syms less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
	<!-- efe472a6c3ff8e53697cca9b64ed6db5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053521" comment="ext4dev-kmp-default less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053534" comment="ext4dev-kmp-pae less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053535" comment="ext4dev-kmp-vmi less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053522" comment="ext4dev-kmp-xen less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053523" comment="kernel-default-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053524" comment="kernel-default less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053536" comment="kernel-pae-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053537" comment="kernel-pae less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053525" comment="kernel-source less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053526" comment="kernel-syms less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053538" comment="kernel-vmi-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053539" comment="kernel-vmi less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053527" comment="kernel-xen-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053528" comment="kernel-xen less than 2.6.27.25-0.1.1"/>
		</criteria>
	</criteria>
	<!-- f73f22d4b713e9a7674cc8c4eebf91dd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061708" comment="kernel-default-man less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091391" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1391</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1391" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1391" source="CVE"/>
	<description>
	Off-by-one error in the inflate function in Zlib.xs in Compress::Raw::Zlib Perl module before 2.017, as used in AMaViS, SpamAssassin, and possibly other products, allows context-dependent attackers to cause a denial of service (hang or crash) via a crafted zlib compressed stream that triggers a heap-based buffer overflow, as exploited in the wild by Trojan.Downloader-71014 in June 2009.
	</description>
 </metadata>
<!-- 5e29d335b627fec85a5ced02fb051e10 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032384" comment="perl-32bit less than 5.10.0-64.43.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032385" comment="perl-base less than 5.10.0-64.43.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032386" comment="perl-doc less than 5.10.0-64.43.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032387" comment="perl-x86 less than 5.10.0-64.43.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032388" comment="perl less than 5.10.0-64.43.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091392" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1392</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1392" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1392" source="CVE"/>
	<description>
	The browser engine in Mozilla Firefox 3 before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsEventStateManager::GetContentState and nsNativeTheme::CheckBooleanAttr; (2) UnhookTextRunFromFrames and ClearAllTextRunReferences; (3) nsTextFrame::ClearTextRun; (4) IsPercentageAware; (5) PL_DHashTableFinish; (6) nsListBoxBodyFrame::GetNextItemBox; (7) AtomTableClearEntry, related to the atom table, DOM mutation events, and Unicode surrogates; (8) nsHTMLEditor::HideResizers; and (9) nsWindow::SetCursor, related to changing the cursor; and other vectors.
	</description>
 </metadata>
<!-- de3e4a68d06355acbebbe6d9a72836b8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032389" comment="MozillaFirefox-translations less than 3.0.11-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032390" comment="MozillaFirefox less than 3.0.11-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032391" comment="mozilla-xulrunner190-32bit less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032392" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032393" comment="mozilla-xulrunner190-translations less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032394" comment="mozilla-xulrunner190-x86 less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032395" comment="mozilla-xulrunner190 less than 1.9.0.11-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091439" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1439</title>
	<affected family="unix">
		<platform>SLE 11 SERVER Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1439" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1439" source="CVE"/>
	<description>
	Buffer overflow in fs/cifs/connect.c in CIFS in the Linux kernel 2.6.29 and earlier allows remote attackers to cause a denial of service (crash) via a long nativeFileSystem field in a Tree Connect response to an SMB mount request.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 25ff738fb8fdfec997736b4640fc8077 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
	</criteria>
	<!-- 2773c03ae3c3dd82f505e14be9163826 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032340" comment="kernel-ppc64-extra less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 3adeb6b3cad3a08bfe6e510b3aa6d567 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032341" comment="kernel-pae-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032342" comment="kernel-xen-extra less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 43382bb2967feb0b60a732109cd020e6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032343" comment="ext4dev-kmp-default less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032344" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032347" comment="kernel-kdump less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032348" comment="kernel-ppc64-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032349" comment="kernel-ppc64 less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 7fbbc2ef69ed11f4e8ad69ed4e13c58e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032343" comment="ext4dev-kmp-default less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032352" comment="kernel-default-man less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 80db93c687bbdeb62c79f877c742f4bb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032343" comment="ext4dev-kmp-default less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032353" comment="ext4dev-kmp-pae less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032354" comment="ext4dev-kmp-vmi less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032355" comment="ext4dev-kmp-xen less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032356" comment="kernel-pae-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032357" comment="kernel-pae less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032358" comment="kernel-vmi-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032359" comment="kernel-vmi less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032360" comment="kernel-xen-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032361" comment="kernel-xen less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 9e40eecb7327c57e210599e2f65e0e81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032343" comment="ext4dev-kmp-default less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032355" comment="ext4dev-kmp-xen less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032360" comment="kernel-xen-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032361" comment="kernel-xen less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- bcf17eb6efd35f9093611e2f283ebcb4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032342" comment="kernel-xen-extra less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- bd9317f09213b352461836898559ddf6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032343" comment="ext4dev-kmp-default less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- d73c0f4846d6cc042e6cc14b4d0c152f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091563" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1563</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1563" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1563" source="CVE"/>
	<description>
	** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2009-0689.  Reason: This candidate is a duplicate of CVE-2009-0689.  Certain codebase relationships were not originally clear.  Notes: All CVE users should reference CVE-2009-0689 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04c6e38838a85fc92531b3e56904b052 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055940" comment="mozilla-xulrunner190-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055941" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055942" comment="mozilla-xulrunner190-translations less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055943" comment="mozilla-xulrunner190-x86 less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055944" comment="mozilla-xulrunner190 less than 1.9.0.15-0.1.2"/>
		</criteria>
	</criteria>
	<!-- 49179a9289fbe778bc2320690c17d088 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055945" comment="MozillaFirefox-translations less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055946" comment="MozillaFirefox less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055947" comment="mozilla-xulrunner191-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055948" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055949" comment="mozilla-xulrunner191-translations less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055950" comment="mozilla-xulrunner191-x86 less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055951" comment="mozilla-xulrunner191 less than 1.9.1.4-2.1.3"/>
		</criteria>
	</criteria>
	<!-- ea83feacee19ffa926f0205c68b1bb6b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056065" comment="mozilla-nspr-32bit less than 4.8.2-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056066" comment="mozilla-nspr-x86 less than 4.8.2-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056067" comment="mozilla-nspr less than 4.8.2-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091571" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1571</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1571" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1571" source="CVE"/>
	<description>
	Use-after-free vulnerability in the HTML parser in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to execute arbitrary code via unspecified method calls that attempt to access freed objects in low-memory situations.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5c9ba6a33f35e3ab788cbbefde6cf8a6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058351" comment="MozillaFirefox-translations less than 3.5.8-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058352" comment="MozillaFirefox less than 3.5.8-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058353" comment="mozilla-xulrunner191-32bit less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058354" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058355" comment="mozilla-xulrunner191-translations less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058356" comment="mozilla-xulrunner191-x86 less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058357" comment="mozilla-xulrunner191 less than 1.9.1.8-1.1.1"/>
		</criteria>
	</criteria>
	<!-- deb36b8154e27ded345f064786253ca1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058358" comment="mozilla-xulrunner190-32bit less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058359" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058360" comment="mozilla-xulrunner190-translations less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058361" comment="mozilla-xulrunner190-x86 less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058362" comment="mozilla-xulrunner190 less than 1.9.0.18-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091572" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1572</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1572" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1572" source="CVE"/>
	<description>
	The BGP daemon (bgpd) in Quagga 0.99.11 and earlier allows remote attackers to cause a denial of service (crash) via an AS path containing ASN elements whose string representation is longer than expected, which triggers an assert error.
	</description>
 </metadata>
<!-- 002f521a14af9399ff450446f62551e0 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032396" comment="quagga less than 0.99.10-17.17.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091574" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1574</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1574" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1574" source="CVE"/>
	<description>
	racoon/isakmp_frag.c in ipsec-tools before 0.7.2 allows remote attackers to cause a denial of service (crash) via crafted fragmented packets without a payload, which triggers a NULL pointer dereference.
	</description>
 </metadata>
<!-- 2e1877e3ae695796f5086a970dc969cc -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032397" comment="ipsec-tools less than 0.7.1-10.31.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091630" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1630</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1630" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1630" source="CVE"/>
	<description>
	The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, when atomic_open is available, does not check execute (aka EXEC or MAY_EXEC) permission bits, which allows local users to bypass permissions and execute files, as demonstrated by files on an NFSv4 fileserver.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 23bbed017e105329dd9057458aa97ecc -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053521" comment="ext4dev-kmp-default less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053522" comment="ext4dev-kmp-xen less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053523" comment="kernel-default-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053524" comment="kernel-default less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053525" comment="kernel-source less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053526" comment="kernel-syms less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053527" comment="kernel-xen-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053528" comment="kernel-xen less than 2.6.27.25-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 4b3276123e80cc0c5cc8cb8df0692921 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053521" comment="ext4dev-kmp-default less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053523" comment="kernel-default-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053524" comment="kernel-default less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053525" comment="kernel-source less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053526" comment="kernel-syms less than 2.6.27.25-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 6c01bf54efa63ecdbae0f446ff833e0a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053521" comment="ext4dev-kmp-default less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053523" comment="kernel-default-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053529" comment="kernel-default-man less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053524" comment="kernel-default less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053525" comment="kernel-source less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053526" comment="kernel-syms less than 2.6.27.25-0.1.1"/>
		</criteria>
	</criteria>
	<!-- cc0c4c5f1aaa38e41b3de12e49e991e3 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053521" comment="ext4dev-kmp-default less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053530" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053523" comment="kernel-default-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053524" comment="kernel-default less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053531" comment="kernel-kdump less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053532" comment="kernel-ppc64-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053533" comment="kernel-ppc64 less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053525" comment="kernel-source less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053526" comment="kernel-syms less than 2.6.27.25-0.1.1"/>
		</criteria>
	</criteria>
	<!-- efe472a6c3ff8e53697cca9b64ed6db5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053521" comment="ext4dev-kmp-default less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053534" comment="ext4dev-kmp-pae less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053535" comment="ext4dev-kmp-vmi less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053522" comment="ext4dev-kmp-xen less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053523" comment="kernel-default-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053524" comment="kernel-default less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053536" comment="kernel-pae-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053537" comment="kernel-pae less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053525" comment="kernel-source less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053526" comment="kernel-syms less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053538" comment="kernel-vmi-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053539" comment="kernel-vmi less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053527" comment="kernel-xen-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053528" comment="kernel-xen less than 2.6.27.25-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091631" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1631</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1631" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1631" source="CVE"/>
	<description>
	The Mailer component in Evolution 2.26.1 and earlier uses world-readable permissions for the .evolution directory, and certain directories and files under .evolution/ related to local mail, which allows local users to obtain sensitive information by reading these files.
	</description>
 </metadata>
<!-- c7c8e33671ac7994fac1b1913560d9bd -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009058657" comment="evolution-data-server-32bit less than 2.24.1.1-11.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058658" comment="evolution-data-server-lang less than 2.24.1.1-11.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058659" comment="evolution-data-server-x86 less than 2.24.1.1-11.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058660" comment="evolution-data-server less than 2.24.1.1-11.12.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091632" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1632</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1632" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1632" source="CVE"/>
	<description>
	Multiple memory leaks in Ipsec-tools before 0.7.2 allow remote attackers to cause a denial of service (memory consumption) via vectors involving (1) signature verification during user authentication with X.509 certificates, related to the eay_check_x509sign function in src/racoon/crypto_openssl.c; and (2) the NAT-Traversal (aka NAT-T) keepalive implementation, related to src/racoon/nattraversal.c.
	</description>
 </metadata>
<!-- 2e1877e3ae695796f5086a970dc969cc -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032397" comment="ipsec-tools less than 0.7.1-10.31.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091633" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1633</title>
	<affected family="unix">
		<platform>SLE 11 SERVER Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1633" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1633" source="CVE"/>
	<description>
	Multiple buffer overflows in the cifs subsystem in the Linux kernel before 2.6.29.4 allow remote CIFS servers to cause a denial of service (memory corruption) and possibly have unspecified other impact via (1) a malformed Unicode string, related to Unicode string area alignment in fs/cifs/sess.c; or (2) long Unicode characters, related to fs/cifs/cifssmb.c and the cifs_readdir function in fs/cifs/readdir.c.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 25ff738fb8fdfec997736b4640fc8077 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
	</criteria>
	<!-- 2773c03ae3c3dd82f505e14be9163826 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032340" comment="kernel-ppc64-extra less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 3adeb6b3cad3a08bfe6e510b3aa6d567 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032341" comment="kernel-pae-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032342" comment="kernel-xen-extra less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 43382bb2967feb0b60a732109cd020e6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032343" comment="ext4dev-kmp-default less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032344" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032347" comment="kernel-kdump less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032348" comment="kernel-ppc64-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032349" comment="kernel-ppc64 less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 7fbbc2ef69ed11f4e8ad69ed4e13c58e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032343" comment="ext4dev-kmp-default less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032352" comment="kernel-default-man less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 80db93c687bbdeb62c79f877c742f4bb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032343" comment="ext4dev-kmp-default less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032353" comment="ext4dev-kmp-pae less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032354" comment="ext4dev-kmp-vmi less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032355" comment="ext4dev-kmp-xen less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032356" comment="kernel-pae-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032357" comment="kernel-pae less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032358" comment="kernel-vmi-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032359" comment="kernel-vmi less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032360" comment="kernel-xen-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032361" comment="kernel-xen less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 9e40eecb7327c57e210599e2f65e0e81 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032343" comment="ext4dev-kmp-default less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032355" comment="ext4dev-kmp-xen less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032360" comment="kernel-xen-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032361" comment="kernel-xen less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- bcf17eb6efd35f9093611e2f283ebcb4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032342" comment="kernel-xen-extra less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- bd9317f09213b352461836898559ddf6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009032343" comment="ext4dev-kmp-default less than 0_2.6.27.23_0.1-7.1.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032345" comment="kernel-default-base less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032346" comment="kernel-default less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032350" comment="kernel-source less than 2.6.27.23-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032351" comment="kernel-syms less than 2.6.27.23-0.1.1"/>
		</criteria>
	</criteria>
	<!-- d73c0f4846d6cc042e6cc14b4d0c152f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009032339" comment="kernel-default-extra less than 2.6.27.23-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091648" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1648</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1648" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1648" source="CVE"/>
	<description>
	The YaST2 LDAP module in yast2-ldap-server on SUSE Linux Enterprise Server 11 (aka SLE11) does not enable the firewall in certain circumstances involving reboots during online updates, which makes it easier for remote attackers to access network services.
	</description>
 </metadata>
<!-- a61c9004daf93521fb888db28237e4b4 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032398" comment="yast2-ldap-server less than 2.17.21-0.1.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091720" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1720</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1720" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1720" source="CVE"/>
	<description>
	Multiple integer overflows in OpenEXR 1.2.2 and 1.6.1 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors that trigger heap-based buffer overflows, related to (1) the Imf::PreviewImage::PreviewImage function and (2) compressor constructors.  NOTE: some of these details are obtained from third party information.
	</description>
 </metadata>
<!-- a9d4fc04f93289a20122dfbd5edb2ce0 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009054495" comment="OpenEXR-32bit less than 1.6.1-83.17.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054496" comment="OpenEXR-x86 less than 1.6.1-83.17.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054497" comment="OpenEXR less than 1.6.1-83.17.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091721" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1721</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1721" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1721" source="CVE"/>
	<description>
	The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a free of an uninitialized pointer.
	</description>
 </metadata>
<!-- a9d4fc04f93289a20122dfbd5edb2ce0 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009054495" comment="OpenEXR-32bit less than 1.6.1-83.17.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054496" comment="OpenEXR-x86 less than 1.6.1-83.17.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054497" comment="OpenEXR less than 1.6.1-83.17.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091725" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1725</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1725" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1725" source="CVE"/>
	<description>
	WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms; KHTML in kdelibs in KDE; QtWebKit (aka Qt toolkit); and possibly other products do not properly handle numeric character references, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.
	</description>
 </metadata>
<!-- 5444a721a519041421447122e142f15c -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009064863" comment="kdelibs3-32bit less than 3.5.10-23.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009064864" comment="kdelibs3-default-style-32bit less than 3.5.10-23.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009064865" comment="kdelibs3-default-style-x86 less than 3.5.10-23.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009064866" comment="kdelibs3-default-style less than 3.5.10-23.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009064867" comment="kdelibs3-x86 less than 3.5.10-23.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009064868" comment="kdelibs3 less than 3.5.10-23.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009064869" comment="kdelibs4-core less than 4.1.3-8.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009064870" comment="kdelibs4 less than 4.1.3-8.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009064871" comment="libkde4-32bit less than 4.1.3-8.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009064872" comment="libkde4-x86 less than 4.1.3-8.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009064873" comment="libkde4 less than 4.1.3-8.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009064874" comment="libkdecore4-32bit less than 4.1.3-8.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009064875" comment="libkdecore4-x86 less than 4.1.3-8.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009064876" comment="libkdecore4 less than 4.1.3-8.21.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091788" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1788</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1788" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1788" source="CVE"/>
	<description>
	Heap-based buffer overflow in voc_read_header in libsndfile 1.0.15 through 1.0.19, as used in Winamp 5.552 and possibly other media programs, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a VOC file with an invalid header value.
	</description>
 </metadata>
<!-- c3156403fc4e395e999fff161ceb9bea -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053458" comment="libsndfile-32bit less than 1.0.17-172.14.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053459" comment="libsndfile-x86 less than 1.0.17-172.14.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053460" comment="libsndfile less than 1.0.17-172.14.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091791" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1791</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1791" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1791" source="CVE"/>
	<description>
	Heap-based buffer overflow in aiff_read_header in libsndfile 1.0.15 through 1.0.19, as used in Winamp 5.552 and possibly other media programs, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an AIFF file with an invalid header value.
	</description>
 </metadata>
<!-- c3156403fc4e395e999fff161ceb9bea -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053458" comment="libsndfile-32bit less than 1.0.17-172.14.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053459" comment="libsndfile-x86 less than 1.0.17-172.14.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053460" comment="libsndfile less than 1.0.17-172.14.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091829" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1829</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1829" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1829" source="CVE"/>
	<description>
	Unspecified vulnerability in the PCNFSD dissector in Wireshark 0.8.20 through 1.0.7 allows remote attackers to cause a denial of service (crash) via crafted PCNFSD packets.
	</description>
 </metadata>
<!-- 9af723e66556cd28d89b219f9e202d7e -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032366" comment="wireshark less than 1.0.5-1.26.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091832" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1832</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1832" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1832" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors involving "double frame construction."
	</description>
 </metadata>
<!-- de3e4a68d06355acbebbe6d9a72836b8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032389" comment="MozillaFirefox-translations less than 3.0.11-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032390" comment="MozillaFirefox less than 3.0.11-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032391" comment="mozilla-xulrunner190-32bit less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032392" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032393" comment="mozilla-xulrunner190-translations less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032394" comment="mozilla-xulrunner190-x86 less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032395" comment="mozilla-xulrunner190 less than 1.9.0.11-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091833" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1833</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1833" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1833" source="CVE"/>
	<description>
	The JavaScript engine in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) js_LeaveSharpObject, (2) ParseXMLSource, and (3) a certain assertion in jsinterp.c; and other vectors.
	</description>
 </metadata>
<!-- de3e4a68d06355acbebbe6d9a72836b8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032389" comment="MozillaFirefox-translations less than 3.0.11-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032390" comment="MozillaFirefox less than 3.0.11-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032391" comment="mozilla-xulrunner190-32bit less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032392" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032393" comment="mozilla-xulrunner190-translations less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032394" comment="mozilla-xulrunner190-x86 less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032395" comment="mozilla-xulrunner190 less than 1.9.0.11-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091834" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1834</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1834" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1834" source="CVE"/>
	<description>
	Visual truncation vulnerability in netwerk/dns/src/nsIDNService.cpp in Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 allows remote attackers to spoof the location bar via an IDN with invalid Unicode characters that are displayed as whitespace, as demonstrated by the \u115A through \u115E characters.
	</description>
 </metadata>
<!-- de3e4a68d06355acbebbe6d9a72836b8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032389" comment="MozillaFirefox-translations less than 3.0.11-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032390" comment="MozillaFirefox less than 3.0.11-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032391" comment="mozilla-xulrunner190-32bit less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032392" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032393" comment="mozilla-xulrunner190-translations less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032394" comment="mozilla-xulrunner190-x86 less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032395" comment="mozilla-xulrunner190 less than 1.9.0.11-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091835" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1835</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1835" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1835" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 associate local documents with external domain names located after the file:// substring in a URL, which allows user-assisted remote attackers to read arbitrary cookies via a crafted HTML document, as demonstrated by a URL with file://example.com/C:/ at the beginning.
	</description>
 </metadata>
<!-- de3e4a68d06355acbebbe6d9a72836b8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032389" comment="MozillaFirefox-translations less than 3.0.11-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032390" comment="MozillaFirefox less than 3.0.11-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032391" comment="mozilla-xulrunner190-32bit less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032392" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032393" comment="mozilla-xulrunner190-translations less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032394" comment="mozilla-xulrunner190-x86 less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032395" comment="mozilla-xulrunner190 less than 1.9.0.11-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091836" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1836</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1836" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1836" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 use the HTTP Host header to determine the context of a document provided in a non-200 CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.
	</description>
 </metadata>
<!-- de3e4a68d06355acbebbe6d9a72836b8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032389" comment="MozillaFirefox-translations less than 3.0.11-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032390" comment="MozillaFirefox less than 3.0.11-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032391" comment="mozilla-xulrunner190-32bit less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032392" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032393" comment="mozilla-xulrunner190-translations less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032394" comment="mozilla-xulrunner190-x86 less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032395" comment="mozilla-xulrunner190 less than 1.9.0.11-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091837" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1837</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1837" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1837" source="CVE"/>
	<description>
	Race condition in the NPObjWrapper_NewResolve function in modules/plugin/base/src/nsJSNPRuntime.cpp in xul.dll in Mozilla Firefox 3 before 3.0.11 might allow remote attackers to execute arbitrary code via a page transition during Java applet loading, related to a use-after-free vulnerability for memory associated with a destroyed Java object.
	</description>
 </metadata>
<!-- de3e4a68d06355acbebbe6d9a72836b8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032389" comment="MozillaFirefox-translations less than 3.0.11-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032390" comment="MozillaFirefox less than 3.0.11-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032391" comment="mozilla-xulrunner190-32bit less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032392" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032393" comment="mozilla-xulrunner190-translations less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032394" comment="mozilla-xulrunner190-x86 less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032395" comment="mozilla-xulrunner190 less than 1.9.0.11-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091838" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1838</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1838" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1838" source="CVE"/>
	<description>
	The garbage-collection implementation in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 sets an element's owner document to null in unspecified circumstances, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted event handler, related to an incorrect context for this event handler.
	</description>
 </metadata>
<!-- de3e4a68d06355acbebbe6d9a72836b8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032389" comment="MozillaFirefox-translations less than 3.0.11-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032390" comment="MozillaFirefox less than 3.0.11-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032391" comment="mozilla-xulrunner190-32bit less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032392" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032393" comment="mozilla-xulrunner190-translations less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032394" comment="mozilla-xulrunner190-x86 less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032395" comment="mozilla-xulrunner190 less than 1.9.0.11-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091839" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1839</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1839" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1839" source="CVE"/>
	<description>
	Mozilla Firefox 3 before 3.0.11 associates an incorrect principal with a file: URL loaded through the location bar, which allows user-assisted remote attackers to bypass intended access restrictions and read files via a crafted HTML document, aka a "file-URL-to-file-URL scripting" attack.
	</description>
 </metadata>
<!-- de3e4a68d06355acbebbe6d9a72836b8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032389" comment="MozillaFirefox-translations less than 3.0.11-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032390" comment="MozillaFirefox less than 3.0.11-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032391" comment="mozilla-xulrunner190-32bit less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032392" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032393" comment="mozilla-xulrunner190-translations less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032394" comment="mozilla-xulrunner190-x86 less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032395" comment="mozilla-xulrunner190 less than 1.9.0.11-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091840" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1840</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1840" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1840" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.11, Thunderbird, and SeaMonkey do not check content policy before loading a script file into a XUL document, which allows remote attackers to bypass intended access restrictions via a crafted HTML document, as demonstrated by a "web bug" in an e-mail message, or web script or an advertisement in a web page.
	</description>
 </metadata>
<!-- de3e4a68d06355acbebbe6d9a72836b8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032389" comment="MozillaFirefox-translations less than 3.0.11-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032390" comment="MozillaFirefox less than 3.0.11-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032391" comment="mozilla-xulrunner190-32bit less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032392" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032393" comment="mozilla-xulrunner190-translations less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032394" comment="mozilla-xulrunner190-x86 less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032395" comment="mozilla-xulrunner190 less than 1.9.0.11-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091841" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1841</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1841" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1841" source="CVE"/>
	<description>
	js/src/xpconnect/src/xpcwrappedjsclass.cpp in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to execute arbitrary web script with the privileges of a chrome object, as demonstrated by the browser sidebar and the FeedWriter.
	</description>
 </metadata>
<!-- de3e4a68d06355acbebbe6d9a72836b8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032389" comment="MozillaFirefox-translations less than 3.0.11-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032390" comment="MozillaFirefox less than 3.0.11-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032391" comment="mozilla-xulrunner190-32bit less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032392" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032393" comment="mozilla-xulrunner190-translations less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032394" comment="mozilla-xulrunner190-x86 less than 1.9.0.11-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032395" comment="mozilla-xulrunner190 less than 1.9.0.11-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091882" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1882</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1882" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1882" source="CVE"/>
	<description>
	Integer overflow in the XMakeImage function in magick/xwindow.c in ImageMagick 6.5.2-8, and GraphicsMagick, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF file, which triggers a buffer overflow.  NOTE: some of these details are obtained from third party information.
	</description>
 </metadata>
<!-- f6592befc7ebf5f90a71638a03946d67 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032399" comment="libMagickCore1-32bit less than 6.4.3.6-7.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032400" comment="libMagickCore1 less than 6.4.3.6-7.19.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091886" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1886</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1886" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1886" source="CVE"/>
	<description>
	Multiple format string vulnerabilities in client/client.c in smbclient in Samba 3.2.0 through 3.2.12 might allow context-dependent attackers to execute arbitrary code via format string specifiers in a filename.
	</description>
 </metadata>
<!-- 3ac5dcd69a8c15958c4ed600c1a9ee9e -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053220" comment="cifs-mount less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053221" comment="ldapsmb less than 1.34b-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053222" comment="libsmbclient0-32bit less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053223" comment="libsmbclient0-x86 less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053224" comment="libsmbclient0 less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053225" comment="libtalloc1-32bit less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053226" comment="libtalloc1-x86 less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053227" comment="libtalloc1 less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053228" comment="libtdb1-32bit less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053229" comment="libtdb1-x86 less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053230" comment="libtdb1 less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053231" comment="libwbclient0-32bit less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053232" comment="libwbclient0-x86 less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053233" comment="libwbclient0 less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053234" comment="samba-32bit less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053235" comment="samba-client-32bit less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053236" comment="samba-client-x86 less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053237" comment="samba-client less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053238" comment="samba-krb-printing less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053239" comment="samba-winbind-32bit less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053240" comment="samba-winbind-x86 less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053241" comment="samba-winbind less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053242" comment="samba-x86 less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053243" comment="samba less than 3.2.7-11.7.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091888" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1888</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1888" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1888" source="CVE"/>
	<description>
	The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x before 3.0.35, 3.1.x and 3.2.x before 3.2.13, and 3.3.x before 3.3.6, when dos filemode is enabled, allows remote attackers to modify access control lists for files via vectors related to read access to uninitialized memory.
	</description>
 </metadata>
<!-- 3ac5dcd69a8c15958c4ed600c1a9ee9e -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053220" comment="cifs-mount less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053221" comment="ldapsmb less than 1.34b-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053222" comment="libsmbclient0-32bit less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053223" comment="libsmbclient0-x86 less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053224" comment="libsmbclient0 less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053225" comment="libtalloc1-32bit less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053226" comment="libtalloc1-x86 less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053227" comment="libtalloc1 less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053228" comment="libtdb1-32bit less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053229" comment="libtdb1-x86 less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053230" comment="libtdb1 less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053231" comment="libwbclient0-32bit less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053232" comment="libwbclient0-x86 less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053233" comment="libwbclient0 less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053234" comment="samba-32bit less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053235" comment="samba-client-32bit less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053236" comment="samba-client-x86 less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053237" comment="samba-client less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053238" comment="samba-krb-printing less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053239" comment="samba-winbind-32bit less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053240" comment="samba-winbind-x86 less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053241" comment="samba-winbind less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053242" comment="samba-x86 less than 3.2.7-11.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053243" comment="samba less than 3.2.7-11.7.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091890" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1890</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1890" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1890" source="CVE"/>
	<description>
	The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests.
	</description>
 </metadata>
<!-- ca7f5abf8025ba6ef69af14cd6570458 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009055706" comment="apache2-doc less than 2.2.10-2.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055707" comment="apache2-example-pages less than 2.2.10-2.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055708" comment="apache2-prefork less than 2.2.10-2.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055709" comment="apache2-utils less than 2.2.10-2.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055710" comment="apache2-worker less than 2.2.10-2.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055711" comment="apache2 less than 2.2.10-2.21.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091891" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1891</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1891" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1891" source="CVE"/>
	<description>
	The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption).
	</description>
 </metadata>
<!-- ca7f5abf8025ba6ef69af14cd6570458 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009055706" comment="apache2-doc less than 2.2.10-2.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055707" comment="apache2-example-pages less than 2.2.10-2.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055708" comment="apache2-prefork less than 2.2.10-2.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055709" comment="apache2-utils less than 2.2.10-2.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055710" comment="apache2-worker less than 2.2.10-2.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055711" comment="apache2 less than 2.2.10-2.21.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091895" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1895</title>
	<affected family="unix">
		<platform>SLE 11 SERVER Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1895" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1895" source="CVE"/>
	<description>
	The personality subsystem in the Linux kernel before 2.6.31-rc3 has a PER_CLEAR_ON_SETID setting that does not clear the ADDR_COMPAT_LAYOUT and MMAP_PAGE_ZERO flags when executing a setuid or setgid program, which makes it easier for local users to leverage the details of memory usage to (1) conduct NULL pointer dereference attacks, (2) bypass the mmap_min_addr protection mechanism, or (3) defeat address space layout randomization (ASLR).
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0522f4d2681968d0e344aad24e0e341b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054104" comment="ext4dev-kmp-default less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054105" comment="ext4dev-kmp-pae less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054106" comment="ext4dev-kmp-vmi less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054107" comment="ext4dev-kmp-xen less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054108" comment="kernel-default-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054109" comment="kernel-default less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054110" comment="kernel-pae-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054111" comment="kernel-pae less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054112" comment="kernel-source less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054113" comment="kernel-syms less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054114" comment="kernel-vmi-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054115" comment="kernel-vmi less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054116" comment="kernel-xen-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054117" comment="kernel-xen less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 05f76631eabd3855f111551f51ab13d2 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054182" comment="kernel-default-extra less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054184" comment="kernel-xen-extra less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 0844fc389fa0754c6d749018876ba285 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054182" comment="kernel-default-extra less than 2.6.27.29-0.1.1"/>
	</criteria>
	<!-- 09b0545deb81e06fa6e4b985a90c0f34 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054182" comment="kernel-default-extra less than 2.6.27.29-0.1.1"/>
	</criteria>
	<!-- 125c8b5a7b30fdb1de7b2255eb1649a7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054104" comment="ext4dev-kmp-default less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054107" comment="ext4dev-kmp-xen less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054108" comment="kernel-default-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054109" comment="kernel-default less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054112" comment="kernel-source less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054113" comment="kernel-syms less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054116" comment="kernel-xen-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054117" comment="kernel-xen less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 974d6162c77e4c04686097bbc340a8f1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054182" comment="kernel-default-extra less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054213" comment="kernel-ppc64-extra less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
	<!-- dafb63e21cf40b926282c5b4b988d0c4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054182" comment="kernel-default-extra less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054183" comment="kernel-pae-extra less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054184" comment="kernel-xen-extra less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
	<!-- db255a76ea8ba6e688475154d00e78ae -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054104" comment="ext4dev-kmp-default less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054108" comment="kernel-default-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054109" comment="kernel-default less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054112" comment="kernel-source less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054113" comment="kernel-syms less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
	<!-- dfbea602689b882f72228d86a5d32316 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054104" comment="ext4dev-kmp-default less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054118" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054108" comment="kernel-default-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054109" comment="kernel-default less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054119" comment="kernel-kdump less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054120" comment="kernel-ppc64-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054121" comment="kernel-ppc64 less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054112" comment="kernel-source less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054113" comment="kernel-syms less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e37bbd585e257a0da7b25b00ac9c72ef -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054104" comment="ext4dev-kmp-default less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054108" comment="kernel-default-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054122" comment="kernel-default-man less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054109" comment="kernel-default less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054112" comment="kernel-source less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054113" comment="kernel-syms less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091904" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1904</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1904" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1904" source="CVE"/>
	<description>
	The BigDecimal library in Ruby 1.8.6 before p369 and 1.8.7 before p173 allows context-dependent attackers to cause a denial of service (application crash) via a string argument that represents a large number, as demonstrated by an attempted conversion to the Float data type.
	</description>
 </metadata>
<!-- c8369586b31bf86da2231acd00ad8f78 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053192" comment="ruby-doc-html less than 1.8.7.p72-5.22.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053193" comment="ruby-tk less than 1.8.7.p72-5.22.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053194" comment="ruby less than 1.8.7.p72-5.22.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091932" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1932</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1932" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1932" source="CVE"/>
	<description>
	Multiple integer overflows in the (1) user_info_callback, (2) user_endrow_callback, and (3) gst_pngdec_task functions (ext/libpng/gstpngdec.c) in GStreamer Good Plug-ins (aka gst-plugins-good or gstreamer-plugins-good) 0.10.15 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted PNG file, which triggers a buffer overflow.
	</description>
 </metadata>
<!-- e3f7d863f6867202ad78ce023a8c99e9 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053079" comment="gstreamer-0_10-plugins-good-doc less than 0.10.10-4.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053080" comment="gstreamer-0_10-plugins-good-lang less than 0.10.10-4.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053081" comment="gstreamer-0_10-plugins-good less than 0.10.10-4.9.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091955" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1955</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1955" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1955" source="CVE"/>
	<description>
	The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564.
	</description>
 </metadata>
<!-- 251e677d425d0b40e5a4c63e49b53955 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053393" comment="libapr-util1-32bit less than 1.3.4-12.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053394" comment="libapr-util1 less than 1.3.4-12.19.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091956" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1956</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1956" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1956" source="CVE"/>
	<description>
	Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.
	</description>
 </metadata>
<!-- 251e677d425d0b40e5a4c63e49b53955 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053393" comment="libapr-util1-32bit less than 1.3.4-12.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053394" comment="libapr-util1 less than 1.3.4-12.19.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091957" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1957</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1957" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1957" source="CVE"/>
	<description>
	charon/sa/ike_sa.c in the charon daemon in strongSWAN before 4.3.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an invalid IKE_SA_INIT request that triggers "an incomplete state," followed by a CREATE_CHILD_SA request.
	</description>
 </metadata>
<!-- f4c39e4414e77c9ed8b34d8cf86dbb93 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032401" comment="strongswan-doc less than 4.2.8-1.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032402" comment="strongswan less than 4.2.8-1.23.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091958" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1958</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1958" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1958" source="CVE"/>
	<description>
	charon/sa/tasks/child_create.c in the charon daemon in strongSWAN before 4.3.1 switches the NULL checks for TSi and TSr payloads, which allows remote attackers to cause a denial of service via an IKE_AUTH request without a (1) TSi or (2) TSr traffic selector.
	</description>
 </metadata>
<!-- f4c39e4414e77c9ed8b34d8cf86dbb93 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032401" comment="strongswan-doc less than 4.2.8-1.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009032402" comment="strongswan less than 4.2.8-1.23.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091961" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-1961</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-1961" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1961" source="CVE"/>
	<description>
	The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, 2.6.29 before 2.6.29.4, and possibly other versions down to 2.6.19 allows local users to cause a denial of service (prevention of file creation and removal) via a series of splice system calls that trigger a deadlock between the generic_file_splice_write, splice_from_pipe, and ocfs2_file_splice_write functions.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 23bbed017e105329dd9057458aa97ecc -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053521" comment="ext4dev-kmp-default less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053522" comment="ext4dev-kmp-xen less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053523" comment="kernel-default-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053524" comment="kernel-default less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053525" comment="kernel-source less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053526" comment="kernel-syms less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053527" comment="kernel-xen-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053528" comment="kernel-xen less than 2.6.27.25-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 4b3276123e80cc0c5cc8cb8df0692921 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053521" comment="ext4dev-kmp-default less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053523" comment="kernel-default-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053524" comment="kernel-default less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053525" comment="kernel-source less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053526" comment="kernel-syms less than 2.6.27.25-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 6c01bf54efa63ecdbae0f446ff833e0a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053521" comment="ext4dev-kmp-default less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053523" comment="kernel-default-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053529" comment="kernel-default-man less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053524" comment="kernel-default less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053525" comment="kernel-source less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053526" comment="kernel-syms less than 2.6.27.25-0.1.1"/>
		</criteria>
	</criteria>
	<!-- cc0c4c5f1aaa38e41b3de12e49e991e3 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053521" comment="ext4dev-kmp-default less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053530" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053523" comment="kernel-default-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053524" comment="kernel-default less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053531" comment="kernel-kdump less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053532" comment="kernel-ppc64-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053533" comment="kernel-ppc64 less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053525" comment="kernel-source less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053526" comment="kernel-syms less than 2.6.27.25-0.1.1"/>
		</criteria>
	</criteria>
	<!-- efe472a6c3ff8e53697cca9b64ed6db5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053521" comment="ext4dev-kmp-default less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053534" comment="ext4dev-kmp-pae less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053535" comment="ext4dev-kmp-vmi less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053522" comment="ext4dev-kmp-xen less than 0_2.6.27.25_0.1-7.1.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053523" comment="kernel-default-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053524" comment="kernel-default less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053536" comment="kernel-pae-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053537" comment="kernel-pae less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053525" comment="kernel-source less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053526" comment="kernel-syms less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053538" comment="kernel-vmi-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053539" comment="kernel-vmi less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053527" comment="kernel-xen-base less than 2.6.27.25-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053528" comment="kernel-xen less than 2.6.27.25-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092042" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2042</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2042" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2042" source="CVE"/>
	<description>
	libpng before 1.2.37 does not properly parse 1-bit interlaced images with width values that are not divisible by 8, which causes libpng to include uninitialized bits in certain rows of a PNG file and might allow remote attackers to read portions of sensitive memory via "out-of-bounds pixels" in the file.
	</description>
 </metadata>
<!-- 347346dddae72c6d0521d44e36060298 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053355" comment="libpng12-0-32bit less than 1.2.31-5.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053356" comment="libpng12-0-x86 less than 1.2.31-5.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053357" comment="libpng12-0 less than 1.2.31-5.12.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092185" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2185</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2185" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2185" source="CVE"/>
	<description>
	The ASN.1 parser (pluto/asn1.c, libstrongswan/asn1/asn1.c, libstrongswan/asn1/asn1_parser.c) in (a) strongSwan 2.8 before 2.8.10, 4.2 before 4.2.16, and 4.3 before 4.3.2; and (b) openSwan 2.6 before 2.6.22 and 2.4 before 2.4.15 allows remote attackers to cause a denial of service (pluto IKE daemon crash) via an X.509 certificate with (1) crafted Relative Distinguished Names (RDNs), (2) a crafted UTCTIME string, or (3) a crafted GENERALIZEDTIME string.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- ae9720d6748a29ac275534cbfa54dfaf -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009052416" comment="strongswan-doc less than 4.2.8-1.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009052417" comment="strongswan less than 4.2.8-1.24.1"/>
		</criteria>
	</criteria>
	<!-- c1b1d2d70b2275e802a8c202b8e6dc63 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053445" comment="openswan-doc less than 2.6.16-1.33.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053446" comment="openswan less than 2.6.16-1.33.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092285" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2285</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2285" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2285" source="CVE"/>
	<description>
	Buffer underflow in the LZWDecodeCompat function in libtiff 3.8.2 allows context-dependent attackers to cause a denial of service (crash) via a crafted TIFF image, a different vulnerability than CVE-2008-2327.
	</description>
 </metadata>
<!-- 2260ae46f623edd1c3e7ba019b3a771d -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053719" comment="libtiff3-32bit less than 3.8.2-141.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053720" comment="libtiff3-x86 less than 3.8.2-141.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053721" comment="libtiff3 less than 3.8.2-141.7.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092287" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2287</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2287" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2287" source="CVE"/>
	<description>
	The kvm_arch_vcpu_ioctl_set_sregs function in the KVM in Linux kernel 2.6 before 2.6.30, when running on x86 systems, does not validate the page table root in a KVM_SET_SREGS call, which allows local users to cause a denial of service (crash or hang) via a crafted cr3 value, which triggers a NULL pointer dereference in the gfn_to_rmap function.
	</description>
 </metadata>
<!-- 3b73baf8f221b972ab3ab4de3e9c3406 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009054848" comment="kvm-kmp-default less than 78.2.6.30.1_2.6.27.25_0.1-0.2.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054849" comment="kvm-kmp-pae less than 78.2.6.30.1_2.6.27.25_0.1-0.2.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054850" comment="kvm less than 78.0.10.5-0.2.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092288" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2288</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2288" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2288" source="CVE"/>
	<description>
	statuswml.cgi in Nagios before 3.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) ping or (2) Traceroute parameters.
	</description>
 </metadata>
<!-- 651ea18d7676831b2d0ed7b899dab2b4 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053627" comment="nagios-www less than 3.0.6-1.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053628" comment="nagios less than 3.0.6-1.21.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092347" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2347</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2347" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2347" source="CVE"/>
	<description>
	Multiple integer overflows in inter-color spaces conversion tools in libtiff 3.8 through 3.8.2, 3.9, and 4.0 allow context-dependent attackers to execute arbitrary code via a TIFF image with large (1) width and (2) height values, which triggers a heap-based buffer overflow in the (a) cvt_whole_image function in tiff2rgba and (b) tiffcvt function in rgb2ycbcr.
	</description>
 </metadata>
<!-- ac9a395c3876a17a1dea5f9f475054d1 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009054049" comment="libtiff3-32bit less than 3.8.2-141.8.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054050" comment="libtiff3-x86 less than 3.8.2-141.8.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054051" comment="libtiff3 less than 3.8.2-141.8.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054052" comment="tiff less than 3.8.2-141.8.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092404" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2404</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2404" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2404" source="CVE"/>
	<description>
	Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thunderbird, SeaMonkey, Evolution, Pidgin, and AOL Instant Messenger (AIM), allows remote SSL servers to cause a denial of service (application crash) or possibly execute arbitrary code via a long domain name in the subject's Common Name (CN) field of an X.509 certificate, related to the cert_TestHostName function.
	</description>
 </metadata>
<!-- 5d306b6d7dd56f9b174098ca596f270a -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053937" comment="libfreebl3-32bit less than 3.12.3.1-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053938" comment="libfreebl3-x86 less than 3.12.3.1-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053939" comment="libfreebl3 less than 3.12.3.1-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053940" comment="mozilla-nss-32bit less than 3.12.3.1-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053941" comment="mozilla-nss-tools less than 3.12.3.1-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053942" comment="mozilla-nss-x86 less than 3.12.3.1-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053943" comment="mozilla-nss less than 3.12.3.1-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092406" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2406</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2406" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2406" source="CVE"/>
	<description>
	Stack-based buffer overflow in the parse_tag_11_packet function in fs/ecryptfs/keystore.c in the eCryptfs subsystem in the Linux kernel before 2.6.30.4 allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving a crafted eCryptfs file, related to not ensuring that the key signature length in a Tag 11 packet is compatible with the key signature buffer size.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0522f4d2681968d0e344aad24e0e341b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054104" comment="ext4dev-kmp-default less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054105" comment="ext4dev-kmp-pae less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054106" comment="ext4dev-kmp-vmi less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054107" comment="ext4dev-kmp-xen less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054108" comment="kernel-default-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054109" comment="kernel-default less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054110" comment="kernel-pae-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054111" comment="kernel-pae less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054112" comment="kernel-source less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054113" comment="kernel-syms less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054114" comment="kernel-vmi-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054115" comment="kernel-vmi less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054116" comment="kernel-xen-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054117" comment="kernel-xen less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 125c8b5a7b30fdb1de7b2255eb1649a7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054104" comment="ext4dev-kmp-default less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054107" comment="ext4dev-kmp-xen less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054108" comment="kernel-default-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054109" comment="kernel-default less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054112" comment="kernel-source less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054113" comment="kernel-syms less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054116" comment="kernel-xen-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054117" comment="kernel-xen less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
	<!-- db255a76ea8ba6e688475154d00e78ae -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054104" comment="ext4dev-kmp-default less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054108" comment="kernel-default-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054109" comment="kernel-default less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054112" comment="kernel-source less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054113" comment="kernel-syms less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
	<!-- dfbea602689b882f72228d86a5d32316 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054104" comment="ext4dev-kmp-default less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054118" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054108" comment="kernel-default-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054109" comment="kernel-default less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054119" comment="kernel-kdump less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054120" comment="kernel-ppc64-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054121" comment="kernel-ppc64 less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054112" comment="kernel-source less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054113" comment="kernel-syms less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e37bbd585e257a0da7b25b00ac9c72ef -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054104" comment="ext4dev-kmp-default less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054108" comment="kernel-default-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054122" comment="kernel-default-man less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054109" comment="kernel-default less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054112" comment="kernel-source less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054113" comment="kernel-syms less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092407" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2407</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2407" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2407" source="CVE"/>
	<description>
	Heap-based buffer overflow in the parse_tag_3_packet function in fs/ecryptfs/keystore.c in the eCryptfs subsystem in the Linux kernel before 2.6.30.4 allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving a crafted eCryptfs file, related to a large encrypted key size in a Tag 3 packet.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0522f4d2681968d0e344aad24e0e341b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054104" comment="ext4dev-kmp-default less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054105" comment="ext4dev-kmp-pae less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054106" comment="ext4dev-kmp-vmi less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054107" comment="ext4dev-kmp-xen less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054108" comment="kernel-default-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054109" comment="kernel-default less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054110" comment="kernel-pae-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054111" comment="kernel-pae less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054112" comment="kernel-source less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054113" comment="kernel-syms less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054114" comment="kernel-vmi-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054115" comment="kernel-vmi less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054116" comment="kernel-xen-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054117" comment="kernel-xen less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 125c8b5a7b30fdb1de7b2255eb1649a7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054104" comment="ext4dev-kmp-default less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054107" comment="ext4dev-kmp-xen less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054108" comment="kernel-default-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054109" comment="kernel-default less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054112" comment="kernel-source less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054113" comment="kernel-syms less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054116" comment="kernel-xen-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054117" comment="kernel-xen less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
	<!-- db255a76ea8ba6e688475154d00e78ae -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054104" comment="ext4dev-kmp-default less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054108" comment="kernel-default-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054109" comment="kernel-default less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054112" comment="kernel-source less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054113" comment="kernel-syms less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
	<!-- dfbea602689b882f72228d86a5d32316 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054104" comment="ext4dev-kmp-default less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054118" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054108" comment="kernel-default-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054109" comment="kernel-default less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054119" comment="kernel-kdump less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054120" comment="kernel-ppc64-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054121" comment="kernel-ppc64 less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054112" comment="kernel-source less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054113" comment="kernel-syms less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e37bbd585e257a0da7b25b00ac9c72ef -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054104" comment="ext4dev-kmp-default less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054108" comment="kernel-default-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054122" comment="kernel-default-man less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054109" comment="kernel-default less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054112" comment="kernel-source less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054113" comment="kernel-syms less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092408" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2408</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2408" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2408" source="CVE"/>
	<description>
	Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority. NOTE: this was originally reported for Firefox before 3.5.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5d306b6d7dd56f9b174098ca596f270a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053937" comment="libfreebl3-32bit less than 3.12.3.1-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053938" comment="libfreebl3-x86 less than 3.12.3.1-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053939" comment="libfreebl3 less than 3.12.3.1-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053940" comment="mozilla-nss-32bit less than 3.12.3.1-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053941" comment="mozilla-nss-tools less than 3.12.3.1-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053942" comment="mozilla-nss-x86 less than 3.12.3.1-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053943" comment="mozilla-nss less than 3.12.3.1-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 8b6ad83a2d239c9f63b11481566420f0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054902" comment="libldap-2_4-2-32bit less than 2.4.12-7.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054903" comment="libldap-2_4-2-x86 less than 2.4.12-7.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054904" comment="libldap-2_4-2 less than 2.4.12-7.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054905" comment="openldap2-back-meta less than 2.4.12-7.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054906" comment="openldap2-client less than 2.4.12-7.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054907" comment="openldap2 less than 2.4.12-7.18.1"/>
		</criteria>
	</criteria>
	<!-- cc9c5a6c5fd4bd88c6a42dc93653674b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054908" comment="mutt less than 1.5.17-42.32.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054909" comment="mutt less than 1.5.17-42.32.2"/>
		</criteria>
	</criteria>
	<!-- db036d6c88b93b6c89d6d75d9b617dce -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055772" comment="libneon27-32bit less than 0.28.3-2.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055773" comment="libneon27-x86 less than 0.28.3-2.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055774" comment="libneon27 less than 0.28.3-2.12.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055775" comment="neon less than 0.28.3-2.12.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092412" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2412</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2412" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2412" source="CVE"/>
	<description>
	Multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (aka APR-util) 0.9.x and 1.3.x allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger crafted calls to the (1) allocator_alloc or (2) apr_palloc function in memory/unix/apr_pools.c in APR; or crafted calls to the (3) apr_rmm_malloc, (4) apr_rmm_calloc, or (5) apr_rmm_realloc function in misc/apr_rmm.c in APR-util; leading to buffer overflows.  NOTE: some of these details are obtained from third party information.
	</description>
 </metadata>
<!-- 015ff2ecbdd9a5bbf220d3d2b1722666 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009055473" comment="libapr-util1-32bit less than 1.3.4-12.20.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055474" comment="libapr-util1 less than 1.3.4-12.20.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055475" comment="libapr1-32bit less than 1.3.3-11.16.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055476" comment="libapr1 less than 1.3.3-11.16.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092416" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2416</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2416" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2416" source="CVE"/>
	<description>
	Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.
	</description>
 </metadata>
<!-- 829b31ab282bbd0be50115fc32887eb8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053779" comment="libxml2-32bit less than 2.7.1-10.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053780" comment="libxml2-doc less than 2.7.1-10.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053781" comment="libxml2-x86 less than 2.7.1-10.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053782" comment="libxml2 less than 2.7.1-10.9.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092417" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2417</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2417" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2417" source="CVE"/>
	<description>
	lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
	</description>
 </metadata>
<!-- bd3c8afff979262cbf1ca535c4eb2e68 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053896" comment="curl less than 7.19.0-11.22.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053897" comment="keyutils-libs-32bit less than 1.2-107.22"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053898" comment="keyutils-libs-x86 less than 1.2-107.22"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053899" comment="keyutils-libs less than 1.2-107.22"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053900" comment="libcurl4-32bit less than 7.19.0-11.22.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053901" comment="libcurl4-x86 less than 7.19.0-11.22.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053902" comment="libcurl4 less than 7.19.0-11.22.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053903" comment="libidn-32bit less than 1.10-3.18"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053904" comment="libidn-x86 less than 1.10-3.18"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053905" comment="libidn less than 1.10-3.18"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092446" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2446</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2446" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2446" source="CVE"/>
	<description>
	Multiple format string vulnerabilities in the dispatch_command function in libmysqld/sql_parse.cc in mysqld in MySQL 4.0.0 through 5.0.83 allow remote authenticated users to cause a denial of service (daemon crash) and possibly have unspecified other impact via format string specifiers in a database name in a (1) COM_CREATE_DB or (2) COM_DROP_DB request.  NOTE: some of these details are obtained from third party information.
	</description>
 </metadata>
<!-- 6b4ffc010711f4a40d2054f5fc473cc7 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009054286" comment="libmysqlclient15-32bit less than 5.0.67-13.16.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054287" comment="libmysqlclient15-x86 less than 5.0.67-13.16.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054288" comment="libmysqlclient15 less than 5.0.67-13.16.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054289" comment="libmysqlclient_r15 less than 5.0.67-13.16.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054290" comment="mysql-Max less than 5.0.67-13.16.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054291" comment="mysql-client less than 5.0.67-13.16.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054292" comment="mysql less than 5.0.67-13.16.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092462" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2462</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2462" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2462" source="CVE"/>
	<description>
	The browser engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) the frame chain and synchronous events, (2) a SetMayHaveFrame assertion and nsCSSFrameConstructor::CreateFloatingLetterFrame, (3) nsCSSFrameConstructor::ConstructFrame, (4) the child list and initial reflow, (5) GetLastSpecialSibling, (6) nsFrameManager::GetPrimaryFrameFor and MathML, (7) nsFrame::GetBoxAscent, (8) nsCSSFrameConstructor::AdjustParentFrame, (9) nsDOMOfflineResourceList, and (10) nsContentUtils::ComparePosition.
	</description>
 </metadata>
<!-- d3be5c712e2e2706b7b11ecd08d9e22f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053589" comment="MozillaFirefox-translations less than 3.0.12-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053590" comment="MozillaFirefox less than 3.0.12-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053591" comment="mozilla-xulrunner190-32bit less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053592" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053593" comment="mozilla-xulrunner190-translations less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053594" comment="mozilla-xulrunner190-x86 less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053595" comment="mozilla-xulrunner190 less than 1.9.0.12-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092463" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2463</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2463" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2463" source="CVE"/>
	<description>
	Multiple integer overflows in the (1) PL_Base64Decode and (2) PL_Base64Encode functions in nsprpub/lib/libc/src/base64.c in Mozilla Firefox before 3.0.12, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors that trigger buffer overflows.
	</description>
 </metadata>
<!-- d3be5c712e2e2706b7b11ecd08d9e22f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053589" comment="MozillaFirefox-translations less than 3.0.12-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053590" comment="MozillaFirefox less than 3.0.12-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053591" comment="mozilla-xulrunner190-32bit less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053592" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053593" comment="mozilla-xulrunner190-translations less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053594" comment="mozilla-xulrunner190-x86 less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053595" comment="mozilla-xulrunner190 less than 1.9.0.12-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092464" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2464</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2464" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2464" source="CVE"/>
	<description>
	The nsXULTemplateQueryProcessorRDF::CheckIsSeparator function in Mozilla Firefox before 3.0.12, SeaMonkey 2.0a1pre, and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to loading multiple RDF files in a XUL tree element.
	</description>
 </metadata>
<!-- d3be5c712e2e2706b7b11ecd08d9e22f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053589" comment="MozillaFirefox-translations less than 3.0.12-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053590" comment="MozillaFirefox less than 3.0.12-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053591" comment="mozilla-xulrunner190-32bit less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053592" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053593" comment="mozilla-xulrunner190-translations less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053594" comment="mozilla-xulrunner190-x86 less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053595" comment="mozilla-xulrunner190 less than 1.9.0.12-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092465" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2465</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2465" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2465" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.12 and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via vectors involving double frame construction, related to (1) nsHTMLContentSink.cpp, (2) nsXMLContentSink.cpp, and (3) nsPresShell.cpp, and the nsSubDocumentFrame::Reflow function.
	</description>
 </metadata>
<!-- d3be5c712e2e2706b7b11ecd08d9e22f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053589" comment="MozillaFirefox-translations less than 3.0.12-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053590" comment="MozillaFirefox less than 3.0.12-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053591" comment="mozilla-xulrunner190-32bit less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053592" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053593" comment="mozilla-xulrunner190-translations less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053594" comment="mozilla-xulrunner190-x86 less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053595" comment="mozilla-xulrunner190 less than 1.9.0.12-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092466" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2466</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2466" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2466" source="CVE"/>
	<description>
	The JavaScript engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsDOMClassInfo.cpp, (2) JS_HashTableRawLookup, and (3) MirrorWrappedNativeParent and js_LockGCThingRT.
	</description>
 </metadata>
<!-- d3be5c712e2e2706b7b11ecd08d9e22f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053589" comment="MozillaFirefox-translations less than 3.0.12-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053590" comment="MozillaFirefox less than 3.0.12-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053591" comment="mozilla-xulrunner190-32bit less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053592" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053593" comment="mozilla-xulrunner190-translations less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053594" comment="mozilla-xulrunner190-x86 less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053595" comment="mozilla-xulrunner190 less than 1.9.0.12-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092467" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2467</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2467" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2467" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.12 and 3.5 before 3.5.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving a Flash object, a slow script dialog, and the unloading of the Flash plugin, which triggers attempted use of a deleted object.
	</description>
 </metadata>
<!-- d3be5c712e2e2706b7b11ecd08d9e22f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053589" comment="MozillaFirefox-translations less than 3.0.12-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053590" comment="MozillaFirefox less than 3.0.12-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053591" comment="mozilla-xulrunner190-32bit less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053592" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053593" comment="mozilla-xulrunner190-translations less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053594" comment="mozilla-xulrunner190-x86 less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053595" comment="mozilla-xulrunner190 less than 1.9.0.12-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092469" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2469</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2469" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2469" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.12 does not properly handle an SVG element that has a property with a watch function and an __defineSetter__ function, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted document, related to a certain pointer misinterpretation.
	</description>
 </metadata>
<!-- d3be5c712e2e2706b7b11ecd08d9e22f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053589" comment="MozillaFirefox-translations less than 3.0.12-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053590" comment="MozillaFirefox less than 3.0.12-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053591" comment="mozilla-xulrunner190-32bit less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053592" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053593" comment="mozilla-xulrunner190-translations less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053594" comment="mozilla-xulrunner190-x86 less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053595" comment="mozilla-xulrunner190 less than 1.9.0.12-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092471" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2471</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2471" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2471" source="CVE"/>
	<description>
	The setTimeout function in Mozilla Firefox before 3.0.12 does not properly preserve object wrapping, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted call, related to XPCNativeWrapper.
	</description>
 </metadata>
<!-- d3be5c712e2e2706b7b11ecd08d9e22f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053589" comment="MozillaFirefox-translations less than 3.0.12-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053590" comment="MozillaFirefox less than 3.0.12-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053591" comment="mozilla-xulrunner190-32bit less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053592" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053593" comment="mozilla-xulrunner190-translations less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053594" comment="mozilla-xulrunner190-x86 less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053595" comment="mozilla-xulrunner190 less than 1.9.0.12-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092472" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2472</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2472" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2472" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted document, related to a "cross origin wrapper bypass."
	</description>
 </metadata>
<!-- d3be5c712e2e2706b7b11ecd08d9e22f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053589" comment="MozillaFirefox-translations less than 3.0.12-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053590" comment="MozillaFirefox less than 3.0.12-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053591" comment="mozilla-xulrunner190-32bit less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053592" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053593" comment="mozilla-xulrunner190-translations less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053594" comment="mozilla-xulrunner190-x86 less than 1.9.0.12-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053595" comment="mozilla-xulrunner190 less than 1.9.0.12-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092473" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2473</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2473" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2473" source="CVE"/>
	<description>
	neon before 0.28.6, when expat is used, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
	</description>
 </metadata>
<!-- db036d6c88b93b6c89d6d75d9b617dce -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009055772" comment="libneon27-32bit less than 0.28.3-2.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055773" comment="libneon27-x86 less than 0.28.3-2.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055774" comment="libneon27 less than 0.28.3-2.12.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055775" comment="neon less than 0.28.3-2.12.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092493" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2493</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2493" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2493" source="CVE"/>
	<description>
	The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1; and Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2; does not properly restrict use of OleLoadFromStream in instantiating objects from data streams, which allows remote attackers to execute arbitrary code via a crafted HTML document with an ATL (1) component or (2) control, related to ATL headers and bypassing security policies, aka "ATL COM Initialization Vulnerability."
	</description>
 </metadata>
<!-- 27428b62b5ccd6ac2929bae4bea6f2dd -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056019" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056020" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056021" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056022" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056023" comment="java-1_6_0-ibm less than 1.6.0_sr6-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092560" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2560</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2560" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2560" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in Wireshark 1.2.0 allow remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace and is processed by the (1) Bluetooth L2CAP, (2) RADIUS, or (3) MIOP dissector. NOTE: it was later reported that the RADIUS issue also affects 0.10.13 through 1.0.9.
	</description>
 </metadata>
<!-- 21376954221689990a2fee3602c8189f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056792" comment="wireshark less than 1.0.5-1.31.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092562" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2562</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2562" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2562" source="CVE"/>
	<description>
	Unspecified vulnerability in the AFS dissector in Wireshark 0.9.2 through 1.2.0 allows remote attackers to cause a denial of service (crash) via unknown vectors.
	</description>
 </metadata>
<!-- dbebbebc6602a5f4dc39225f2c067daa -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054498" comment="wireshark less than 1.0.5-1.27.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092563" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2563</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2563" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2563" source="CVE"/>
	<description>
	Unspecified vulnerability in the Infiniband dissector in Wireshark 1.0.6 through 1.2.0, when running on unspecified platforms, allows remote attackers to cause a denial of service (crash) via unknown vectors.
	</description>
 </metadata>
<!-- 963ff40259d4863a011be226650534cb -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058844" comment="wireshark less than 1.0.5-1.34.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092621" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2621</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2621" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2621" source="CVE"/>
	<description>
	Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 does not properly enforce "buffer limits and related bound checks," which allows remote attackers to cause a denial of service via (1) an incomplete request or (2) a request with a large header size, related to (a) HttpMsg.cc and (b) client_side.cc.
	</description>
 </metadata>
<!-- e7ccdbbe46c91059fa6548099ec50325 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059011" comment="squid less than 2.7.STABLE5-2.4.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092622" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2622</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2622" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2622" source="CVE"/>
	<description>
	Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 allows remote attackers to cause a denial of service via malformed requests including (1) "missing or mismatched protocol identifier," (2) missing or negative status value," (3) "missing version," or (4) "missing or invalid status number," related to (a) HttpMsg.cc and (b) HttpReply.cc.
	</description>
 </metadata>
<!-- e7ccdbbe46c91059fa6548099ec50325 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059011" comment="squid less than 2.7.STABLE5-2.4.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092624" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2624</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2624" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2624" source="CVE"/>
	<description>
	The huft_build function in inflate.c in gzip before 1.3.13 creates a hufts (aka huffman) table that is too small, which allows remote attackers to cause a denial of service (application crash or infinite loop) or possibly execute arbitrary code via a crafted archive.  NOTE: this issue is caused by a CVE-2006-4334 regression.
	</description>
 </metadata>
<!-- 8388a149c9d32703af6f0ac8782851c4 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057426" comment="gzip less than 1.3.12-69.19.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092625" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2625</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2625" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2625" source="CVE"/>
	<description>
	XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1f9677a08fca714e8676c96c9e388edb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054296" comment="xerces-j2-xml-apis less than 2.8.1-238.27.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054297" comment="xerces-j2-xml-resolver less than 2.8.1-238.27.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054298" comment="xerces-j2 less than 2.8.1-238.27.1"/>
		</criteria>
	</criteria>
	<!-- 27428b62b5ccd6ac2929bae4bea6f2dd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056019" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056020" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056021" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056022" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056023" comment="java-1_6_0-ibm less than 1.6.0_sr6-1.1.1"/>
		</criteria>
	</criteria>
	<!-- cc3e3bda8217aa28262b6982edd9bee5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060325" comment="libpython2_6-1_0-32bit less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060326" comment="libpython2_6-1_0-x86 less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060327" comment="libpython2_6-1_0 less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060328" comment="python-32bit less than 2.6.0-8.9.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060329" comment="python-base-32bit less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060330" comment="python-base-x86 less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060331" comment="python-base less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060332" comment="python-curses less than 2.6.0-8.9.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060333" comment="python-demo less than 2.6.0-8.9.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060334" comment="python-gdbm less than 2.6.0-8.9.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060335" comment="python-idle less than 2.6.0-8.9.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060336" comment="python-tk less than 2.6.0-8.9.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060337" comment="python-x86 less than 2.6.0-8.9.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060338" comment="python-xml less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060339" comment="python less than 2.6.0-8.9.1.1"/>
		</criteria>
	</criteria>
	<!-- d3ab7cbc3008183adb364cf6fbd6c4df -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055058" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.1-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055059" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.1-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055060" comment="java-1_4_2-ibm less than 1.4.2_sr13.1-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092626" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2626</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2626" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2626" source="CVE"/>
	<description>
	The zend_restore_ini_entry_cb function in zend_ini.c in PHP 5.3.0, 5.2.10, and earlier versions allows context-specific attackers to obtain sensitive information (memory contents) and cause a PHP crash by using the ini_set function to declare a variable, then using the ini_restore function to restore the variable.
	</description>
 </metadata>
<!-- bfb263e4c75cfb6dca1c2ee69633f369 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009058031" comment="apache2-mod_php5 less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058032" comment="php5-bcmath less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058033" comment="php5-bz2 less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058034" comment="php5-calendar less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058035" comment="php5-ctype less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058036" comment="php5-curl less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058037" comment="php5-dba less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058038" comment="php5-dbase less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058039" comment="php5-dom less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058040" comment="php5-exif less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058041" comment="php5-fastcgi less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058042" comment="php5-ftp less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058043" comment="php5-gd less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058044" comment="php5-gettext less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058045" comment="php5-gmp less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058046" comment="php5-hash less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058047" comment="php5-iconv less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058048" comment="php5-json less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058049" comment="php5-ldap less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058050" comment="php5-mbstring less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058051" comment="php5-mcrypt less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058052" comment="php5-mysql less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058053" comment="php5-odbc less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058054" comment="php5-openssl less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058055" comment="php5-pcntl less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058056" comment="php5-pdo less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058057" comment="php5-pear less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058058" comment="php5-pgsql less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058059" comment="php5-pspell less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058060" comment="php5-shmop less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058061" comment="php5-snmp less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058062" comment="php5-soap less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058063" comment="php5-suhosin less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058064" comment="php5-sysvmsg less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058065" comment="php5-sysvsem less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058066" comment="php5-sysvshm less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058067" comment="php5-tokenizer less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058068" comment="php5-wddx less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058069" comment="php5-xmlreader less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058070" comment="php5-xmlrpc less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058071" comment="php5-xmlwriter less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058072" comment="php5-xsl less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058073" comment="php5-zip less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058074" comment="php5-zlib less than 5.2.6-50.24.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092632" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2632</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2632" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2632" source="CVE"/>
	<description>
	Buffer overflow in the SIEVE script component (sieve/script.c), as used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, allows local users to execute arbitrary code and read or modify arbitrary messages via a crafted SIEVE script, related to the incorrect use of the sizeof operator for determining buffer length, combined with an integer signedness error.
	</description>
 </metadata>
<!-- dfdade9d42f73e792247dfb5f261a66e -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009054972" comment="cyrus-imapd less than 2.3.11-60.20.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054973" comment="perl-Cyrus-IMAP less than 2.3.11-60.20.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054974" comment="perl-Cyrus-SIEVE-managesieve less than 2.3.11-60.20.2"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092654" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2654</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2654" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2654" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.13, and 3.5.x before 3.5.2, allows remote attackers to spoof the address bar, and possibly conduct phishing attacks, via a crafted web page that calls window.open with an invalid character in the URL, makes document.write calls to the resulting object, and then calls the stop method during the loading of the error page.
	</description>
 </metadata>
<!-- 0f13983ab3e07c9cb46294b6377d70a9 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053944" comment="MozillaFirefox-translations less than 3.0.13-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053945" comment="MozillaFirefox less than 3.0.13-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053946" comment="gconf2-32bit less than 2.24.0-7.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053947" comment="gconf2-x86 less than 2.24.0-7.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053948" comment="gconf2 less than 2.24.0-7.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053949" comment="libidl-32bit less than 0.8.11-2.14"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053950" comment="libidl-x86 less than 0.8.11-2.14"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053951" comment="libidl less than 0.8.11-2.14"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053952" comment="mozilla-xulrunner190-32bit less than 1.9.0.13-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053953" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.13-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053954" comment="mozilla-xulrunner190-translations less than 1.9.0.13-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053955" comment="mozilla-xulrunner190-x86 less than 1.9.0.13-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053956" comment="mozilla-xulrunner190 less than 1.9.0.13-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053957" comment="orbit2-32bit less than 2.14.16-2.16"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053958" comment="orbit2-x86 less than 2.14.16-2.16"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053959" comment="orbit2 less than 2.14.16-2.16"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092661" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2661</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2661" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2661" source="CVE"/>
	<description>
	The asn1_length function in strongSwan 2.8 before 2.8.11, 4.2 before 4.2.17, and 4.3 before 4.3.3 does not properly handle X.509 certificates with crafted Relative Distinguished Names (RDNs), which allows remote attackers to cause a denial of service (pluto IKE daemon crash) via malformed ASN.1 data.  NOTE: this is due to an incomplete fix for CVE-2009-2185.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 05409f59cd8b07e9b7c37d898f9fb045 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054996" comment="openswan-doc less than 2.6.16-1.34.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054997" comment="openswan less than 2.6.16-1.34.3"/>
		</criteria>
	</criteria>
	<!-- 7bd868252707205186bba5dbee528e97 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054910" comment="strongswan-doc less than 4.2.8-1.27.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054911" comment="strongswan less than 4.2.8-1.27.2"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092662" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2662</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2662" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2662" source="CVE"/>
	<description>
	The browser engine in Mozilla Firefox 3.5.x before 3.5.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the TraceRecorder::snapshot function in js/src/jstracer.cpp, and unspecified other vectors.
	</description>
 </metadata>
<!-- 0f13983ab3e07c9cb46294b6377d70a9 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053944" comment="MozillaFirefox-translations less than 3.0.13-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053945" comment="MozillaFirefox less than 3.0.13-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053946" comment="gconf2-32bit less than 2.24.0-7.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053947" comment="gconf2-x86 less than 2.24.0-7.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053948" comment="gconf2 less than 2.24.0-7.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053949" comment="libidl-32bit less than 0.8.11-2.14"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053950" comment="libidl-x86 less than 0.8.11-2.14"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053951" comment="libidl less than 0.8.11-2.14"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053952" comment="mozilla-xulrunner190-32bit less than 1.9.0.13-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053953" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.13-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053954" comment="mozilla-xulrunner190-translations less than 1.9.0.13-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053955" comment="mozilla-xulrunner190-x86 less than 1.9.0.13-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053956" comment="mozilla-xulrunner190 less than 1.9.0.13-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053957" comment="orbit2-32bit less than 2.14.16-2.16"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053958" comment="orbit2-x86 less than 2.14.16-2.16"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053959" comment="orbit2 less than 2.14.16-2.16"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092663" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2663</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2009-2663" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2663" source="CVE"/>
	<description>
	libvorbis before r16182, as used in Mozilla Firefox 3.5.x before 3.5.2 and other products, allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .ogg file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0f13983ab3e07c9cb46294b6377d70a9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009053944" comment="MozillaFirefox-translations less than 3.0.13-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053945" comment="MozillaFirefox less than 3.0.13-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053946" comment="gconf2-32bit less than 2.24.0-7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053947" comment="gconf2-x86 less than 2.24.0-7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053948" comment="gconf2 less than 2.24.0-7.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053949" comment="libidl-32bit less than 0.8.11-2.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053950" comment="libidl-x86 less than 0.8.11-2.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053951" comment="libidl less than 0.8.11-2.14"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053952" comment="mozilla-xulrunner190-32bit less than 1.9.0.13-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053953" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.13-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053954" comment="mozilla-xulrunner190-translations less than 1.9.0.13-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053955" comment="mozilla-xulrunner190-x86 less than 1.9.0.13-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053956" comment="mozilla-xulrunner190 less than 1.9.0.13-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053957" comment="orbit2-32bit less than 2.14.16-2.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053958" comment="orbit2-x86 less than 2.14.16-2.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009053959" comment="orbit2 less than 2.14.16-2.16"/>
		</criteria>
	</criteria>
	<!-- 29a723aec45f6f33d099de1d7add5181 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061090" comment="libvorbis-32bit less than 1.2.0-79.13.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061091" comment="libvorbis-doc less than 1.2.0-79.13.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061092" comment="libvorbis-x86 less than 1.2.0-79.13.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061093" comment="libvorbis less than 1.2.0-79.13.1"/>
		</criteria>
	</criteria>
	<!-- 6f61731fb3658c18c77c67445b09caf1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061090" comment="libvorbis-32bit less than 1.2.0-79.13.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061091" comment="libvorbis-doc less than 1.2.0-79.13.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061092" comment="libvorbis-x86 less than 1.2.0-79.13.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061093" comment="libvorbis less than 1.2.0-79.13.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092664" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2664</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2664" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2664" source="CVE"/>
	<description>
	The js_watch_set function in js/src/jsdbgapi.cpp in the JavaScript engine in Mozilla Firefox before 3.0.12 allows remote attackers to cause a denial of service (assertion failure and application exit) or possibly execute arbitrary code via a crafted .js file, related to a "memory safety bug." NOTE: this was originally reported as affecting versions before 3.0.13.
	</description>
 </metadata>
<!-- 0f13983ab3e07c9cb46294b6377d70a9 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053944" comment="MozillaFirefox-translations less than 3.0.13-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053945" comment="MozillaFirefox less than 3.0.13-0.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053946" comment="gconf2-32bit less than 2.24.0-7.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053947" comment="gconf2-x86 less than 2.24.0-7.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053948" comment="gconf2 less than 2.24.0-7.5"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053949" comment="libidl-32bit less than 0.8.11-2.14"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053950" comment="libidl-x86 less than 0.8.11-2.14"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053951" comment="libidl less than 0.8.11-2.14"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053952" comment="mozilla-xulrunner190-32bit less than 1.9.0.13-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053953" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.13-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053954" comment="mozilla-xulrunner190-translations less than 1.9.0.13-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053955" comment="mozilla-xulrunner190-x86 less than 1.9.0.13-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053956" comment="mozilla-xulrunner190 less than 1.9.0.13-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053957" comment="orbit2-32bit less than 2.14.16-2.16"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053958" comment="orbit2-x86 less than 2.14.16-2.16"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053959" comment="orbit2 less than 2.14.16-2.16"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092666" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2666</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2666" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2666" source="CVE"/>
	<description>
	socket.c in fetchmail before 6.3.11 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
	</description>
 </metadata>
<!-- 26aa1c657e53800ab93f6510f4c057b5 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009053783" comment="fetchmail less than 6.3.8.90-13.16.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009053784" comment="fetchmailconf less than 6.3.8.90-13.16.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092670" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2670</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2670" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2670" source="CVE"/>
	<description>
	The audio system in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to java.lang.System properties by (1) untrusted applets and (2) Java Web Start applications, which allows context-dependent attackers to obtain sensitive information by reading these properties.
	</description>
 </metadata>
<!-- 27428b62b5ccd6ac2929bae4bea6f2dd -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056019" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056020" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056021" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056022" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056023" comment="java-1_6_0-ibm less than 1.6.0_sr6-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092671" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2671</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2671" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2671" source="CVE"/>
	<description>
	The SOCKS proxy implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows remote attackers to discover the username of the account that invoked an untrusted (1) applet or (2) Java Web Start application via unspecified vectors.
	</description>
 </metadata>
<!-- 27428b62b5ccd6ac2929bae4bea6f2dd -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056019" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056020" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056021" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056022" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056023" comment="java-1_6_0-ibm less than 1.6.0_sr6-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092672" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2672</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2672" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2672" source="CVE"/>
	<description>
	The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to browser cookies by untrusted (1) applets and (2) Java Web Start applications, which allows remote attackers to hijack web sessions via unspecified vectors.
	</description>
 </metadata>
<!-- 27428b62b5ccd6ac2929bae4bea6f2dd -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056019" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056020" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056021" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056022" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056023" comment="java-1_6_0-ibm less than 1.6.0_sr6-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092673" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2673</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2673" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2673" source="CVE"/>
	<description>
	The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unspecified vectors, related to a declaration that lacks the final keyword.
	</description>
 </metadata>
<!-- 27428b62b5ccd6ac2929bae4bea6f2dd -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056019" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056020" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056021" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056022" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056023" comment="java-1_6_0-ibm less than 1.6.0_sr6-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092674" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2674</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2674" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2674" source="CVE"/>
	<description>
	Integer overflow in javaws.exe in Sun Java Web Start in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 allows context-dependent attackers to execute arbitrary code via a crafted JPEG image that is not properly handled during display to a splash screen, which triggers a heap-based buffer overflow.
	</description>
 </metadata>
<!-- 27428b62b5ccd6ac2929bae4bea6f2dd -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056019" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056020" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056021" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056022" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056023" comment="java-1_6_0-ibm less than 1.6.0_sr6-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092675" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2675</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2675" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2675" source="CVE"/>
	<description>
	Integer overflow in the unpack200 utility in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows context-dependent attackers to gain privileges via unspecified length fields in the header of a Pack200-compressed JAR file, which leads to a heap-based buffer overflow during decompression.
	</description>
 </metadata>
<!-- 27428b62b5ccd6ac2929bae4bea6f2dd -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056019" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056020" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056021" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056022" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056023" comment="java-1_6_0-ibm less than 1.6.0_sr6-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092676" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2676</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2676" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2676" source="CVE"/>
	<description>
	Unspecified vulnerability in JNLPAppletlauncher in Sun Java SE, and SE for Business, in JDK and JRE 6 Update 14 and earlier and JDK and JRE 5.0 Update 19 and earlier; and Java SE for Business in SDK and JRE 1.4.2_21 and earlier; allows remote attackers to create or modify arbitrary files via vectors involving an untrusted Java applet that accesses an old version of JNLPAppletLauncher.
	</description>
 </metadata>
<!-- 27428b62b5ccd6ac2929bae4bea6f2dd -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056019" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056020" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056021" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056022" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056023" comment="java-1_6_0-ibm less than 1.6.0_sr6-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092687" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2687</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2687" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2687" source="CVE"/>
	<description>
	The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 6f524102537d5a77ed575f0190599d68 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055145" comment="apache2-mod_php5 less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055146" comment="php5-bcmath less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055147" comment="php5-bz2 less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055148" comment="php5-calendar less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055149" comment="php5-ctype less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055150" comment="php5-curl less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055151" comment="php5-dba less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055152" comment="php5-dbase less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055153" comment="php5-dom less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055154" comment="php5-exif less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055155" comment="php5-fastcgi less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055156" comment="php5-ftp less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055157" comment="php5-gd less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055158" comment="php5-gettext less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055159" comment="php5-gmp less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055160" comment="php5-hash less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055161" comment="php5-iconv less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055162" comment="php5-json less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055163" comment="php5-ldap less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055164" comment="php5-mbstring less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055165" comment="php5-mcrypt less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055166" comment="php5-mysql less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055167" comment="php5-odbc less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055168" comment="php5-openssl less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055169" comment="php5-pcntl less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055170" comment="php5-pdo less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055171" comment="php5-pear less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055172" comment="php5-pgsql less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055173" comment="php5-pspell less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055174" comment="php5-shmop less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055175" comment="php5-snmp less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055176" comment="php5-soap less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055177" comment="php5-suhosin less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055178" comment="php5-sysvmsg less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055179" comment="php5-sysvsem less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055180" comment="php5-sysvshm less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055181" comment="php5-tokenizer less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055182" comment="php5-wddx less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055183" comment="php5-xmlreader less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055184" comment="php5-xmlrpc less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055185" comment="php5-xmlwriter less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055186" comment="php5-xsl less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055187" comment="php5-zip less than 5.2.6-50.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055188" comment="php5-zlib less than 5.2.6-50.23.1"/>
		</criteria>
	</criteria>
	<!-- bfb263e4c75cfb6dca1c2ee69633f369 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058031" comment="apache2-mod_php5 less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058032" comment="php5-bcmath less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058033" comment="php5-bz2 less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058034" comment="php5-calendar less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058035" comment="php5-ctype less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058036" comment="php5-curl less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058037" comment="php5-dba less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058038" comment="php5-dbase less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058039" comment="php5-dom less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058040" comment="php5-exif less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058041" comment="php5-fastcgi less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058042" comment="php5-ftp less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058043" comment="php5-gd less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058044" comment="php5-gettext less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058045" comment="php5-gmp less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058046" comment="php5-hash less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058047" comment="php5-iconv less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058048" comment="php5-json less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058049" comment="php5-ldap less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058050" comment="php5-mbstring less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058051" comment="php5-mcrypt less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058052" comment="php5-mysql less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058053" comment="php5-odbc less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058054" comment="php5-openssl less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058055" comment="php5-pcntl less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058056" comment="php5-pdo less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058057" comment="php5-pear less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058058" comment="php5-pgsql less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058059" comment="php5-pspell less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058060" comment="php5-shmop less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058061" comment="php5-snmp less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058062" comment="php5-soap less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058063" comment="php5-suhosin less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058064" comment="php5-sysvmsg less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058065" comment="php5-sysvsem less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058066" comment="php5-sysvshm less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058067" comment="php5-tokenizer less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058068" comment="php5-wddx less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058069" comment="php5-xmlreader less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058070" comment="php5-xmlrpc less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058071" comment="php5-xmlwriter less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058072" comment="php5-xsl less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058073" comment="php5-zip less than 5.2.6-50.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058074" comment="php5-zlib less than 5.2.6-50.24.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092692" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2692</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2692" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2692" source="CVE"/>
	<description>
	The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using mmap to map page zero, placing arbitrary code on this page, and then invoking an unavailable operation, as demonstrated by the sendpage operation (sock_sendpage function) on a PF_PPPOX socket.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0522f4d2681968d0e344aad24e0e341b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054104" comment="ext4dev-kmp-default less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054105" comment="ext4dev-kmp-pae less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054106" comment="ext4dev-kmp-vmi less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054107" comment="ext4dev-kmp-xen less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054108" comment="kernel-default-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054109" comment="kernel-default less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054110" comment="kernel-pae-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054111" comment="kernel-pae less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054112" comment="kernel-source less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054113" comment="kernel-syms less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054114" comment="kernel-vmi-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054115" comment="kernel-vmi less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054116" comment="kernel-xen-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054117" comment="kernel-xen less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 125c8b5a7b30fdb1de7b2255eb1649a7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054104" comment="ext4dev-kmp-default less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054107" comment="ext4dev-kmp-xen less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054108" comment="kernel-default-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054109" comment="kernel-default less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054112" comment="kernel-source less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054113" comment="kernel-syms less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054116" comment="kernel-xen-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054117" comment="kernel-xen less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
	<!-- db255a76ea8ba6e688475154d00e78ae -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054104" comment="ext4dev-kmp-default less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054108" comment="kernel-default-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054109" comment="kernel-default less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054112" comment="kernel-source less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054113" comment="kernel-syms less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
	<!-- dfbea602689b882f72228d86a5d32316 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054104" comment="ext4dev-kmp-default less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054118" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054108" comment="kernel-default-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054109" comment="kernel-default less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054119" comment="kernel-kdump less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054120" comment="kernel-ppc64-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054121" comment="kernel-ppc64 less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054112" comment="kernel-source less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054113" comment="kernel-syms less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e37bbd585e257a0da7b25b00ac9c72ef -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009054104" comment="ext4dev-kmp-default less than 0_2.6.27.29_0.1-7.1.13"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054108" comment="kernel-default-base less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054122" comment="kernel-default-man less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054109" comment="kernel-default less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054112" comment="kernel-source less than 2.6.27.29-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009054113" comment="kernel-syms less than 2.6.27.29-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092700" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2700</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2700" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2700" source="CVE"/>
	<description>
	src/network/ssl/qsslcertificate.cpp in Nokia Trolltech Qt 4.x does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
	</description>
 </metadata>
<!-- c980cdd57955d1f78a74976fd2c23c32 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056137" comment="libqt4-32bit less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056138" comment="libqt4-qt3support-32bit less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056139" comment="libqt4-qt3support-x86 less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056140" comment="libqt4-qt3support less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056141" comment="libqt4-sql-32bit less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056142" comment="libqt4-sql-sqlite less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056143" comment="libqt4-sql-x86 less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056144" comment="libqt4-sql less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056145" comment="libqt4-x11-32bit less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056146" comment="libqt4-x11-x86 less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056147" comment="libqt4-x11 less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056148" comment="libqt4-x86 less than 4.4.3-12.11.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056149" comment="libqt4 less than 4.4.3-12.11.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092730" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2730</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2730" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2730" source="CVE"/>
	<description>
	libgnutls in GnuTLS before 2.8.2 does not properly handle a '\0' character in a domain name in the subject's (1) Common Name (CN) or (2) Subject Alternative Name (SAN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
	</description>
 </metadata>
<!-- af7de3dbf0c217bd35268d7b9dccbe34 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009054538" comment="gnutls less than 2.4.1-24.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054539" comment="libgnutls26-32bit less than 2.4.1-24.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054540" comment="libgnutls26-x86 less than 2.4.1-24.19.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054541" comment="libgnutls26 less than 2.4.1-24.19.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092813" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2813</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2813" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2813" source="CVE"/>
	<description>
	Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in the SMB subsystem in Apple Mac OS X 10.5.8 when Windows File Sharing is enabled, Fedora 11, and other operating systems, does not properly handle errors in resolving pathnames, which allows remote authenticated users to bypass intended sharing restrictions, and read, create, or modify files, in certain circumstances involving user accounts that lack home directories.
	</description>
 </metadata>
<!-- dbedb3fb1fc74639fa0c893e6c0ad7f6 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009055477" comment="cifs-mount less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055478" comment="ldapsmb less than 1.34b-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055479" comment="libsmbclient0-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055480" comment="libsmbclient0-x86 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055481" comment="libsmbclient0 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055482" comment="libtalloc1-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055483" comment="libtalloc1-x86 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055484" comment="libtalloc1 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055485" comment="libtdb1-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055486" comment="libtdb1-x86 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055487" comment="libtdb1 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055488" comment="libwbclient0-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055489" comment="libwbclient0-x86 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055490" comment="libwbclient0 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055491" comment="samba-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055492" comment="samba-client-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055493" comment="samba-client-x86 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055494" comment="samba-client less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055495" comment="samba-krb-printing less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055496" comment="samba-winbind-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055497" comment="samba-winbind-x86 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055498" comment="samba-winbind less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055499" comment="samba-x86 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055500" comment="samba less than 3.2.7-11.8.2"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092820" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2820</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2820" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2820" source="CVE"/>
	<description>
	The web interface in CUPS before 1.4.2, as used on Apple Mac OS X before 10.6.2 and other platforms, does not properly handle (1) HTTP headers and (2) HTML templates, which allows remote attackers to conduct cross-site scripting (XSS) attacks and HTTP response splitting attacks via vectors related to (a) the product's web interface, (b) the configuration of the print system, and (c) the titles of printed jobs, as demonstrated by an XSS attack that uses the kerberos parameter to the admin program, and leverages attribute injection and HTTP Parameter Pollution (HPP) issues.
	</description>
 </metadata>
<!-- d4e3a70fb8819a66d8ccea9697c425ea -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056119" comment="cups-client less than 1.3.9-8.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056120" comment="cups-libs-32bit less than 1.3.9-8.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056121" comment="cups-libs-x86 less than 1.3.9-8.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056122" comment="cups-libs less than 1.3.9-8.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056123" comment="cups less than 1.3.9-8.20.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092848" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2848</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2848" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2848" source="CVE"/>
	<description>
	The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current-&gt;clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via a clone system call with CLONE_CHILD_SETTID or CLONE_CHILD_CLEARTID enabled, which is not properly handled during thread creation and exit.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 180ffe58c62210bba55d0af594f5207f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055900" comment="ext4dev-kmp-default less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055901" comment="ext4dev-kmp-pae less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055902" comment="ext4dev-kmp-vmi less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055903" comment="ext4dev-kmp-xen less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055844" comment="kernel-default-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055846" comment="kernel-default less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055852" comment="kernel-pae-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055854" comment="kernel-pae less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055859" comment="kernel-source less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055860" comment="kernel-syms less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055904" comment="kernel-vmi-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055905" comment="kernel-vmi less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055865" comment="kernel-xen-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055867" comment="kernel-xen less than 2.6.27.37-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 650f64250b48193ff6617a946612537f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055900" comment="ext4dev-kmp-default less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055844" comment="kernel-default-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055846" comment="kernel-default less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055859" comment="kernel-source less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055860" comment="kernel-syms less than 2.6.27.37-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 6d2f53ab7e3e69501a86208057c2ef96 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055900" comment="ext4dev-kmp-default less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055903" comment="ext4dev-kmp-xen less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055844" comment="kernel-default-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055846" comment="kernel-default less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055859" comment="kernel-source less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055860" comment="kernel-syms less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055865" comment="kernel-xen-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055867" comment="kernel-xen less than 2.6.27.37-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 6dba097d1becca3dbbb21d37603b4abd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055900" comment="ext4dev-kmp-default less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055844" comment="kernel-default-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055906" comment="kernel-default-man less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055846" comment="kernel-default less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055859" comment="kernel-source less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055860" comment="kernel-syms less than 2.6.27.37-0.1.1"/>
		</criteria>
	</criteria>
	<!-- ecd5c197b4c69dacf23b245089132742 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055900" comment="ext4dev-kmp-default less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055907" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055844" comment="kernel-default-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055846" comment="kernel-default less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055851" comment="kernel-kdump less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055855" comment="kernel-ppc64-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055857" comment="kernel-ppc64 less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055859" comment="kernel-source less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055860" comment="kernel-syms less than 2.6.27.37-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092855" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2855</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2855" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2855" source="CVE"/>
	<description>
	The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function.
	</description>
 </metadata>
<!-- e7ccdbbe46c91059fa6548099ec50325 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059011" comment="squid less than 2.7.STABLE5-2.4.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092903" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2903</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2903" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2903" source="CVE"/>
	<description>
	Memory leak in the appletalk subsystem in the Linux kernel 2.4.x through 2.4.37.6 and 2.6.x through 2.6.31, when the appletalk and ipddp modules are loaded but the ipddp"N" device is not found, allows remote attackers to cause a denial of service (memory consumption) via IP-DDP datagrams.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 114b9cf953db7d4a1a91082495d33414 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056506" comment="ext4dev-kmp-xen less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056511" comment="kernel-xen-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056512" comment="kernel-xen less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- 9b6d121530adca742ba4b1a99075559a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056513" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056514" comment="kernel-kdump less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056515" comment="kernel-ppc64-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056516" comment="kernel-ppc64 less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- a3c4f0428e25dca1993e5018e76d6758 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056517" comment="ext4dev-kmp-pae less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056518" comment="ext4dev-kmp-vmi less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056506" comment="ext4dev-kmp-xen less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056519" comment="kernel-pae-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056520" comment="kernel-pae less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056521" comment="kernel-vmi-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056522" comment="kernel-vmi less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056511" comment="kernel-xen-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056512" comment="kernel-xen less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- dfdf7dd3f18b0b2cf8024eb5a30e51ba -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- faf6558ee52bc90aea4840dc79e5757f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056523" comment="kernel-default-man less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092906" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2906</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2906" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2906" source="CVE"/>
	<description>
	smbd in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8, and 3.4 before 3.4.2 allows remote authenticated users to cause a denial of service (infinite loop) via an unanticipated oplock break notification reply packet.
	</description>
 </metadata>
<!-- dbedb3fb1fc74639fa0c893e6c0ad7f6 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009055477" comment="cifs-mount less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055478" comment="ldapsmb less than 1.34b-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055479" comment="libsmbclient0-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055480" comment="libsmbclient0-x86 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055481" comment="libsmbclient0 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055482" comment="libtalloc1-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055483" comment="libtalloc1-x86 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055484" comment="libtalloc1 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055485" comment="libtdb1-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055486" comment="libtdb1-x86 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055487" comment="libtdb1 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055488" comment="libwbclient0-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055489" comment="libwbclient0-x86 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055490" comment="libwbclient0 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055491" comment="samba-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055492" comment="samba-client-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055493" comment="samba-client-x86 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055494" comment="samba-client less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055495" comment="samba-krb-printing less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055496" comment="samba-winbind-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055497" comment="samba-winbind-x86 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055498" comment="samba-winbind less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055499" comment="samba-x86 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055500" comment="samba less than 3.2.7-11.8.2"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092909" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2909</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2909" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2909" source="CVE"/>
	<description>
	Integer signedness error in the ax25_setsockopt function in net/ax25/af_ax25.c in the ax25 subsystem in the Linux kernel before 2.6.31.2 allows local users to cause a denial of service (OOPS) via a crafted optlen value in an SO_BINDTODEVICE operation.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 180ffe58c62210bba55d0af594f5207f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055900" comment="ext4dev-kmp-default less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055901" comment="ext4dev-kmp-pae less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055902" comment="ext4dev-kmp-vmi less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055903" comment="ext4dev-kmp-xen less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055844" comment="kernel-default-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055846" comment="kernel-default less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055852" comment="kernel-pae-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055854" comment="kernel-pae less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055859" comment="kernel-source less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055860" comment="kernel-syms less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055904" comment="kernel-vmi-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055905" comment="kernel-vmi less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055865" comment="kernel-xen-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055867" comment="kernel-xen less than 2.6.27.37-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 650f64250b48193ff6617a946612537f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055900" comment="ext4dev-kmp-default less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055844" comment="kernel-default-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055846" comment="kernel-default less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055859" comment="kernel-source less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055860" comment="kernel-syms less than 2.6.27.37-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 6d2f53ab7e3e69501a86208057c2ef96 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055900" comment="ext4dev-kmp-default less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055903" comment="ext4dev-kmp-xen less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055844" comment="kernel-default-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055846" comment="kernel-default less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055859" comment="kernel-source less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055860" comment="kernel-syms less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055865" comment="kernel-xen-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055867" comment="kernel-xen less than 2.6.27.37-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 6dba097d1becca3dbbb21d37603b4abd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055900" comment="ext4dev-kmp-default less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055844" comment="kernel-default-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055906" comment="kernel-default-man less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055846" comment="kernel-default less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055859" comment="kernel-source less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055860" comment="kernel-syms less than 2.6.27.37-0.1.1"/>
		</criteria>
	</criteria>
	<!-- ecd5c197b4c69dacf23b245089132742 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055900" comment="ext4dev-kmp-default less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055907" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055844" comment="kernel-default-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055846" comment="kernel-default less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055851" comment="kernel-kdump less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055855" comment="kernel-ppc64-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055857" comment="kernel-ppc64 less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055859" comment="kernel-source less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055860" comment="kernel-syms less than 2.6.27.37-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092910" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2910</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2910" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2910" source="CVE"/>
	<description>
	arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.31.4 on the x86_64 platform does not clear certain kernel registers before a return to user mode, which allows local users to read register values from an earlier process by switching an ia32 process to 64-bit mode.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 114b9cf953db7d4a1a91082495d33414 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056506" comment="ext4dev-kmp-xen less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056511" comment="kernel-xen-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056512" comment="kernel-xen less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- 180ffe58c62210bba55d0af594f5207f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055900" comment="ext4dev-kmp-default less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055901" comment="ext4dev-kmp-pae less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055902" comment="ext4dev-kmp-vmi less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055903" comment="ext4dev-kmp-xen less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055844" comment="kernel-default-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055846" comment="kernel-default less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055852" comment="kernel-pae-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055854" comment="kernel-pae less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055859" comment="kernel-source less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055860" comment="kernel-syms less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055904" comment="kernel-vmi-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055905" comment="kernel-vmi less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055865" comment="kernel-xen-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055867" comment="kernel-xen less than 2.6.27.37-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 650f64250b48193ff6617a946612537f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055900" comment="ext4dev-kmp-default less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055844" comment="kernel-default-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055846" comment="kernel-default less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055859" comment="kernel-source less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055860" comment="kernel-syms less than 2.6.27.37-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 6d2f53ab7e3e69501a86208057c2ef96 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055900" comment="ext4dev-kmp-default less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055903" comment="ext4dev-kmp-xen less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055844" comment="kernel-default-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055846" comment="kernel-default less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055859" comment="kernel-source less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055860" comment="kernel-syms less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055865" comment="kernel-xen-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055867" comment="kernel-xen less than 2.6.27.37-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 6dba097d1becca3dbbb21d37603b4abd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055900" comment="ext4dev-kmp-default less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055844" comment="kernel-default-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055906" comment="kernel-default-man less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055846" comment="kernel-default less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055859" comment="kernel-source less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055860" comment="kernel-syms less than 2.6.27.37-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 9b6d121530adca742ba4b1a99075559a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056513" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056514" comment="kernel-kdump less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056515" comment="kernel-ppc64-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056516" comment="kernel-ppc64 less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- a3c4f0428e25dca1993e5018e76d6758 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056517" comment="ext4dev-kmp-pae less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056518" comment="ext4dev-kmp-vmi less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056506" comment="ext4dev-kmp-xen less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056519" comment="kernel-pae-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056520" comment="kernel-pae less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056521" comment="kernel-vmi-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056522" comment="kernel-vmi less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056511" comment="kernel-xen-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056512" comment="kernel-xen less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- dfdf7dd3f18b0b2cf8024eb5a30e51ba -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- ecd5c197b4c69dacf23b245089132742 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055900" comment="ext4dev-kmp-default less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055907" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055844" comment="kernel-default-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055846" comment="kernel-default less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055851" comment="kernel-kdump less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055855" comment="kernel-ppc64-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055857" comment="kernel-ppc64 less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055859" comment="kernel-source less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055860" comment="kernel-syms less than 2.6.27.37-0.1.1"/>
		</criteria>
	</criteria>
	<!-- faf6558ee52bc90aea4840dc79e5757f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056523" comment="kernel-default-man less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092948" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2948</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2948" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2948" source="CVE"/>
	<description>
	mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly enforce permissions, which allows local users to read part of the credentials file and obtain the password by specifying the path to the credentials file and using the --verbose or -v option.
	</description>
 </metadata>
<!-- dbedb3fb1fc74639fa0c893e6c0ad7f6 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009055477" comment="cifs-mount less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055478" comment="ldapsmb less than 1.34b-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055479" comment="libsmbclient0-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055480" comment="libsmbclient0-x86 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055481" comment="libsmbclient0 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055482" comment="libtalloc1-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055483" comment="libtalloc1-x86 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055484" comment="libtalloc1 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055485" comment="libtdb1-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055486" comment="libtdb1-x86 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055487" comment="libtdb1 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055488" comment="libwbclient0-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055489" comment="libwbclient0-x86 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055490" comment="libwbclient0 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055491" comment="samba-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055492" comment="samba-client-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055493" comment="samba-client-x86 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055494" comment="samba-client less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055495" comment="samba-krb-printing less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055496" comment="samba-winbind-32bit less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055497" comment="samba-winbind-x86 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055498" comment="samba-winbind less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055499" comment="samba-x86 less than 3.2.7-11.8.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055500" comment="samba less than 3.2.7-11.8.2"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092957" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2957</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2957" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2957" source="CVE"/>
	<description>
	Heap-based buffer overflow in the tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, might allow remote attackers to execute arbitrary code via a long filename in a TFTP packet, as demonstrated by a read (aka RRQ) request.
	</description>
 </metadata>
<!-- 8a9b5d38120dd10534d589b7deb85f02 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054813" comment="dnsmasq less than 2.45-12.23.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092958" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-2958</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-2958" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2958" source="CVE"/>
	<description>
	The tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a TFTP read (aka RRQ) request with a malformed blksize option.
	</description>
 </metadata>
<!-- 8a9b5d38120dd10534d589b7deb85f02 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054813" comment="dnsmasq less than 2.45-12.23.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093002" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3002</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3002" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3002" source="CVE"/>
	<description>
	The Linux kernel before 2.6.31-rc7 does not initialize certain data structures within getname functions, which allows local users to read the contents of some kernel memory locations by calling getsockname on (1) an AF_APPLETALK socket, related to the atalk_getname function in net/appletalk/ddp.c; (2) an AF_IRDA socket, related to the irda_getname function in net/irda/af_irda.c; (3) an AF_ECONET socket, related to the econet_getname function in net/econet/af_econet.c; (4) an AF_NETROM socket, related to the nr_getname function in net/netrom/af_netrom.c; (5) an AF_ROSE socket, related to the rose_getname function in net/rose/af_rose.c; or (6) a raw CAN socket, related to the raw_getname function in net/can/raw.c.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 180ffe58c62210bba55d0af594f5207f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055900" comment="ext4dev-kmp-default less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055901" comment="ext4dev-kmp-pae less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055902" comment="ext4dev-kmp-vmi less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055903" comment="ext4dev-kmp-xen less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055844" comment="kernel-default-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055846" comment="kernel-default less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055852" comment="kernel-pae-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055854" comment="kernel-pae less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055859" comment="kernel-source less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055860" comment="kernel-syms less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055904" comment="kernel-vmi-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055905" comment="kernel-vmi less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055865" comment="kernel-xen-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055867" comment="kernel-xen less than 2.6.27.37-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 650f64250b48193ff6617a946612537f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055900" comment="ext4dev-kmp-default less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055844" comment="kernel-default-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055846" comment="kernel-default less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055859" comment="kernel-source less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055860" comment="kernel-syms less than 2.6.27.37-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 6d2f53ab7e3e69501a86208057c2ef96 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055900" comment="ext4dev-kmp-default less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055903" comment="ext4dev-kmp-xen less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055844" comment="kernel-default-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055846" comment="kernel-default less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055859" comment="kernel-source less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055860" comment="kernel-syms less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055865" comment="kernel-xen-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055867" comment="kernel-xen less than 2.6.27.37-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 6dba097d1becca3dbbb21d37603b4abd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055900" comment="ext4dev-kmp-default less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055844" comment="kernel-default-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055906" comment="kernel-default-man less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055846" comment="kernel-default less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055859" comment="kernel-source less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055860" comment="kernel-syms less than 2.6.27.37-0.1.1"/>
		</criteria>
	</criteria>
	<!-- ecd5c197b4c69dacf23b245089132742 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055900" comment="ext4dev-kmp-default less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055907" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.37_0.1-7.1.18"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055844" comment="kernel-default-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055846" comment="kernel-default less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055851" comment="kernel-kdump less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055855" comment="kernel-ppc64-base less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055857" comment="kernel-ppc64 less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055859" comment="kernel-source less than 2.6.27.37-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055860" comment="kernel-syms less than 2.6.27.37-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093024" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3024</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3024" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3024" source="CVE"/>
	<description>
	The verify_hostname_of_cert function in the certificate checking feature in IO-Socket-SSL (IO::Socket::SSL) 1.14 through 1.25 only matches the prefix of a hostname when no wildcard is used, which allows remote attackers to bypass the hostname check for a certificate.
	</description>
 </metadata>
<!-- bd0f3fd9459d5cdf06cf5c9214d908b2 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009054781" comment="perl-IO-Socket-SSL less than 1.16-3.2.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093025" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3025</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3025" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3025" source="CVE"/>
	<description>
	Unspecified vulnerability in Pidgin 2.6.0 allows remote attackers to cause a denial of service (crash) via a link in a Yahoo IM.
	</description>
 </metadata>
<!-- 036b34b556d9338c53561c16d2f5a3ce -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056524" comment="cdparanoia-32bit less than IIIalpha9.8-691.22"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056525" comment="cdparanoia-x86 less than IIIalpha9.8-691.22"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056526" comment="cdparanoia less than IIIalpha9.8-691.22"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056527" comment="desktop-file-utils less than 0.15-1.29"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056528" comment="fam-32bit less than 2.7.0-130.21"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056529" comment="fam-x86 less than 2.7.0-130.21"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056530" comment="fam less than 2.7.0-130.21"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056531" comment="gnome-vfs2-32bit less than 2.24.0-7.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056532" comment="gnome-vfs2-x86 less than 2.24.0-7.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056533" comment="gnome-vfs2 less than 2.24.0-7.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056534" comment="gstreamer-0_10 less than 0.10.21-3.20"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056535" comment="libogg0-32bit less than 1.1.3-87.12"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056536" comment="libogg0-x86 less than 1.1.3-87.12"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056537" comment="libogg0 less than 1.1.3-87.12"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056538" comment="liboil-32bit less than 0.3.15-3.10"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056539" comment="liboil-x86 less than 0.3.15-3.10"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056540" comment="liboil less than 0.3.15-3.10"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056541" comment="libtheora0-32bit less than 1.0.beta2-4.28"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056542" comment="libtheora0-x86 less than 1.0.beta2-4.28"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056543" comment="libtheora0 less than 1.0.beta2-4.28"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093026" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3026</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3026" source="CVE"/>
	<description>
	protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions.
	</description>
 </metadata>
<!-- 036b34b556d9338c53561c16d2f5a3ce -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056524" comment="cdparanoia-32bit less than IIIalpha9.8-691.22"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056525" comment="cdparanoia-x86 less than IIIalpha9.8-691.22"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056526" comment="cdparanoia less than IIIalpha9.8-691.22"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056527" comment="desktop-file-utils less than 0.15-1.29"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056528" comment="fam-32bit less than 2.7.0-130.21"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056529" comment="fam-x86 less than 2.7.0-130.21"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056530" comment="fam less than 2.7.0-130.21"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056531" comment="gnome-vfs2-32bit less than 2.24.0-7.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056532" comment="gnome-vfs2-x86 less than 2.24.0-7.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056533" comment="gnome-vfs2 less than 2.24.0-7.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056534" comment="gstreamer-0_10 less than 0.10.21-3.20"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056535" comment="libogg0-32bit less than 1.1.3-87.12"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056536" comment="libogg0-x86 less than 1.1.3-87.12"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056537" comment="libogg0 less than 1.1.3-87.12"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056538" comment="liboil-32bit less than 0.3.15-3.10"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056539" comment="liboil-x86 less than 0.3.15-3.10"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056540" comment="liboil less than 0.3.15-3.10"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056541" comment="libtheora0-32bit less than 1.0.beta2-4.28"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056542" comment="libtheora0-x86 less than 1.0.beta2-4.28"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056543" comment="libtheora0 less than 1.0.beta2-4.28"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093069" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3069</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3069" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3069" source="CVE"/>
	<description>
	Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 37796416bd210b06cf2ab2fa7d6b1bd9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055061" comment="mozilla-xulrunner190-32bit less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055062" comment="mozilla-xulrunner190-32bit less than 1.9.0.14-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055063" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055064" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.14-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055065" comment="mozilla-xulrunner190-translations less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055066" comment="mozilla-xulrunner190-translations less than 1.9.0.14-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055067" comment="mozilla-xulrunner190-x86 less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055068" comment="mozilla-xulrunner190 less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055069" comment="mozilla-xulrunner190 less than 1.9.0.14-1.1.2"/>
		</criteria>
	</criteria>
	<!-- dbecc804be7d87cf75529f49774665cb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055070" comment="MozillaFirefox-branding-SLED less than 3.5-1.1.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055071" comment="MozillaFirefox-translations less than 3.5.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055072" comment="MozillaFirefox less than 3.5.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055073" comment="libfreebl3-32bit less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055074" comment="libfreebl3-x86 less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055075" comment="libfreebl3 less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055076" comment="mozilla-nspr-32bit less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055077" comment="mozilla-nspr-x86 less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055078" comment="mozilla-nspr less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055079" comment="mozilla-nss-32bit less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055080" comment="mozilla-nss-tools less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055081" comment="mozilla-nss-x86 less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055082" comment="mozilla-nss less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055083" comment="mozilla-xulrunner191-32bit less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055084" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055085" comment="mozilla-xulrunner191-translations less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055086" comment="mozilla-xulrunner191-x86 less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055087" comment="mozilla-xulrunner191 less than 1.9.1.3-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093070" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3070</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3070" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3070" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 37796416bd210b06cf2ab2fa7d6b1bd9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055061" comment="mozilla-xulrunner190-32bit less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055062" comment="mozilla-xulrunner190-32bit less than 1.9.0.14-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055063" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055064" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.14-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055065" comment="mozilla-xulrunner190-translations less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055066" comment="mozilla-xulrunner190-translations less than 1.9.0.14-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055067" comment="mozilla-xulrunner190-x86 less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055068" comment="mozilla-xulrunner190 less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055069" comment="mozilla-xulrunner190 less than 1.9.0.14-1.1.2"/>
		</criteria>
	</criteria>
	<!-- dbecc804be7d87cf75529f49774665cb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055070" comment="MozillaFirefox-branding-SLED less than 3.5-1.1.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055071" comment="MozillaFirefox-translations less than 3.5.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055072" comment="MozillaFirefox less than 3.5.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055073" comment="libfreebl3-32bit less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055074" comment="libfreebl3-x86 less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055075" comment="libfreebl3 less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055076" comment="mozilla-nspr-32bit less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055077" comment="mozilla-nspr-x86 less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055078" comment="mozilla-nspr less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055079" comment="mozilla-nss-32bit less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055080" comment="mozilla-nss-tools less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055081" comment="mozilla-nss-x86 less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055082" comment="mozilla-nss less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055083" comment="mozilla-xulrunner191-32bit less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055084" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055085" comment="mozilla-xulrunner191-translations less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055086" comment="mozilla-xulrunner191-x86 less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055087" comment="mozilla-xulrunner191 less than 1.9.1.3-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093071" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3071</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3071" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3071" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.2, allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 37796416bd210b06cf2ab2fa7d6b1bd9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055061" comment="mozilla-xulrunner190-32bit less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055062" comment="mozilla-xulrunner190-32bit less than 1.9.0.14-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055063" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055064" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.14-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055065" comment="mozilla-xulrunner190-translations less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055066" comment="mozilla-xulrunner190-translations less than 1.9.0.14-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055067" comment="mozilla-xulrunner190-x86 less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055068" comment="mozilla-xulrunner190 less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055069" comment="mozilla-xulrunner190 less than 1.9.0.14-1.1.2"/>
		</criteria>
	</criteria>
	<!-- dbecc804be7d87cf75529f49774665cb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055070" comment="MozillaFirefox-branding-SLED less than 3.5-1.1.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055071" comment="MozillaFirefox-translations less than 3.5.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055072" comment="MozillaFirefox less than 3.5.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055073" comment="libfreebl3-32bit less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055074" comment="libfreebl3-x86 less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055075" comment="libfreebl3 less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055076" comment="mozilla-nspr-32bit less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055077" comment="mozilla-nspr-x86 less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055078" comment="mozilla-nspr less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055079" comment="mozilla-nss-32bit less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055080" comment="mozilla-nss-tools less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055081" comment="mozilla-nss-x86 less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055082" comment="mozilla-nss less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055083" comment="mozilla-xulrunner191-32bit less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055084" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055085" comment="mozilla-xulrunner191-translations less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055086" comment="mozilla-xulrunner191-x86 less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055087" comment="mozilla-xulrunner191 less than 1.9.1.3-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093072" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3072</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3072" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3072" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14 and 3.5.x before 3.5.3, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the BinHex decoder in netwerk/streamconv/converters/nsBinHexDecoder.cpp, and unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 37796416bd210b06cf2ab2fa7d6b1bd9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055061" comment="mozilla-xulrunner190-32bit less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055062" comment="mozilla-xulrunner190-32bit less than 1.9.0.14-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055063" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055064" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.14-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055065" comment="mozilla-xulrunner190-translations less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055066" comment="mozilla-xulrunner190-translations less than 1.9.0.14-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055067" comment="mozilla-xulrunner190-x86 less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055068" comment="mozilla-xulrunner190 less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055069" comment="mozilla-xulrunner190 less than 1.9.0.14-1.1.2"/>
		</criteria>
	</criteria>
	<!-- dbecc804be7d87cf75529f49774665cb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055070" comment="MozillaFirefox-branding-SLED less than 3.5-1.1.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055071" comment="MozillaFirefox-translations less than 3.5.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055072" comment="MozillaFirefox less than 3.5.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055073" comment="libfreebl3-32bit less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055074" comment="libfreebl3-x86 less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055075" comment="libfreebl3 less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055076" comment="mozilla-nspr-32bit less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055077" comment="mozilla-nspr-x86 less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055078" comment="mozilla-nspr less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055079" comment="mozilla-nss-32bit less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055080" comment="mozilla-nss-tools less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055081" comment="mozilla-nss-x86 less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055082" comment="mozilla-nss less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055083" comment="mozilla-xulrunner191-32bit less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055084" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055085" comment="mozilla-xulrunner191-translations less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055086" comment="mozilla-xulrunner191-x86 less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055087" comment="mozilla-xulrunner191 less than 1.9.1.3-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093073" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3073</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3073" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3073" source="CVE"/>
	<description>
	Unspecified vulnerability in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 37796416bd210b06cf2ab2fa7d6b1bd9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055061" comment="mozilla-xulrunner190-32bit less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055062" comment="mozilla-xulrunner190-32bit less than 1.9.0.14-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055063" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055064" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.14-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055065" comment="mozilla-xulrunner190-translations less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055066" comment="mozilla-xulrunner190-translations less than 1.9.0.14-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055067" comment="mozilla-xulrunner190-x86 less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055068" comment="mozilla-xulrunner190 less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055069" comment="mozilla-xulrunner190 less than 1.9.0.14-1.1.2"/>
		</criteria>
	</criteria>
	<!-- dbecc804be7d87cf75529f49774665cb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055070" comment="MozillaFirefox-branding-SLED less than 3.5-1.1.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055071" comment="MozillaFirefox-translations less than 3.5.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055072" comment="MozillaFirefox less than 3.5.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055073" comment="libfreebl3-32bit less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055074" comment="libfreebl3-x86 less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055075" comment="libfreebl3 less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055076" comment="mozilla-nspr-32bit less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055077" comment="mozilla-nspr-x86 less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055078" comment="mozilla-nspr less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055079" comment="mozilla-nss-32bit less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055080" comment="mozilla-nss-tools less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055081" comment="mozilla-nss-x86 less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055082" comment="mozilla-nss less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055083" comment="mozilla-xulrunner191-32bit less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055084" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055085" comment="mozilla-xulrunner191-translations less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055086" comment="mozilla-xulrunner191-x86 less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055087" comment="mozilla-xulrunner191 less than 1.9.1.3-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093075" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3075</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3075" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3075" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox before 3.0.14 and 3.5.x before 3.5.2, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to use of mutable strings in the js_StringReplaceHelper function in js/src/jsstr.cpp, and unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 37796416bd210b06cf2ab2fa7d6b1bd9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055061" comment="mozilla-xulrunner190-32bit less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055062" comment="mozilla-xulrunner190-32bit less than 1.9.0.14-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055063" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055064" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.14-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055065" comment="mozilla-xulrunner190-translations less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055066" comment="mozilla-xulrunner190-translations less than 1.9.0.14-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055067" comment="mozilla-xulrunner190-x86 less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055068" comment="mozilla-xulrunner190 less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055069" comment="mozilla-xulrunner190 less than 1.9.0.14-1.1.2"/>
		</criteria>
	</criteria>
	<!-- dbecc804be7d87cf75529f49774665cb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055070" comment="MozillaFirefox-branding-SLED less than 3.5-1.1.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055071" comment="MozillaFirefox-translations less than 3.5.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055072" comment="MozillaFirefox less than 3.5.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055073" comment="libfreebl3-32bit less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055074" comment="libfreebl3-x86 less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055075" comment="libfreebl3 less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055076" comment="mozilla-nspr-32bit less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055077" comment="mozilla-nspr-x86 less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055078" comment="mozilla-nspr less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055079" comment="mozilla-nss-32bit less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055080" comment="mozilla-nss-tools less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055081" comment="mozilla-nss-x86 less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055082" comment="mozilla-nss less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055083" comment="mozilla-xulrunner191-32bit less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055084" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055085" comment="mozilla-xulrunner191-translations less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055086" comment="mozilla-xulrunner191-x86 less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055087" comment="mozilla-xulrunner191 less than 1.9.1.3-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093076" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3076</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3076" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3076" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.14 does not properly implement certain dialogs associated with the (1) pkcs11.addmodule and (2) pkcs11.deletemodule operations, which makes it easier for remote attackers to trick a user into installing or removing an arbitrary PKCS11 module.
	</description>
 </metadata>
<!-- 37796416bd210b06cf2ab2fa7d6b1bd9 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009055061" comment="mozilla-xulrunner190-32bit less than 1.9.0.14-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055062" comment="mozilla-xulrunner190-32bit less than 1.9.0.14-1.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055063" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.14-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055064" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.14-1.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055065" comment="mozilla-xulrunner190-translations less than 1.9.0.14-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055066" comment="mozilla-xulrunner190-translations less than 1.9.0.14-1.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055067" comment="mozilla-xulrunner190-x86 less than 1.9.0.14-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055068" comment="mozilla-xulrunner190 less than 1.9.0.14-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055069" comment="mozilla-xulrunner190 less than 1.9.0.14-1.1.2"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093077" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3077</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3077" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3077" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, does not properly manage pointers for the columns (aka TreeColumns) of a XUL tree element, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to a "dangling pointer vulnerability."
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 37796416bd210b06cf2ab2fa7d6b1bd9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055061" comment="mozilla-xulrunner190-32bit less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055062" comment="mozilla-xulrunner190-32bit less than 1.9.0.14-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055063" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055064" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.14-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055065" comment="mozilla-xulrunner190-translations less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055066" comment="mozilla-xulrunner190-translations less than 1.9.0.14-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055067" comment="mozilla-xulrunner190-x86 less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055068" comment="mozilla-xulrunner190 less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055069" comment="mozilla-xulrunner190 less than 1.9.0.14-1.1.2"/>
		</criteria>
	</criteria>
	<!-- dbecc804be7d87cf75529f49774665cb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055070" comment="MozillaFirefox-branding-SLED less than 3.5-1.1.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055071" comment="MozillaFirefox-translations less than 3.5.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055072" comment="MozillaFirefox less than 3.5.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055073" comment="libfreebl3-32bit less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055074" comment="libfreebl3-x86 less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055075" comment="libfreebl3 less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055076" comment="mozilla-nspr-32bit less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055077" comment="mozilla-nspr-x86 less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055078" comment="mozilla-nspr less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055079" comment="mozilla-nss-32bit less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055080" comment="mozilla-nss-tools less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055081" comment="mozilla-nss-x86 less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055082" comment="mozilla-nss less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055083" comment="mozilla-xulrunner191-32bit less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055084" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055085" comment="mozilla-xulrunner191-translations less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055086" comment="mozilla-xulrunner191-x86 less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055087" comment="mozilla-xulrunner191 less than 1.9.1.3-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093078" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3078</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3078" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3078" source="CVE"/>
	<description>
	Visual truncation vulnerability in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, allows remote attackers to trigger a vertical scroll and spoof URLs via unspecified Unicode characters with a tall line-height property.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 37796416bd210b06cf2ab2fa7d6b1bd9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055061" comment="mozilla-xulrunner190-32bit less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055062" comment="mozilla-xulrunner190-32bit less than 1.9.0.14-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055063" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055064" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.14-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055065" comment="mozilla-xulrunner190-translations less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055066" comment="mozilla-xulrunner190-translations less than 1.9.0.14-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055067" comment="mozilla-xulrunner190-x86 less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055068" comment="mozilla-xulrunner190 less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055069" comment="mozilla-xulrunner190 less than 1.9.0.14-1.1.2"/>
		</criteria>
	</criteria>
	<!-- dbecc804be7d87cf75529f49774665cb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055070" comment="MozillaFirefox-branding-SLED less than 3.5-1.1.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055071" comment="MozillaFirefox-translations less than 3.5.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055072" comment="MozillaFirefox less than 3.5.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055073" comment="libfreebl3-32bit less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055074" comment="libfreebl3-x86 less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055075" comment="libfreebl3 less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055076" comment="mozilla-nspr-32bit less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055077" comment="mozilla-nspr-x86 less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055078" comment="mozilla-nspr less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055079" comment="mozilla-nss-32bit less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055080" comment="mozilla-nss-tools less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055081" comment="mozilla-nss-x86 less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055082" comment="mozilla-nss less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055083" comment="mozilla-xulrunner191-32bit less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055084" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055085" comment="mozilla-xulrunner191-translations less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055086" comment="mozilla-xulrunner191-x86 less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055087" comment="mozilla-xulrunner191 less than 1.9.1.3-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093079" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3079</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3079" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3079" source="CVE"/>
	<description>
	Unspecified vulnerability in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, allows remote attackers to execute arbitrary JavaScript with chrome privileges via vectors involving an object, the FeedWriter, and the BrowserFeedWriter.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 37796416bd210b06cf2ab2fa7d6b1bd9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055061" comment="mozilla-xulrunner190-32bit less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055062" comment="mozilla-xulrunner190-32bit less than 1.9.0.14-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055063" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055064" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.14-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055065" comment="mozilla-xulrunner190-translations less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055066" comment="mozilla-xulrunner190-translations less than 1.9.0.14-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055067" comment="mozilla-xulrunner190-x86 less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055068" comment="mozilla-xulrunner190 less than 1.9.0.14-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055069" comment="mozilla-xulrunner190 less than 1.9.0.14-1.1.2"/>
		</criteria>
	</criteria>
	<!-- dbecc804be7d87cf75529f49774665cb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055070" comment="MozillaFirefox-branding-SLED less than 3.5-1.1.5"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055071" comment="MozillaFirefox-translations less than 3.5.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055072" comment="MozillaFirefox less than 3.5.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055073" comment="libfreebl3-32bit less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055074" comment="libfreebl3-x86 less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055075" comment="libfreebl3 less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055076" comment="mozilla-nspr-32bit less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055077" comment="mozilla-nspr-x86 less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055078" comment="mozilla-nspr less than 4.8-1.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055079" comment="mozilla-nss-32bit less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055080" comment="mozilla-nss-tools less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055081" comment="mozilla-nss-x86 less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055082" comment="mozilla-nss less than 3.12.3.1-1.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055083" comment="mozilla-xulrunner191-32bit less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055084" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055085" comment="mozilla-xulrunner191-translations less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055086" comment="mozilla-xulrunner191-x86 less than 1.9.1.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055087" comment="mozilla-xulrunner191 less than 1.9.1.3-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093080" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3080</title>
	<affected family="unix">
		<platform>SLE 11 SERVER Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3080" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3080" source="CVE"/>
	<description>
	Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows local users to cause a denial of service or possibly gain privileges via a negative event index in an IOCTL request.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 4971d1bc45dfe19245872ca92e7fe051 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057255" comment="kernel-default-extra less than 2.6.27.39-0.3.2"/>
	</criteria>
	<!-- 51cdeaf4505dbc37870fece945793189 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057255" comment="kernel-default-extra less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057256" comment="kernel-ppc64-extra less than 2.6.27.39-0.3.2"/>
		</criteria>
	</criteria>
	<!-- 5ecbc30d0c137f9f7ce500a198dee54a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057257" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057258" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.39_0.3-7.1.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057259" comment="kernel-default-base less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057260" comment="kernel-default less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057261" comment="kernel-kdump less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057262" comment="kernel-ppc64-base less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057263" comment="kernel-ppc64 less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057264" comment="kernel-source less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057265" comment="kernel-syms less than 2.6.27.39-0.3.2"/>
		</criteria>
	</criteria>
	<!-- 9a0454a0e15d8a3d7e1869913ff2b725 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057233" comment="kernel-xen-extra less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- c9825ea9eb0265fbaf58b4e7f15828d7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
	</criteria>
	<!-- d4c3d61ff4cb77f117d3acbc6602aaeb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057220" comment="kernel-pae-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057233" comment="kernel-xen-extra less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e7c5f7ef7eeb152d788f9406d2374894 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059470" comment="ext4dev-kmp-default less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059471" comment="ext4dev-kmp-pae less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059472" comment="ext4dev-kmp-vmi less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059473" comment="ext4dev-kmp-xen less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057219" comment="kernel-pae-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057221" comment="kernel-pae less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059474" comment="kernel-vmi-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059475" comment="kernel-vmi less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057232" comment="kernel-xen-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057234" comment="kernel-xen less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e87c441668f87fa162f810ea0e06c3ba -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059470" comment="ext4dev-kmp-default less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059473" comment="ext4dev-kmp-xen less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057232" comment="kernel-xen-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057234" comment="kernel-xen less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- ef72143c4837b653dc18408ca8832f96 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057257" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057259" comment="kernel-default-base less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057260" comment="kernel-default less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057264" comment="kernel-source less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057265" comment="kernel-syms less than 2.6.27.39-0.3.2"/>
		</criteria>
	</criteria>
	<!-- f5e83f559ce7469c64852e5d2a3cc38d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059470" comment="ext4dev-kmp-default less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059476" comment="kernel-default-man less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093083" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3083</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3083" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3083" source="CVE"/>
	<description>
	The msn_slp_sip_recv function in libpurple/protocols/msn/slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an SLP invite message that lacks certain required fields, as demonstrated by a malformed message from a KMess client.
	</description>
 </metadata>
<!-- 036b34b556d9338c53561c16d2f5a3ce -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056524" comment="cdparanoia-32bit less than IIIalpha9.8-691.22"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056525" comment="cdparanoia-x86 less than IIIalpha9.8-691.22"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056526" comment="cdparanoia less than IIIalpha9.8-691.22"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056527" comment="desktop-file-utils less than 0.15-1.29"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056528" comment="fam-32bit less than 2.7.0-130.21"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056529" comment="fam-x86 less than 2.7.0-130.21"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056530" comment="fam less than 2.7.0-130.21"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056531" comment="gnome-vfs2-32bit less than 2.24.0-7.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056532" comment="gnome-vfs2-x86 less than 2.24.0-7.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056533" comment="gnome-vfs2 less than 2.24.0-7.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056534" comment="gstreamer-0_10 less than 0.10.21-3.20"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056535" comment="libogg0-32bit less than 1.1.3-87.12"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056536" comment="libogg0-x86 less than 1.1.3-87.12"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056537" comment="libogg0 less than 1.1.3-87.12"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056538" comment="liboil-32bit less than 0.3.15-3.10"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056539" comment="liboil-x86 less than 0.3.15-3.10"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056540" comment="liboil less than 0.3.15-3.10"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056541" comment="libtheora0-32bit less than 1.0.beta2-4.28"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056542" comment="libtheora0-x86 less than 1.0.beta2-4.28"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056543" comment="libtheora0 less than 1.0.beta2-4.28"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093084" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3084</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3084" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3084" source="CVE"/>
	<description>
	The msn_slp_process_msg function in libpurple/protocols/msn/slpcall.c in the MSN protocol plugin in libpurple 2.6.0 and 2.6.1, as used in Pidgin before 2.6.2, allows remote attackers to cause a denial of service (application crash) via a handwritten (aka Ink) message, related to an uninitialized variable and the incorrect "UTF16-LE" charset name.
	</description>
 </metadata>
<!-- 036b34b556d9338c53561c16d2f5a3ce -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056524" comment="cdparanoia-32bit less than IIIalpha9.8-691.22"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056525" comment="cdparanoia-x86 less than IIIalpha9.8-691.22"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056526" comment="cdparanoia less than IIIalpha9.8-691.22"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056527" comment="desktop-file-utils less than 0.15-1.29"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056528" comment="fam-32bit less than 2.7.0-130.21"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056529" comment="fam-x86 less than 2.7.0-130.21"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056530" comment="fam less than 2.7.0-130.21"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056531" comment="gnome-vfs2-32bit less than 2.24.0-7.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056532" comment="gnome-vfs2-x86 less than 2.24.0-7.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056533" comment="gnome-vfs2 less than 2.24.0-7.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056534" comment="gstreamer-0_10 less than 0.10.21-3.20"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056535" comment="libogg0-32bit less than 1.1.3-87.12"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056536" comment="libogg0-x86 less than 1.1.3-87.12"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056537" comment="libogg0 less than 1.1.3-87.12"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056538" comment="liboil-32bit less than 0.3.15-3.10"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056539" comment="liboil-x86 less than 0.3.15-3.10"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056540" comment="liboil less than 0.3.15-3.10"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056541" comment="libtheora0-32bit less than 1.0.beta2-4.28"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056542" comment="libtheora0-x86 less than 1.0.beta2-4.28"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056543" comment="libtheora0 less than 1.0.beta2-4.28"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093085" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3085</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3085" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3085" source="CVE"/>
	<description>
	The XMPP protocol plugin in libpurple in Pidgin before 2.6.2 does not properly handle an error IQ stanza during an attempted fetch of a custom smiley, which allows remote attackers to cause a denial of service (application crash) via XHTML-IM content with cid: images.
	</description>
 </metadata>
<!-- 036b34b556d9338c53561c16d2f5a3ce -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056524" comment="cdparanoia-32bit less than IIIalpha9.8-691.22"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056525" comment="cdparanoia-x86 less than IIIalpha9.8-691.22"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056526" comment="cdparanoia less than IIIalpha9.8-691.22"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056527" comment="desktop-file-utils less than 0.15-1.29"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056528" comment="fam-32bit less than 2.7.0-130.21"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056529" comment="fam-x86 less than 2.7.0-130.21"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056530" comment="fam less than 2.7.0-130.21"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056531" comment="gnome-vfs2-32bit less than 2.24.0-7.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056532" comment="gnome-vfs2-x86 less than 2.24.0-7.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056533" comment="gnome-vfs2 less than 2.24.0-7.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056534" comment="gstreamer-0_10 less than 0.10.21-3.20"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056535" comment="libogg0-32bit less than 1.1.3-87.12"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056536" comment="libogg0-x86 less than 1.1.3-87.12"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056537" comment="libogg0 less than 1.1.3-87.12"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056538" comment="liboil-32bit less than 0.3.15-3.10"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056539" comment="liboil-x86 less than 0.3.15-3.10"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056540" comment="liboil less than 0.3.15-3.10"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056541" comment="libtheora0-32bit less than 1.0.beta2-4.28"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056542" comment="libtheora0-x86 less than 1.0.beta2-4.28"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056543" comment="libtheora0 less than 1.0.beta2-4.28"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093094" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3094</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3094" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3094" source="CVE"/>
	<description>
	The ap_proxy_ftp_handler function in modules/proxy/proxy_ftp.c in the mod_proxy_ftp module in the Apache HTTP Server 2.0.63 and 2.2.13 allows remote FTP servers to cause a denial of service (NULL pointer dereference and child process crash) via a malformed reply to an EPSV command.
	</description>
 </metadata>
<!-- ca7f5abf8025ba6ef69af14cd6570458 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009055706" comment="apache2-doc less than 2.2.10-2.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055707" comment="apache2-example-pages less than 2.2.10-2.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055708" comment="apache2-prefork less than 2.2.10-2.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055709" comment="apache2-utils less than 2.2.10-2.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055710" comment="apache2-worker less than 2.2.10-2.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055711" comment="apache2 less than 2.2.10-2.21.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093095" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3095</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3095" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3095" source="CVE"/>
	<description>
	The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstrated by a certain module in VulnDisco Pack Professional 8.11.
	</description>
 </metadata>
<!-- ca7f5abf8025ba6ef69af14cd6570458 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009055706" comment="apache2-doc less than 2.2.10-2.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055707" comment="apache2-example-pages less than 2.2.10-2.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055708" comment="apache2-prefork less than 2.2.10-2.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055709" comment="apache2-utils less than 2.2.10-2.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055710" comment="apache2-worker less than 2.2.10-2.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055711" comment="apache2 less than 2.2.10-2.21.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093229" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3229</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3229" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3229" source="CVE"/>
	<description>
	The core server component in PostgreSQL 8.4 before 8.4.1, 8.3 before 8.3.8, and 8.2 before 8.2.14 allows remote authenticated users to cause a denial of service (backend shutdown) by "re-LOAD-ing" libraries from a certain plugins directory.
	</description>
 </metadata>
<!-- cd52231925ea5e4eb6c7b6a30a4b49ca -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009055020" comment="postgresql-contrib less than 8.3.8-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055021" comment="postgresql-docs less than 8.3.8-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055022" comment="postgresql-libs-32bit less than 8.3.8-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055023" comment="postgresql-libs-x86 less than 8.3.8-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055024" comment="postgresql-libs less than 8.3.8-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055025" comment="postgresql-server less than 8.3.8-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055026" comment="postgresql less than 8.3.8-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093230" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3230</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3230" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3230" source="CVE"/>
	<description>
	The core server component in PostgreSQL 8.4 before 8.4.1, 8.3 before 8.3.8, 8.2 before 8.2.14, 8.1 before 8.1.18, 8.0 before 8.0.22, and 7.4 before 7.4.26 does not use the appropriate privileges for the (1) RESET ROLE and (2) RESET SESSION AUTHORIZATION operations, which allows remote authenticated users to gain privileges.  NOTE: this is due to an incomplete fix for CVE-2007-6600.
	</description>
 </metadata>
<!-- cd52231925ea5e4eb6c7b6a30a4b49ca -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009055020" comment="postgresql-contrib less than 8.3.8-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055021" comment="postgresql-docs less than 8.3.8-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055022" comment="postgresql-libs-32bit less than 8.3.8-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055023" comment="postgresql-libs-x86 less than 8.3.8-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055024" comment="postgresql-libs less than 8.3.8-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055025" comment="postgresql-server less than 8.3.8-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055026" comment="postgresql less than 8.3.8-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093231" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3231</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3231" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3231" source="CVE"/>
	<description>
	The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.
	</description>
 </metadata>
<!-- cd52231925ea5e4eb6c7b6a30a4b49ca -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009055020" comment="postgresql-contrib less than 8.3.8-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055021" comment="postgresql-docs less than 8.3.8-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055022" comment="postgresql-libs-32bit less than 8.3.8-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055023" comment="postgresql-libs-x86 less than 8.3.8-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055024" comment="postgresql-libs less than 8.3.8-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055025" comment="postgresql-server less than 8.3.8-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055026" comment="postgresql less than 8.3.8-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093235" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3235</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3235" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3235" source="CVE"/>
	<description>
	Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-2632.
	</description>
 </metadata>
<!-- 6cb1abd475b993f09a98d4a2191bb23f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009055776" comment="cyrus-imapd less than 2.3.11-60.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055777" comment="perl-Cyrus-IMAP less than 2.3.11-60.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055778" comment="perl-Cyrus-SIEVE-managesieve less than 2.3.11-60.21.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093245" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3245</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3245" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3245" source="CVE"/>
	<description>
	OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact and context-dependent attack vectors.
	</description>
 </metadata>
<!-- fba66235e940d7d2f4064d7e1e803b60 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059248" comment="libopenssl0_9_8-32bit less than 0.9.8h-30.22.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059249" comment="libopenssl0_9_8-x86 less than 0.9.8h-30.22.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059250" comment="libopenssl0_9_8 less than 0.9.8h-30.22.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059251" comment="openssl-doc less than 0.9.8h-30.22.21.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059252" comment="openssl less than 0.9.8h-30.22.21.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093274" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3274</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3274" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3274" source="CVE"/>
	<description>
	Mozilla Firefox 3.6a1, 3.5.3, 3.5.2, and earlier 3.5.x versions, and 3.0.14 and earlier 2.x and 3.x versions, on Linux uses a predictable /tmp pathname for files selected from the Downloads window, which allows local users to replace an arbitrary downloaded file by placing a file in a /tmp location before the download occurs, related to the Download Manager component. NOTE: some of these details are obtained from third party information.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04c6e38838a85fc92531b3e56904b052 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055940" comment="mozilla-xulrunner190-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055941" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055942" comment="mozilla-xulrunner190-translations less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055943" comment="mozilla-xulrunner190-x86 less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055944" comment="mozilla-xulrunner190 less than 1.9.0.15-0.1.2"/>
		</criteria>
	</criteria>
	<!-- 49179a9289fbe778bc2320690c17d088 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055945" comment="MozillaFirefox-translations less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055946" comment="MozillaFirefox less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055947" comment="mozilla-xulrunner191-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055948" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055949" comment="mozilla-xulrunner191-translations less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055950" comment="mozilla-xulrunner191-x86 less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055951" comment="mozilla-xulrunner191 less than 1.9.1.4-2.1.3"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093286" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3286</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3286" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3286" source="CVE"/>
	<description>
	NFSv4 in the Linux kernel 2.6.18, and possibly other versions, does not properly clean up an inode when an O_EXCL create fails, which causes files to be created with insecure settings such as setuid bits, and possibly allows local users to gain privileges, related to the execution of the do_open_permission function even when a create fails.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 114b9cf953db7d4a1a91082495d33414 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056506" comment="ext4dev-kmp-xen less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056511" comment="kernel-xen-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056512" comment="kernel-xen less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- 9b6d121530adca742ba4b1a99075559a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056513" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056514" comment="kernel-kdump less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056515" comment="kernel-ppc64-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056516" comment="kernel-ppc64 less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- a3c4f0428e25dca1993e5018e76d6758 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056517" comment="ext4dev-kmp-pae less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056518" comment="ext4dev-kmp-vmi less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056506" comment="ext4dev-kmp-xen less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056519" comment="kernel-pae-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056520" comment="kernel-pae less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056521" comment="kernel-vmi-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056522" comment="kernel-vmi less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056511" comment="kernel-xen-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056512" comment="kernel-xen less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- dfdf7dd3f18b0b2cf8024eb5a30e51ba -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- faf6558ee52bc90aea4840dc79e5757f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056523" comment="kernel-default-man less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093289" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3289</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3289" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3289" source="CVE"/>
	<description>
	The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), which allows user-assisted local users to modify files of other users, as demonstrated by using Nautilus to modify the permissions of the user home directory.
	</description>
 </metadata>
<!-- 9d502b72aea0be06bdfccffe06a4262e -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059846" comment="glib2-doc less than 2.18.2-7.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059847" comment="glib2-lang less than 2.18.2-7.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059848" comment="glib2 less than 2.18.2-7.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059849" comment="libgio-2_0-0-32bit less than 2.18.2-7.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059850" comment="libgio-2_0-0-x86 less than 2.18.2-7.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059851" comment="libgio-2_0-0 less than 2.18.2-7.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059852" comment="libglib-2_0-0-32bit less than 2.18.2-7.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059853" comment="libglib-2_0-0-x86 less than 2.18.2-7.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059854" comment="libglib-2_0-0 less than 2.18.2-7.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059855" comment="libgmodule-2_0-0-32bit less than 2.18.2-7.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059856" comment="libgmodule-2_0-0-x86 less than 2.18.2-7.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059857" comment="libgmodule-2_0-0 less than 2.18.2-7.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059858" comment="libgobject-2_0-0-32bit less than 2.18.2-7.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059859" comment="libgobject-2_0-0-x86 less than 2.18.2-7.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059860" comment="libgobject-2_0-0 less than 2.18.2-7.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059861" comment="libgthread-2_0-0-32bit less than 2.18.2-7.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059862" comment="libgthread-2_0-0-x86 less than 2.18.2-7.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059863" comment="libgthread-2_0-0 less than 2.18.2-7.9.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093291" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3291</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3291" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3291" source="CVE"/>
	<description>
	The php_openssl_apply_verification_policy function in PHP before 5.2.11 does not properly perform certificate validation, which has unknown impact and attack vectors, probably related to an ability to spoof certificates.
	</description>
 </metadata>
<!-- 6f524102537d5a77ed575f0190599d68 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009055145" comment="apache2-mod_php5 less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055146" comment="php5-bcmath less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055147" comment="php5-bz2 less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055148" comment="php5-calendar less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055149" comment="php5-ctype less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055150" comment="php5-curl less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055151" comment="php5-dba less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055152" comment="php5-dbase less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055153" comment="php5-dom less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055154" comment="php5-exif less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055155" comment="php5-fastcgi less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055156" comment="php5-ftp less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055157" comment="php5-gd less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055158" comment="php5-gettext less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055159" comment="php5-gmp less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055160" comment="php5-hash less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055161" comment="php5-iconv less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055162" comment="php5-json less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055163" comment="php5-ldap less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055164" comment="php5-mbstring less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055165" comment="php5-mcrypt less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055166" comment="php5-mysql less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055167" comment="php5-odbc less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055168" comment="php5-openssl less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055169" comment="php5-pcntl less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055170" comment="php5-pdo less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055171" comment="php5-pear less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055172" comment="php5-pgsql less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055173" comment="php5-pspell less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055174" comment="php5-shmop less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055175" comment="php5-snmp less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055176" comment="php5-soap less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055177" comment="php5-suhosin less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055178" comment="php5-sysvmsg less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055179" comment="php5-sysvsem less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055180" comment="php5-sysvshm less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055181" comment="php5-tokenizer less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055182" comment="php5-wddx less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055183" comment="php5-xmlreader less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055184" comment="php5-xmlrpc less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055185" comment="php5-xmlwriter less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055186" comment="php5-xsl less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055187" comment="php5-zip less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055188" comment="php5-zlib less than 5.2.6-50.23.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093292" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3292</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3292" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3292" source="CVE"/>
	<description>
	Unspecified vulnerability in PHP before 5.2.11, and 5.3.x before 5.3.1, has unknown impact and attack vectors related to "missing sanity checks around exif processing."
	</description>
 </metadata>
<!-- 6f524102537d5a77ed575f0190599d68 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009055145" comment="apache2-mod_php5 less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055146" comment="php5-bcmath less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055147" comment="php5-bz2 less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055148" comment="php5-calendar less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055149" comment="php5-ctype less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055150" comment="php5-curl less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055151" comment="php5-dba less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055152" comment="php5-dbase less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055153" comment="php5-dom less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055154" comment="php5-exif less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055155" comment="php5-fastcgi less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055156" comment="php5-ftp less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055157" comment="php5-gd less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055158" comment="php5-gettext less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055159" comment="php5-gmp less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055160" comment="php5-hash less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055161" comment="php5-iconv less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055162" comment="php5-json less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055163" comment="php5-ldap less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055164" comment="php5-mbstring less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055165" comment="php5-mcrypt less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055166" comment="php5-mysql less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055167" comment="php5-odbc less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055168" comment="php5-openssl less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055169" comment="php5-pcntl less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055170" comment="php5-pdo less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055171" comment="php5-pear less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055172" comment="php5-pgsql less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055173" comment="php5-pspell less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055174" comment="php5-shmop less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055175" comment="php5-snmp less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055176" comment="php5-soap less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055177" comment="php5-suhosin less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055178" comment="php5-sysvmsg less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055179" comment="php5-sysvsem less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055180" comment="php5-sysvshm less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055181" comment="php5-tokenizer less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055182" comment="php5-wddx less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055183" comment="php5-xmlreader less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055184" comment="php5-xmlrpc less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055185" comment="php5-xmlwriter less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055186" comment="php5-xsl less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055187" comment="php5-zip less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055188" comment="php5-zlib less than 5.2.6-50.23.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093293" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3293</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3293" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3293" source="CVE"/>
	<description>
	Unspecified vulnerability in the imagecolortransparent function in PHP before 5.2.11 has unknown impact and attack vectors related to an incorrect "sanity check for the color index."
	</description>
 </metadata>
<!-- 6f524102537d5a77ed575f0190599d68 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009055145" comment="apache2-mod_php5 less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055146" comment="php5-bcmath less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055147" comment="php5-bz2 less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055148" comment="php5-calendar less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055149" comment="php5-ctype less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055150" comment="php5-curl less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055151" comment="php5-dba less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055152" comment="php5-dbase less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055153" comment="php5-dom less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055154" comment="php5-exif less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055155" comment="php5-fastcgi less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055156" comment="php5-ftp less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055157" comment="php5-gd less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055158" comment="php5-gettext less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055159" comment="php5-gmp less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055160" comment="php5-hash less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055161" comment="php5-iconv less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055162" comment="php5-json less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055163" comment="php5-ldap less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055164" comment="php5-mbstring less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055165" comment="php5-mcrypt less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055166" comment="php5-mysql less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055167" comment="php5-odbc less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055168" comment="php5-openssl less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055169" comment="php5-pcntl less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055170" comment="php5-pdo less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055171" comment="php5-pear less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055172" comment="php5-pgsql less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055173" comment="php5-pspell less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055174" comment="php5-shmop less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055175" comment="php5-snmp less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055176" comment="php5-soap less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055177" comment="php5-suhosin less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055178" comment="php5-sysvmsg less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055179" comment="php5-sysvsem less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055180" comment="php5-sysvshm less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055181" comment="php5-tokenizer less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055182" comment="php5-wddx less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055183" comment="php5-xmlreader less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055184" comment="php5-xmlrpc less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055185" comment="php5-xmlwriter less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055186" comment="php5-xsl less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055187" comment="php5-zip less than 5.2.6-50.23.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055188" comment="php5-zlib less than 5.2.6-50.23.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093295" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3295</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3295" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3295" source="CVE"/>
	<description>
	The prep_reprocess_req function in kdc/do_tgs_req.c in the cross-realm referral implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a ticket request.
	</description>
 </metadata>
<!-- f95c0cbef4a252636c67dd8d77f705f6 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009057338" comment="krb5-32bit less than 1.6.3-133.26.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057339" comment="krb5-apps-clients less than 1.6.3-133.26.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057340" comment="krb5-apps-servers less than 1.6.3-133.26.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057341" comment="krb5-client less than 1.6.3-133.26.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057342" comment="krb5-server less than 1.6.3-133.26.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057343" comment="krb5-x86 less than 1.6.3-133.26.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057344" comment="krb5 less than 1.6.3-133.26.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093297" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3297</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3297" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3297" source="CVE"/>
	<description>
	** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2010-0787, CVE-2010-0788, CVE-2010-0789.  Reason: this candidate was intended for one issue in Samba, but it was used for multiple distinct issues, including one in FUSE and one in ncpfs.  Notes: All CVE users should consult CVE-2010-0787 (Samba), CVE-2010-0788 (ncpfs), and CVE-2010-0789 (FUSE) to determine which ID is appropriate.  All references and descriptions in this candidate have been removed to prevent accidental usage.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- b56bbe075a71b8de518011c0b0f5e42e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060019" comment="fuse less than 2.7.2-61.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060020" comment="libfuse2 less than 2.7.2-61.18.1"/>
		</criteria>
	</criteria>
	<!-- f1ed5706f5031275bd4d15784f3692ad -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057690" comment="fuse less than 2.7.2-61.15.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057691" comment="libfuse2 less than 2.7.2-61.15.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093370" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3370</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3370" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3370" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.15, and 3.5.x before 3.5.4, allows remote attackers to read form history by forging mouse and keyboard events that leverage the auto-fill feature to populate form fields, in an attacker-readable form, with history entries.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04c6e38838a85fc92531b3e56904b052 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055940" comment="mozilla-xulrunner190-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055941" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055942" comment="mozilla-xulrunner190-translations less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055943" comment="mozilla-xulrunner190-x86 less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055944" comment="mozilla-xulrunner190 less than 1.9.0.15-0.1.2"/>
		</criteria>
	</criteria>
	<!-- 49179a9289fbe778bc2320690c17d088 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055945" comment="MozillaFirefox-translations less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055946" comment="MozillaFirefox less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055947" comment="mozilla-xulrunner191-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055948" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055949" comment="mozilla-xulrunner191-translations less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055950" comment="mozilla-xulrunner191-x86 less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055951" comment="mozilla-xulrunner191 less than 1.9.1.4-2.1.3"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093371" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3371</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3371" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3371" source="CVE"/>
	<description>
	Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by creating JavaScript web-workers recursively.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04c6e38838a85fc92531b3e56904b052 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055940" comment="mozilla-xulrunner190-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055941" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055942" comment="mozilla-xulrunner190-translations less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055943" comment="mozilla-xulrunner190-x86 less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055944" comment="mozilla-xulrunner190 less than 1.9.0.15-0.1.2"/>
		</criteria>
	</criteria>
	<!-- 49179a9289fbe778bc2320690c17d088 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055945" comment="MozillaFirefox-translations less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055946" comment="MozillaFirefox less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055947" comment="mozilla-xulrunner191-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055948" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055949" comment="mozilla-xulrunner191-translations less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055950" comment="mozilla-xulrunner191-x86 less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055951" comment="mozilla-xulrunner191 less than 1.9.1.4-2.1.3"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093372" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3372</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3372" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3372" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via a crafted regular expression in a Proxy Auto-configuration (PAC) file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04c6e38838a85fc92531b3e56904b052 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055940" comment="mozilla-xulrunner190-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055941" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055942" comment="mozilla-xulrunner190-translations less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055943" comment="mozilla-xulrunner190-x86 less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055944" comment="mozilla-xulrunner190 less than 1.9.0.15-0.1.2"/>
		</criteria>
	</criteria>
	<!-- 49179a9289fbe778bc2320690c17d088 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055945" comment="MozillaFirefox-translations less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055946" comment="MozillaFirefox less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055947" comment="mozilla-xulrunner191-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055948" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055949" comment="mozilla-xulrunner191-translations less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055950" comment="mozilla-xulrunner191-x86 less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055951" comment="mozilla-xulrunner191 less than 1.9.1.4-2.1.3"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093373" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3373</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3373" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3373" source="CVE"/>
	<description>
	Heap-based buffer overflow in the GIF image parser in Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via unspecified vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04c6e38838a85fc92531b3e56904b052 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055940" comment="mozilla-xulrunner190-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055941" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055942" comment="mozilla-xulrunner190-translations less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055943" comment="mozilla-xulrunner190-x86 less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055944" comment="mozilla-xulrunner190 less than 1.9.0.15-0.1.2"/>
		</criteria>
	</criteria>
	<!-- 49179a9289fbe778bc2320690c17d088 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055945" comment="MozillaFirefox-translations less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055946" comment="MozillaFirefox less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055947" comment="mozilla-xulrunner191-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055948" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055949" comment="mozilla-xulrunner191-translations less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055950" comment="mozilla-xulrunner191-x86 less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055951" comment="mozilla-xulrunner191 less than 1.9.1.4-2.1.3"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093374" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3374</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3374" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3374" source="CVE"/>
	<description>
	The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04c6e38838a85fc92531b3e56904b052 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055940" comment="mozilla-xulrunner190-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055941" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055942" comment="mozilla-xulrunner190-translations less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055943" comment="mozilla-xulrunner190-x86 less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055944" comment="mozilla-xulrunner190 less than 1.9.0.15-0.1.2"/>
		</criteria>
	</criteria>
	<!-- 49179a9289fbe778bc2320690c17d088 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055945" comment="MozillaFirefox-translations less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055946" comment="MozillaFirefox less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055947" comment="mozilla-xulrunner191-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055948" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055949" comment="mozilla-xulrunner191-translations less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055950" comment="mozilla-xulrunner191-x86 less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055951" comment="mozilla-xulrunner191 less than 1.9.1.4-2.1.3"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093375" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3375</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3375" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3375" source="CVE"/>
	<description>
	content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allows user-assisted remote attackers to bypass the Same Origin Policy and read an arbitrary content selection via the document.getSelection function.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04c6e38838a85fc92531b3e56904b052 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055940" comment="mozilla-xulrunner190-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055941" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055942" comment="mozilla-xulrunner190-translations less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055943" comment="mozilla-xulrunner190-x86 less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055944" comment="mozilla-xulrunner190 less than 1.9.0.15-0.1.2"/>
		</criteria>
	</criteria>
	<!-- 49179a9289fbe778bc2320690c17d088 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055945" comment="MozillaFirefox-translations less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055946" comment="MozillaFirefox less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055947" comment="mozilla-xulrunner191-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055948" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055949" comment="mozilla-xulrunner191-translations less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055950" comment="mozilla-xulrunner191-x86 less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055951" comment="mozilla-xulrunner191 less than 1.9.1.4-2.1.3"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093376" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3376</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3376" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3376" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, does not properly handle a right-to-left override (aka RLO or U+202E) Unicode character in a download filename, which allows remote attackers to spoof file extensions via a crafted filename, as demonstrated by displaying a non-executable extension for an executable file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04c6e38838a85fc92531b3e56904b052 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055940" comment="mozilla-xulrunner190-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055941" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055942" comment="mozilla-xulrunner190-translations less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055943" comment="mozilla-xulrunner190-x86 less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055944" comment="mozilla-xulrunner190 less than 1.9.0.15-0.1.2"/>
		</criteria>
	</criteria>
	<!-- 49179a9289fbe778bc2320690c17d088 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055945" comment="MozillaFirefox-translations less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055946" comment="MozillaFirefox less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055947" comment="mozilla-xulrunner191-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055948" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055949" comment="mozilla-xulrunner191-translations less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055950" comment="mozilla-xulrunner191-x86 less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055951" comment="mozilla-xulrunner191 less than 1.9.1.4-2.1.3"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093377" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3377</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3377" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3377" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in liboggz before cf5feeaab69b05e24, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
<!-- 49179a9289fbe778bc2320690c17d088 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009055945" comment="MozillaFirefox-translations less than 3.5.4-1.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055946" comment="MozillaFirefox less than 3.5.4-1.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055947" comment="mozilla-xulrunner191-32bit less than 1.9.1.4-2.1.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055948" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.4-2.1.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055949" comment="mozilla-xulrunner191-translations less than 1.9.1.4-2.1.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055950" comment="mozilla-xulrunner191-x86 less than 1.9.1.4-2.1.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055951" comment="mozilla-xulrunner191 less than 1.9.1.4-2.1.3"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093378" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3378</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3378" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3378" source="CVE"/>
	<description>
	The oggplay_data_handle_theora_frame function in media/liboggplay/src/liboggplay/oggplay_data.c in liboggplay, as used in Mozilla Firefox 3.5.x before 3.5.4, attempts to reuse an earlier frame data structure upon encountering a decoding error for the first frame, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via a crafted .ogg video file.
	</description>
 </metadata>
<!-- 49179a9289fbe778bc2320690c17d088 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009055945" comment="MozillaFirefox-translations less than 3.5.4-1.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055946" comment="MozillaFirefox less than 3.5.4-1.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055947" comment="mozilla-xulrunner191-32bit less than 1.9.1.4-2.1.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055948" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.4-2.1.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055949" comment="mozilla-xulrunner191-translations less than 1.9.1.4-2.1.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055950" comment="mozilla-xulrunner191-x86 less than 1.9.1.4-2.1.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055951" comment="mozilla-xulrunner191 less than 1.9.1.4-2.1.3"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093379" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3379</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3379" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3379" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in libvorbis, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.  NOTE: this might overlap CVE-2009-2663.
	</description>
 </metadata>
<!-- 49179a9289fbe778bc2320690c17d088 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009055945" comment="MozillaFirefox-translations less than 3.5.4-1.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055946" comment="MozillaFirefox less than 3.5.4-1.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055947" comment="mozilla-xulrunner191-32bit less than 1.9.1.4-2.1.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055948" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.4-2.1.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055949" comment="mozilla-xulrunner191-translations less than 1.9.1.4-2.1.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055950" comment="mozilla-xulrunner191-x86 less than 1.9.1.4-2.1.3"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009055951" comment="mozilla-xulrunner191 less than 1.9.1.4-2.1.3"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093380" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3380</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3380" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3380" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04c6e38838a85fc92531b3e56904b052 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055940" comment="mozilla-xulrunner190-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055941" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055942" comment="mozilla-xulrunner190-translations less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055943" comment="mozilla-xulrunner190-x86 less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055944" comment="mozilla-xulrunner190 less than 1.9.0.15-0.1.2"/>
		</criteria>
	</criteria>
	<!-- 49179a9289fbe778bc2320690c17d088 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055945" comment="MozillaFirefox-translations less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055946" comment="MozillaFirefox less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055947" comment="mozilla-xulrunner191-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055948" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055949" comment="mozilla-xulrunner191-translations less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055950" comment="mozilla-xulrunner191-x86 less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055951" comment="mozilla-xulrunner191 less than 1.9.1.4-2.1.3"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093381" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3381</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3381" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3381" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04c6e38838a85fc92531b3e56904b052 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055940" comment="mozilla-xulrunner190-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055941" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055942" comment="mozilla-xulrunner190-translations less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055943" comment="mozilla-xulrunner190-x86 less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055944" comment="mozilla-xulrunner190 less than 1.9.0.15-0.1.2"/>
		</criteria>
	</criteria>
	<!-- 49179a9289fbe778bc2320690c17d088 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055945" comment="MozillaFirefox-translations less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055946" comment="MozillaFirefox less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055947" comment="mozilla-xulrunner191-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055948" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055949" comment="mozilla-xulrunner191-translations less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055950" comment="mozilla-xulrunner191-x86 less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055951" comment="mozilla-xulrunner191 less than 1.9.1.4-2.1.3"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093382" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3382</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3382" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3382" source="CVE"/>
	<description>
	layout/base/nsCSSFrameConstructor.cpp in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 does not properly handle first-letter frames, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04c6e38838a85fc92531b3e56904b052 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055940" comment="mozilla-xulrunner190-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055941" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055942" comment="mozilla-xulrunner190-translations less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055943" comment="mozilla-xulrunner190-x86 less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055944" comment="mozilla-xulrunner190 less than 1.9.0.15-0.1.2"/>
		</criteria>
	</criteria>
	<!-- 49179a9289fbe778bc2320690c17d088 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055945" comment="MozillaFirefox-translations less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055946" comment="MozillaFirefox less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055947" comment="mozilla-xulrunner191-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055948" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055949" comment="mozilla-xulrunner191-translations less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055950" comment="mozilla-xulrunner191-x86 less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055951" comment="mozilla-xulrunner191 less than 1.9.1.4-2.1.3"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093383" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3383</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3383" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3383" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 04c6e38838a85fc92531b3e56904b052 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055940" comment="mozilla-xulrunner190-32bit less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055941" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055942" comment="mozilla-xulrunner190-translations less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055943" comment="mozilla-xulrunner190-x86 less than 1.9.0.15-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055944" comment="mozilla-xulrunner190 less than 1.9.0.15-0.1.2"/>
		</criteria>
	</criteria>
	<!-- 49179a9289fbe778bc2320690c17d088 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009055945" comment="MozillaFirefox-translations less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055946" comment="MozillaFirefox less than 3.5.4-1.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055947" comment="mozilla-xulrunner191-32bit less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055948" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055949" comment="mozilla-xulrunner191-translations less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055950" comment="mozilla-xulrunner191-x86 less than 1.9.1.4-2.1.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009055951" comment="mozilla-xulrunner191 less than 1.9.1.4-2.1.3"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093388" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3388</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3388" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3388" source="CVE"/>
	<description>
	liboggplay in Mozilla Firefox 3.5.x before 3.5.6 and SeaMonkey before 2.0.1 might allow context-dependent attackers to cause a denial of service (application crash) or execute arbitrary code via unspecified vectors, related to "memory safety issues."
	</description>
 </metadata>
<!-- 5d919095d6df0dbca3e4ed34b00f367c -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056886" comment="MozillaFirefox-translations less than 3.5.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056887" comment="MozillaFirefox less than 3.5.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056888" comment="mozilla-xulrunner191-32bit less than 1.9.1.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056889" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056890" comment="mozilla-xulrunner191-translations less than 1.9.1.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056891" comment="mozilla-xulrunner191-x86 less than 1.9.1.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056892" comment="mozilla-xulrunner191 less than 1.9.1.6-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093389" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3389</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3389" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3389" source="CVE"/>
	<description>
	Integer overflow in libtheora in Xiph.Org Theora before 1.1, as used in Mozilla Firefox 3.5 before 3.5.6 and SeaMonkey before 2.0.1, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a video with large dimensions.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5d919095d6df0dbca3e4ed34b00f367c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056886" comment="MozillaFirefox-translations less than 3.5.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056887" comment="MozillaFirefox less than 3.5.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056888" comment="mozilla-xulrunner191-32bit less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056889" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056890" comment="mozilla-xulrunner191-translations less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056891" comment="mozilla-xulrunner191-x86 less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056892" comment="mozilla-xulrunner191 less than 1.9.1.6-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 8019505f916608385487352839f7512d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059264" comment="libtheora0-32bit less than 1.0.beta2-6.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059265" comment="libtheora0-x86 less than 1.0.beta2-6.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059266" comment="libtheora0 less than 1.0.beta2-6.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093525" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3525</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3525" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3525" source="CVE"/>
	<description>
	The pyGrub boot loader in Xen 3.0.3, 3.3.0, and Xen-3.3.1 does not support the password option in grub.conf for para-virtualized guests, which allows attackers with access to the para-virtualized guest console to boot the guest or modify the guest's kernel boot parameters without providing the expected password.
	</description>
 </metadata>
<!-- 12418b25d25b9d86798e8ea9fc6f68a8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060673" comment="libcmpiutil less than 0.5-15.16.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060674" comment="libvirt-cim less than 0.5.2-8.47.85"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060675" comment="libvirt-doc less than 0.4.6-14.60.16"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060676" comment="libvirt-python less than 0.4.6-14.60.16"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060677" comment="libvirt less than 0.4.6-14.60.16"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060678" comment="virt-manager less than 0.5.3-66.42.13"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060679" comment="virt-viewer less than 0.0.3-3.57.13"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060680" comment="vm-install less than 0.3.27-0.1.15"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060681" comment="xen-doc-html less than 3.3.1_18546_24-0.3.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060682" comment="xen-doc-pdf less than 3.3.1_18546_24-0.3.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060683" comment="xen-kmp-default less than 3.3.1_18546_24_2.6.27.45_0.3-0.3.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060684" comment="xen-kmp-pae less than 3.3.1_18546_24_2.6.27.45_0.3-0.3.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060685" comment="xen-libs less than 3.3.1_18546_24-0.3.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060686" comment="xen-tools-domU less than 3.3.1_18546_24-0.3.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060687" comment="xen-tools less than 3.3.1_18546_24-0.3.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060688" comment="xen less than 3.3.1_18546_24-0.3.7"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093546" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3546</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3546" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3546" source="CVE"/>
	<description>
	The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtained from third party information.
	</description>
 </metadata>
<!-- bfb263e4c75cfb6dca1c2ee69633f369 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009058031" comment="apache2-mod_php5 less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058032" comment="php5-bcmath less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058033" comment="php5-bz2 less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058034" comment="php5-calendar less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058035" comment="php5-ctype less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058036" comment="php5-curl less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058037" comment="php5-dba less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058038" comment="php5-dbase less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058039" comment="php5-dom less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058040" comment="php5-exif less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058041" comment="php5-fastcgi less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058042" comment="php5-ftp less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058043" comment="php5-gd less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058044" comment="php5-gettext less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058045" comment="php5-gmp less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058046" comment="php5-hash less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058047" comment="php5-iconv less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058048" comment="php5-json less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058049" comment="php5-ldap less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058050" comment="php5-mbstring less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058051" comment="php5-mcrypt less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058052" comment="php5-mysql less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058053" comment="php5-odbc less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058054" comment="php5-openssl less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058055" comment="php5-pcntl less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058056" comment="php5-pdo less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058057" comment="php5-pear less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058058" comment="php5-pgsql less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058059" comment="php5-pspell less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058060" comment="php5-shmop less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058061" comment="php5-snmp less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058062" comment="php5-soap less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058063" comment="php5-suhosin less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058064" comment="php5-sysvmsg less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058065" comment="php5-sysvsem less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058066" comment="php5-sysvshm less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058067" comment="php5-tokenizer less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058068" comment="php5-wddx less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058069" comment="php5-xmlreader less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058070" comment="php5-xmlrpc less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058071" comment="php5-xmlwriter less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058072" comment="php5-xsl less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058073" comment="php5-zip less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058074" comment="php5-zlib less than 5.2.6-50.24.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093547" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3547</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3547" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3547" source="CVE"/>
	<description>
	Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous pipe via a /proc/*/fd/ pathname.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 114b9cf953db7d4a1a91082495d33414 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056506" comment="ext4dev-kmp-xen less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056511" comment="kernel-xen-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056512" comment="kernel-xen less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- 9b6d121530adca742ba4b1a99075559a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056513" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056514" comment="kernel-kdump less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056515" comment="kernel-ppc64-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056516" comment="kernel-ppc64 less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- a3c4f0428e25dca1993e5018e76d6758 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056517" comment="ext4dev-kmp-pae less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056518" comment="ext4dev-kmp-vmi less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056506" comment="ext4dev-kmp-xen less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056519" comment="kernel-pae-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056520" comment="kernel-pae less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056521" comment="kernel-vmi-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056522" comment="kernel-vmi less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056511" comment="kernel-xen-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056512" comment="kernel-xen less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- dfdf7dd3f18b0b2cf8024eb5a30e51ba -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- faf6558ee52bc90aea4840dc79e5757f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056523" comment="kernel-default-man less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093549" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3549</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3549" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3549" source="CVE"/>
	<description>
	packet-paltalk.c in the Paltalk dissector in Wireshark 1.2.0 through 1.2.2, on SPARC and certain other platforms, allows remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace.
	</description>
 </metadata>
<!-- 21376954221689990a2fee3602c8189f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056792" comment="wireshark less than 1.0.5-1.31.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093550" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3550</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3550" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3550" source="CVE"/>
	<description>
	The DCERPC/NT dissector in Wireshark 0.10.10 through 1.0.9 and 1.2.0 through 1.2.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a file that records a malformed packet trace.  NOTE: some of these details are obtained from third party information.
	</description>
 </metadata>
<!-- 21376954221689990a2fee3602c8189f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056792" comment="wireshark less than 1.0.5-1.31.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093551" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3551</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3551" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3551" source="CVE"/>
	<description>
	Off-by-one error in the dissect_negprot_response function in packet-smb.c in the SMB dissector in Wireshark 1.2.0 through 1.2.2 allows remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace.  NOTE: some of these details are obtained from third party information.
	</description>
 </metadata>
<!-- 21376954221689990a2fee3602c8189f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056792" comment="wireshark less than 1.0.5-1.31.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093553" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3553</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3553" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3553" source="CVE"/>
	<description>
	Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS 1.3.7 and 1.3.10 allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, related to improperly maintaining a reference count.  NOTE: some of these details are obtained from third party information.
	</description>
 </metadata>
<!-- a3fa76d8e915d3f22a35726188aa910b -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009058941" comment="cups-client less than 1.3.9-8.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058942" comment="cups-libs-32bit less than 1.3.9-8.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058943" comment="cups-libs-x86 less than 1.3.9-8.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058944" comment="cups-libs less than 1.3.9-8.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058945" comment="cups less than 1.3.9-8.30.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093555" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3555</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Java 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2009-3555" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3555" source="CVE"/>
	<description>
	The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 270423861f1375425ccfee7b8dcce023 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009065190" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.6-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065191" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.6-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065192" comment="java-1_4_2-ibm less than 1.4.2_sr13.6-1.6.1"/>
		</criteria>
	</criteria>
	<!-- 6e2a4a18951fab782ad3726c24acc765 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060825" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.4-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060826" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.4-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060827" comment="java-1_4_2-ibm less than 1.4.2_sr13.4-1.6.1"/>
		</criteria>
	</criteria>
	<!-- 8ead451f2aa5a3390fe43fc3d4eff649 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059477" comment="mozilla-xulrunner190-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059478" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059479" comment="mozilla-xulrunner190-translations less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059480" comment="mozilla-xulrunner190-x86 less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059481" comment="mozilla-xulrunner190 less than 1.9.0.19-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 983e7a903db92e0d94f70e9a34c1d5cb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060825" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.4-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060826" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.4-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060827" comment="java-1_4_2-ibm less than 1.4.2_sr13.4-1.6.1"/>
		</criteria>
	</criteria>
	<!-- 99e3a681bfd3aa624a61230811cf88e5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009065622" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr9.0-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065623" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr9.0-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065624" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr9.0-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065625" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr9.0-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065626" comment="java-1_6_0-ibm less than 1.6.0_sr9.0-0.2.1"/>
		</criteria>
	</criteria>
	<!-- afa1b8679c41392c0a7c5bf73788d74b -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009065171" comment="gnutls less than 2.4.1-24.32.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065172" comment="libgnutls26-32bit less than 2.4.1-24.32.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065173" comment="libgnutls26-x86 less than 2.4.1-24.32.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065174" comment="libgnutls26 less than 2.4.1-24.32.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009065171" comment="gnutls less than 2.4.1-24.32.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065172" comment="libgnutls26-32bit less than 2.4.1-24.32.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065174" comment="libgnutls26 less than 2.4.1-24.32.1"/>
			</criteria>
		</criteria></criteria>
	<!-- d0129289ed5f99e99f64649fe9227069 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056248" comment="libopenssl0_9_8-32bit less than 0.9.8h-30.15.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056249" comment="libopenssl0_9_8-x86 less than 0.9.8h-30.15.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056250" comment="libopenssl0_9_8 less than 0.9.8h-30.15.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056251" comment="openssl-doc less than 0.9.8h-30.15.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056252" comment="openssl less than 0.9.8h-30.15.1"/>
		</criteria>
	</criteria>
	<!-- e687f5d3988822ee23e0bd97566703f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059482" comment="MozillaFirefox-translations less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059483" comment="MozillaFirefox less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059484" comment="mozilla-xulrunner191-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059485" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059486" comment="mozilla-xulrunner191-translations less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059487" comment="mozilla-xulrunner191-x86 less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059488" comment="mozilla-xulrunner191 less than 1.9.1.9-1.1.1"/>
		</criteria>
	</criteria>
	<!-- ed55e89901ea18fdd2a60bdd8a878403 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059415" comment="libfreebl3-32bit less than 3.12.6-3.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059416" comment="libfreebl3-x86 less than 3.12.6-3.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059417" comment="libfreebl3 less than 3.12.6-3.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059418" comment="mozilla-nss-32bit less than 3.12.6-3.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059419" comment="mozilla-nss-tools less than 3.12.6-3.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059420" comment="mozilla-nss-x86 less than 3.12.6-3.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059421" comment="mozilla-nss less than 3.12.6-3.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059422" comment="zlib-32bit less than 1.2.3-106.34"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059423" comment="zlib-x86 less than 1.2.3-106.34"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059424" comment="zlib less than 1.2.3-106.34"/>
		</criteria>
	</criteria>
	<!-- f0725ef2d5a4faab266acd72f09fb8ac -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009065171" comment="gnutls less than 2.4.1-24.32.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065172" comment="libgnutls26-32bit less than 2.4.1-24.32.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065173" comment="libgnutls26-x86 less than 2.4.1-24.32.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065174" comment="libgnutls26 less than 2.4.1-24.32.1"/>
		</criteria>
	</criteria>
	<!-- fba66235e940d7d2f4064d7e1e803b60 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059248" comment="libopenssl0_9_8-32bit less than 0.9.8h-30.22.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059249" comment="libopenssl0_9_8-x86 less than 0.9.8h-30.22.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059250" comment="libopenssl0_9_8 less than 0.9.8h-30.22.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059251" comment="openssl-doc less than 0.9.8h-30.22.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059252" comment="openssl less than 0.9.8h-30.22.21.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093560" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3560</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3560" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3560" source="CVE"/>
	<description>
	The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with malformed UTF-8 sequences that trigger a buffer over-read, related to the doProlog function in lib/xmlparse.c, a different vulnerability than CVE-2009-2625 and CVE-2009-3720.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 84cc1e78a5b951cb599ebd0537f0c213 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056872" comment="pyxml less than 0.8.4-194.19.1"/>
	</criteria>
	<!-- cc3e3bda8217aa28262b6982edd9bee5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060325" comment="libpython2_6-1_0-32bit less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060326" comment="libpython2_6-1_0-x86 less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060327" comment="libpython2_6-1_0 less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060328" comment="python-32bit less than 2.6.0-8.9.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060329" comment="python-base-32bit less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060330" comment="python-base-x86 less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060331" comment="python-base less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060332" comment="python-curses less than 2.6.0-8.9.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060333" comment="python-demo less than 2.6.0-8.9.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060334" comment="python-gdbm less than 2.6.0-8.9.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060335" comment="python-idle less than 2.6.0-8.9.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060336" comment="python-tk less than 2.6.0-8.9.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060337" comment="python-x86 less than 2.6.0-8.9.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060338" comment="python-xml less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060339" comment="python less than 2.6.0-8.9.1.1"/>
		</criteria>
	</criteria>
	<!-- df7fac6ab40235408e8ea35318a13920 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056827" comment="expat less than 2.0.1-88.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056828" comment="libexpat1-32bit less than 2.0.1-88.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056829" comment="libexpat1-x86 less than 2.0.1-88.23.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056830" comment="libexpat1 less than 2.0.1-88.23.1"/>
		</criteria>
	</criteria>
	<!-- fd770268071e50829313d8b6d3bc05c8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057200" comment="expat less than 2.0.1-88.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057201" comment="libexpat1-32bit less than 2.0.1-88.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057202" comment="libexpat1-x86 less than 2.0.1-88.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057203" comment="libexpat1 less than 2.0.1-88.26.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093563" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3563</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3563" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3563" source="CVE"/>
	<description>
	ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by using MODE_PRIVATE to send a spoofed (1) request or (2) response packet that triggers a continuous exchange of MODE_PRIVATE error responses between two NTP daemons.
	</description>
 </metadata>
<!-- 56ca97c7cac4e3de1757053bc75f217f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009057189" comment="ntp-doc less than 4.2.4p6-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057190" comment="ntp less than 4.2.4p6-1.18.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093607" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3607</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3607" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3607" source="CVE"/>
	<description>
	Integer overflow in the create_surface_from_thumbnail_data function in glib/poppler-page.cc in Poppler 0.x allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.  NOTE: some of these details are obtained from third party information.
	</description>
 </metadata>
<!-- bde2b755a6dc83d88dd11394793d4482 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009057042" comment="libpoppler-glib4 less than 0.10.1-1.31.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057043" comment="libpoppler-qt4-3 less than 0.10.1-1.31.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057044" comment="libpoppler4 less than 0.10.1-1.31.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057045" comment="poppler-tools less than 0.10.1-1.31.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093608" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3608</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3608" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3608" source="CVE"/>
	<description>
	Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and teTeX, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.
	</description>
 </metadata>
<!-- bde2b755a6dc83d88dd11394793d4482 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009057042" comment="libpoppler-glib4 less than 0.10.1-1.31.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057043" comment="libpoppler-qt4-3 less than 0.10.1-1.31.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057044" comment="libpoppler4 less than 0.10.1-1.31.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057045" comment="poppler-tools less than 0.10.1-1.31.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093612" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3612</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3612" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3612" source="CVE"/>
	<description>
	The tcf_fill_node function in net/sched/cls_api.c in the netlink subsystem in the Linux kernel 2.6.x before 2.6.32-rc5, and 2.4.37.6 and earlier, does not initialize a certain tcm__pad2 structure member, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors.  NOTE: this issue exists because of an incomplete fix for CVE-2005-4881.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 114b9cf953db7d4a1a91082495d33414 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056506" comment="ext4dev-kmp-xen less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056511" comment="kernel-xen-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056512" comment="kernel-xen less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- 9b6d121530adca742ba4b1a99075559a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056513" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056514" comment="kernel-kdump less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056515" comment="kernel-ppc64-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056516" comment="kernel-ppc64 less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- a3c4f0428e25dca1993e5018e76d6758 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056517" comment="ext4dev-kmp-pae less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056518" comment="ext4dev-kmp-vmi less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056506" comment="ext4dev-kmp-xen less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056519" comment="kernel-pae-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056520" comment="kernel-pae less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056521" comment="kernel-vmi-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056522" comment="kernel-vmi less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056511" comment="kernel-xen-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056512" comment="kernel-xen less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- dfdf7dd3f18b0b2cf8024eb5a30e51ba -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- faf6558ee52bc90aea4840dc79e5757f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056523" comment="kernel-default-man less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093615" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3615</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3615" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3615" source="CVE"/>
	<description>
	The OSCAR protocol plugin in libpurple in Pidgin before 2.6.3 and Adium before 1.3.7 allows remote attackers to cause a denial of service (application crash) via crafted contact-list data for (1) ICQ and possibly (2) AIM, as demonstrated by the SIM IM client.
	</description>
 </metadata>
<!-- 036b34b556d9338c53561c16d2f5a3ce -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056524" comment="cdparanoia-32bit less than IIIalpha9.8-691.22"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056525" comment="cdparanoia-x86 less than IIIalpha9.8-691.22"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056526" comment="cdparanoia less than IIIalpha9.8-691.22"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056527" comment="desktop-file-utils less than 0.15-1.29"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056528" comment="fam-32bit less than 2.7.0-130.21"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056529" comment="fam-x86 less than 2.7.0-130.21"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056530" comment="fam less than 2.7.0-130.21"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056531" comment="gnome-vfs2-32bit less than 2.24.0-7.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056532" comment="gnome-vfs2-x86 less than 2.24.0-7.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056533" comment="gnome-vfs2 less than 2.24.0-7.4"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056534" comment="gstreamer-0_10 less than 0.10.21-3.20"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056535" comment="libogg0-32bit less than 1.1.3-87.12"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056536" comment="libogg0-x86 less than 1.1.3-87.12"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056537" comment="libogg0 less than 1.1.3-87.12"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056538" comment="liboil-32bit less than 0.3.15-3.10"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056539" comment="liboil-x86 less than 0.3.15-3.10"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056540" comment="liboil less than 0.3.15-3.10"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056541" comment="libtheora0-32bit less than 1.0.beta2-4.28"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056542" comment="libtheora0-x86 less than 1.0.beta2-4.28"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056543" comment="libtheora0 less than 1.0.beta2-4.28"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093616" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3616</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3616" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3616" source="CVE"/>
	<description>
	Multiple use-after-free vulnerabilities in vnc.c in the VNC server in QEMU 0.10.6 and earlier might allow guest OS users to execute arbitrary code on the host OS by establishing a connection from a VNC client and then (1) disconnecting during data transfer, (2) sending a message using incorrect integer data types, or (3) using the Fuzzy Screen Mode protocol, related to double free vulnerabilities.
	</description>
 </metadata>
<!-- f4e5016874884c9afd74eae568a826e1 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056324" comment="kvm-kmp-default less than 78.2.6.30.1_2.6.27.37_0.1-0.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056325" comment="kvm-kmp-pae less than 78.2.6.30.1_2.6.27.37_0.1-0.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056326" comment="kvm less than 78.0.10.6-0.3.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093620" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3620</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3620" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3620" source="CVE"/>
	<description>
	The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE) state initialization, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly gain privileges via unspecified ioctl calls.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 114b9cf953db7d4a1a91082495d33414 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056506" comment="ext4dev-kmp-xen less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056511" comment="kernel-xen-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056512" comment="kernel-xen less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- 9b6d121530adca742ba4b1a99075559a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056513" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056514" comment="kernel-kdump less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056515" comment="kernel-ppc64-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056516" comment="kernel-ppc64 less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- a3c4f0428e25dca1993e5018e76d6758 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056517" comment="ext4dev-kmp-pae less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056518" comment="ext4dev-kmp-vmi less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056506" comment="ext4dev-kmp-xen less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056519" comment="kernel-pae-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056520" comment="kernel-pae less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056521" comment="kernel-vmi-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056522" comment="kernel-vmi less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056511" comment="kernel-xen-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056512" comment="kernel-xen less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- dfdf7dd3f18b0b2cf8024eb5a30e51ba -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- faf6558ee52bc90aea4840dc79e5757f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056523" comment="kernel-default-man less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093621" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3621</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3621" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3621" source="CVE"/>
	<description>
	net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang) by creating an abstract-namespace AF_UNIX listening socket, performing a shutdown operation on this socket, and then performing a series of connect operations to this socket.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 114b9cf953db7d4a1a91082495d33414 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056506" comment="ext4dev-kmp-xen less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056511" comment="kernel-xen-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056512" comment="kernel-xen less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- 9b6d121530adca742ba4b1a99075559a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056513" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056514" comment="kernel-kdump less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056515" comment="kernel-ppc64-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056516" comment="kernel-ppc64 less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- a3c4f0428e25dca1993e5018e76d6758 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056517" comment="ext4dev-kmp-pae less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056518" comment="ext4dev-kmp-vmi less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056506" comment="ext4dev-kmp-xen less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056519" comment="kernel-pae-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056520" comment="kernel-pae less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056521" comment="kernel-vmi-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056522" comment="kernel-vmi less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056511" comment="kernel-xen-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056512" comment="kernel-xen less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- dfdf7dd3f18b0b2cf8024eb5a30e51ba -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- faf6558ee52bc90aea4840dc79e5757f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056523" comment="kernel-default-man less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093627" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3627</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3627" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3627" source="CVE"/>
	<description>
	The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service (infinite loop) via an incomplete SGML numeric character reference, which triggers generation of an invalid UTF-8 character.
	</description>
 </metadata>
<!-- 58f42631ae5a6c4bdfd6fb69a2114c32 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056793" comment="perl-HTML-Parser less than 3.56-1.18.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093638" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3638</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3638" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3638" source="CVE"/>
	<description>
	Integer overflow in the kvm_dev_ioctl_get_supported_cpuid function in arch/x86/kvm/x86.c in the KVM subsystem in the Linux kernel before 2.6.31.4 allows local users to have an unspecified impact via a KVM_GET_SUPPORTED_CPUID request to the kvm_arch_dev_ioctl function.
	</description>
 </metadata>
<!-- f4e5016874884c9afd74eae568a826e1 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056324" comment="kvm-kmp-default less than 78.2.6.30.1_2.6.27.37_0.1-0.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056325" comment="kvm-kmp-pae less than 78.2.6.30.1_2.6.27.37_0.1-0.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056326" comment="kvm less than 78.0.10.6-0.3.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093640" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3640</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3640" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3640" source="CVE"/>
	<description>
	The update_cr8_intercept function in arch/x86/kvm/x86.c in the KVM subsystem in the Linux kernel before 2.6.32-rc1 does not properly handle the absence of an Advanced Programmable Interrupt Controller (APIC), which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly gain privileges via a call to the kvm_vcpu_ioctl function.
	</description>
 </metadata>
<!-- f4e5016874884c9afd74eae568a826e1 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056324" comment="kvm-kmp-default less than 78.2.6.30.1_2.6.27.37_0.1-0.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056325" comment="kvm-kmp-pae less than 78.2.6.30.1_2.6.27.37_0.1-0.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056326" comment="kvm less than 78.0.10.6-0.3.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093720" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3720</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3720" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3720" source="CVE"/>
	<description>
	The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 84cc1e78a5b951cb599ebd0537f0c213 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056872" comment="pyxml less than 0.8.4-194.19.1"/>
	</criteria>
	<!-- 9920a6312eee8fe0580ddf07cc011eb9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056327" comment="expat less than 2.0.1-88.22.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056328" comment="libexpat1-32bit less than 2.0.1-88.22.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056329" comment="libexpat1-x86 less than 2.0.1-88.22.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056330" comment="libexpat1 less than 2.0.1-88.22.1"/>
		</criteria>
	</criteria>
	<!-- cc3e3bda8217aa28262b6982edd9bee5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060325" comment="libpython2_6-1_0-32bit less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060326" comment="libpython2_6-1_0-x86 less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060327" comment="libpython2_6-1_0 less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060328" comment="python-32bit less than 2.6.0-8.9.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060329" comment="python-base-32bit less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060330" comment="python-base-x86 less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060331" comment="python-base less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060332" comment="python-curses less than 2.6.0-8.9.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060333" comment="python-demo less than 2.6.0-8.9.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060334" comment="python-gdbm less than 2.6.0-8.9.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060335" comment="python-idle less than 2.6.0-8.9.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060336" comment="python-tk less than 2.6.0-8.9.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060337" comment="python-x86 less than 2.6.0-8.9.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060338" comment="python-xml less than 2.6.0-8.8.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060339" comment="python less than 2.6.0-8.9.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093726" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3726</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3726" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3726" source="CVE"/>
	<description>
	The nfs4_proc_lock function in fs/nfs/nfs4proc.c in the NFSv4 client in the Linux kernel before 2.6.31-rc4 allows remote NFS servers to cause a denial of service (NULL pointer dereference and panic) by sending a certain response containing incorrect file attributes, which trigger attempted use of an open file that lacks NFSv4 state.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 114b9cf953db7d4a1a91082495d33414 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056506" comment="ext4dev-kmp-xen less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056511" comment="kernel-xen-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056512" comment="kernel-xen less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- 9b6d121530adca742ba4b1a99075559a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056513" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056514" comment="kernel-kdump less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056515" comment="kernel-ppc64-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056516" comment="kernel-ppc64 less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- a3c4f0428e25dca1993e5018e76d6758 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056517" comment="ext4dev-kmp-pae less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056518" comment="ext4dev-kmp-vmi less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056506" comment="ext4dev-kmp-xen less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056519" comment="kernel-pae-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056520" comment="kernel-pae less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056521" comment="kernel-vmi-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056522" comment="kernel-vmi less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056511" comment="kernel-xen-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056512" comment="kernel-xen less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- dfdf7dd3f18b0b2cf8024eb5a30e51ba -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
	<!-- faf6558ee52bc90aea4840dc79e5757f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056505" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.22"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056507" comment="kernel-default-base less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056523" comment="kernel-default-man less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056508" comment="kernel-default less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056509" comment="kernel-source less than 2.6.27.39-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056510" comment="kernel-syms less than 2.6.27.39-0.3.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093736" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3736</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3736" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3736" source="CVE"/>
	<description>
	ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, which allows local users to gain privileges via a Trojan horse file.
	</description>
 </metadata>
<!-- 47556f0ada22d5f48c6e9e760e265eda -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009057089" comment="libltdl7-32bit less than 2.2.6-2.131.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057090" comment="libltdl7-x86 less than 2.2.6-2.131.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057091" comment="libltdl7 less than 2.2.6-2.131.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057092" comment="libtool-32bit less than 2.2.6-2.131.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057093" comment="libtool-x86 less than 2.2.6-2.131.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057094" comment="libtool less than 2.2.6-2.131.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093743" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3743</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for Teradata</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
		<platform>SUSE Linux Enterprise Server 11 SP2</platform>
	</affected>
	<reference ref_id="CVE-2009-3743" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3743" source="CVE"/>
	<description>
	Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript before 8.71 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a malformed TrueType font in a document that trigger an integer overflow and a heap-based buffer overflow.
	</description>
 </metadata>
<!-- d32438d017a666c248f87a90698dda0a -->
<criteria operator="AND">
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009073673" comment="sles11-sp1_for_sp2 is installed"/>
	</criteria>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009073459" comment="ghostscript-fonts-other less than 8.62-32.32.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009073460" comment="ghostscript-fonts-rus less than 8.62-32.32.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009073461" comment="ghostscript-fonts-std less than 8.62-32.32.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009073462" comment="ghostscript-library less than 8.62-32.32.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009073463" comment="ghostscript-omni less than 8.62-32.32.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009073464" comment="ghostscript-x11 less than 8.62-32.32.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009073465" comment="libgimpprint less than 4.2.7-32.32.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093829" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3829</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3829" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3829" source="CVE"/>
	<description>
	Integer overflow in wiretap/erf.c in Wireshark before 1.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted erf file, related to an "unsigned integer wrap vulnerability."
	</description>
 </metadata>
<!-- 21376954221689990a2fee3602c8189f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056792" comment="wireshark less than 1.0.5-1.31.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093865" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3865</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3865" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3865" source="CVE"/>
	<description>
	The launch method in the Deployment Toolkit plugin in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 6 before Update 17 allows remote attackers to execute arbitrary commands via a crafted web page, aka Bug Id 6869752.
	</description>
 </metadata>
<!-- 39e43680df27683c7e496d57e45f7060 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009057184" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr7.0-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057185" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr7.0-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057186" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr7.0-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057187" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr7.0-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057188" comment="java-1_6_0-ibm less than 1.6.0_sr7.0-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093866" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3866</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3866" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3866" source="CVE"/>
	<description>
	The Java Web Start Installer in Sun Java SE in JDK and JRE 6 before Update 17 does not properly use security model permissions when removing installer extensions, which allows remote attackers to execute arbitrary code by modifying a certain JNLP file to have a URL field that points to an unintended trusted application, aka Bug Id 6872824.
	</description>
 </metadata>
<!-- 39e43680df27683c7e496d57e45f7060 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009057184" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr7.0-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057185" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr7.0-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057186" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr7.0-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057187" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr7.0-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057188" comment="java-1_6_0-ibm less than 1.6.0_sr7.0-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093867" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3867</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3867" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3867" source="CVE"/>
	<description>
	Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a long file: URL in an argument, aka Bug Id 6854303.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 290c77bc3a064e0fbc5d2853627df587 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057169" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057170" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057171" comment="java-1_4_2-ibm less than 1.4.2_sr13.3-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 39e43680df27683c7e496d57e45f7060 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057184" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057185" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057186" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057187" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057188" comment="java-1_6_0-ibm less than 1.6.0_sr7.0-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093868" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3868</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3868" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3868" source="CVE"/>
	<description>
	Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 does not properly parse color profiles, which allows remote attackers to gain privileges via a crafted image file, aka Bug Id 6862970.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 078e3d197ce1488682c8fe5574f20e9b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056369" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056370" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056371" comment="java-1_4_2-ibm less than 1.4.2_sr13.2-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 39e43680df27683c7e496d57e45f7060 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057184" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057185" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057186" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057187" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057188" comment="java-1_6_0-ibm less than 1.6.0_sr7.0-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093869" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3869</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3869" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3869" source="CVE"/>
	<description>
	Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a crafted argument, aka Bug Id 6872357.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 290c77bc3a064e0fbc5d2853627df587 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057169" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057170" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057171" comment="java-1_4_2-ibm less than 1.4.2_sr13.3-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 39e43680df27683c7e496d57e45f7060 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057184" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057185" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057186" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057187" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057188" comment="java-1_6_0-ibm less than 1.6.0_sr7.0-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093871" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3871</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3871" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3871" source="CVE"/>
	<description>
	Heap-based buffer overflow in the setBytePixels function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via crafted arguments, aka Bug Id 6872358.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 290c77bc3a064e0fbc5d2853627df587 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057169" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057170" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057171" comment="java-1_4_2-ibm less than 1.4.2_sr13.3-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 39e43680df27683c7e496d57e45f7060 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057184" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057185" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057186" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057187" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057188" comment="java-1_6_0-ibm less than 1.6.0_sr7.0-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093872" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3872</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3872" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3872" source="CVE"/>
	<description>
	Unspecified vulnerability in the JPEG JFIF Decoder in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, aka Bug Id 6862969.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 078e3d197ce1488682c8fe5574f20e9b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056369" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056370" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056371" comment="java-1_4_2-ibm less than 1.4.2_sr13.2-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 39e43680df27683c7e496d57e45f7060 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057184" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057185" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057186" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057187" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057188" comment="java-1_6_0-ibm less than 1.6.0_sr7.0-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093873" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3873</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3873" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3873" source="CVE"/>
	<description>
	The JPEG Image Writer in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, related to a "quantization problem," aka Bug Id 6862968.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 078e3d197ce1488682c8fe5574f20e9b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056369" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056370" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056371" comment="java-1_4_2-ibm less than 1.4.2_sr13.2-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 39e43680df27683c7e496d57e45f7060 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057184" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057185" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057186" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057187" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057188" comment="java-1_6_0-ibm less than 1.6.0_sr7.0-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093874" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3874</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3874" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3874" source="CVE"/>
	<description>
	Integer overflow in the JPEGImageReader implementation in the ImageI/O component in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via large subsample dimensions in a JPEG file that triggers a heap-based buffer overflow, aka Bug Id 6874643.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 290c77bc3a064e0fbc5d2853627df587 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057169" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057170" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057171" comment="java-1_4_2-ibm less than 1.4.2_sr13.3-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 39e43680df27683c7e496d57e45f7060 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057184" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057185" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057186" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057187" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057188" comment="java-1_6_0-ibm less than 1.6.0_sr7.0-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093875" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3875</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3875" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3875" source="CVE"/>
	<description>
	The MessageDigest.isEqual function in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to spoof HMAC-based digital signatures, and possibly bypass authentication, via unspecified vectors related to "timing attack vulnerabilities," aka Bug Id 6863503.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 290c77bc3a064e0fbc5d2853627df587 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057169" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057170" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.3-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057171" comment="java-1_4_2-ibm less than 1.4.2_sr13.3-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 39e43680df27683c7e496d57e45f7060 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057184" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057185" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057186" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057187" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057188" comment="java-1_6_0-ibm less than 1.6.0_sr7.0-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093876" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3876</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3876" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3876" source="CVE"/>
	<description>
	Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to cause a denial of service (memory consumption) via crafted DER encoded data, which is not properly decoded by the ASN.1 DER input stream parser, aka Bug Id 6864911.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 078e3d197ce1488682c8fe5574f20e9b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056369" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056370" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056371" comment="java-1_4_2-ibm less than 1.4.2_sr13.2-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 39e43680df27683c7e496d57e45f7060 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057184" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057185" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057186" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057187" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057188" comment="java-1_6_0-ibm less than 1.6.0_sr7.0-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093877" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3877</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3877" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3877" source="CVE"/>
	<description>
	Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to cause a denial of service (memory consumption) via crafted HTTP headers, which are not properly parsed by the ASN.1 DER input stream parser, aka Bug Id 6864911.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 078e3d197ce1488682c8fe5574f20e9b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056369" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056370" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.2-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056371" comment="java-1_4_2-ibm less than 1.4.2_sr13.2-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 39e43680df27683c7e496d57e45f7060 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057184" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057185" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057186" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057187" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr7.0-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057188" comment="java-1_6_0-ibm less than 1.6.0_sr7.0-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093938" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3938</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3938" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3938" source="CVE"/>
	<description>
	Buffer overflow in the ABWOutputDev::endWord function in poppler/ABWOutputDev.cc in Poppler (aka libpoppler) 0.10.6, 0.12.0, and possibly other versions, as used by the Abiword pdftoabw utility, allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted PDF file.
	</description>
 </metadata>
<!-- bde2b755a6dc83d88dd11394793d4482 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009057042" comment="libpoppler-glib4 less than 0.10.1-1.31.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057043" comment="libpoppler-qt4-3 less than 0.10.1-1.31.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057044" comment="libpoppler4 less than 0.10.1-1.31.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057045" comment="poppler-tools less than 0.10.1-1.31.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093939" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3939</title>
	<affected family="unix">
		<platform>SLE 11 SERVER Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3939" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3939" source="CVE"/>
	<description>
	The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1cc9f9878be828ca9494ad136beab1d1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 4971d1bc45dfe19245872ca92e7fe051 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057255" comment="kernel-default-extra less than 2.6.27.39-0.3.2"/>
	</criteria>
	<!-- 51cdeaf4505dbc37870fece945793189 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057255" comment="kernel-default-extra less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057256" comment="kernel-ppc64-extra less than 2.6.27.39-0.3.2"/>
		</criteria>
	</criteria>
	<!-- 5bc8b282021bec5a0602dd1e1fb86cc0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058496" comment="ext4dev-kmp-xen less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 5ecbc30d0c137f9f7ce500a198dee54a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057257" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057258" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.39_0.3-7.1.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057259" comment="kernel-default-base less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057260" comment="kernel-default less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057261" comment="kernel-kdump less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057262" comment="kernel-ppc64-base less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057263" comment="kernel-ppc64 less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057264" comment="kernel-source less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057265" comment="kernel-syms less than 2.6.27.39-0.3.2"/>
		</criteria>
	</criteria>
	<!-- 8de370e0ec03088da9aa16f31064b5c4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058499" comment="ext4dev-kmp-pae less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058500" comment="ext4dev-kmp-vmi less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058496" comment="ext4dev-kmp-xen less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058501" comment="kernel-pae-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058502" comment="kernel-pae less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058503" comment="kernel-vmi-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058504" comment="kernel-vmi less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 9a0454a0e15d8a3d7e1869913ff2b725 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057233" comment="kernel-xen-extra less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- b6015de562091b64634bc48dd8f9db1a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058505" comment="kernel-default-man less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- c9825ea9eb0265fbaf58b4e7f15828d7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
	</criteria>
	<!-- d4c3d61ff4cb77f117d3acbc6602aaeb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057220" comment="kernel-pae-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057233" comment="kernel-xen-extra less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e5c7588310814dc753e7fc885f8955fb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058506" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058507" comment="kernel-kdump less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058508" comment="kernel-ppc64-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058509" comment="kernel-ppc64 less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e7c5f7ef7eeb152d788f9406d2374894 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059470" comment="ext4dev-kmp-default less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059471" comment="ext4dev-kmp-pae less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059472" comment="ext4dev-kmp-vmi less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059473" comment="ext4dev-kmp-xen less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057219" comment="kernel-pae-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057221" comment="kernel-pae less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059474" comment="kernel-vmi-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059475" comment="kernel-vmi less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057232" comment="kernel-xen-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057234" comment="kernel-xen less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e87c441668f87fa162f810ea0e06c3ba -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059470" comment="ext4dev-kmp-default less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059473" comment="ext4dev-kmp-xen less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057232" comment="kernel-xen-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057234" comment="kernel-xen less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- ef72143c4837b653dc18408ca8832f96 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057257" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057259" comment="kernel-default-base less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057260" comment="kernel-default less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057264" comment="kernel-source less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057265" comment="kernel-syms less than 2.6.27.39-0.3.2"/>
		</criteria>
	</criteria>
	<!-- f5e83f559ce7469c64852e5d2a3cc38d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059470" comment="ext4dev-kmp-default less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059476" comment="kernel-default-man less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093978" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3978</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3978" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3978" source="CVE"/>
	<description>
	The nsGIFDecoder2::GifWrite function in decoders/gif/nsGIFDecoder2.cpp in libpr0n in Mozilla Firefox before 3.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an animated GIF file with a large image size, a different vulnerability than CVE-2009-3373.
	</description>
 </metadata>
<!-- a8ef456fbe2f7e3278460baef881cddc -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056346" comment="MozillaFirefox-translations less than 3.5.5-1.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056347" comment="MozillaFirefox less than 3.5.5-1.1.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056348" comment="mozilla-xulrunner191-32bit less than 1.9.1.5-1.3.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056349" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.5-1.3.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056350" comment="mozilla-xulrunner191-translations less than 1.9.1.5-1.3.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056351" comment="mozilla-xulrunner191-x86 less than 1.9.1.5-1.3.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056352" comment="mozilla-xulrunner191 less than 1.9.1.5-1.3.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093979" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3979</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3979" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3979" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5d919095d6df0dbca3e4ed34b00f367c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056886" comment="MozillaFirefox-translations less than 3.5.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056887" comment="MozillaFirefox less than 3.5.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056888" comment="mozilla-xulrunner191-32bit less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056889" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056890" comment="mozilla-xulrunner191-translations less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056891" comment="mozilla-xulrunner191-x86 less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056892" comment="mozilla-xulrunner191 less than 1.9.1.6-1.1.1"/>
		</criteria>
	</criteria>
	<!-- f95e0523ee35275bfe5a5ff2cd4fe04f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056893" comment="mozilla-xulrunner190-32bit less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056894" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056895" comment="mozilla-xulrunner190-translations less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056896" comment="mozilla-xulrunner190-x86 less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056897" comment="mozilla-xulrunner190 less than 1.9.0.16-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093980" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3980</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3980" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3980" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
<!-- 5d919095d6df0dbca3e4ed34b00f367c -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056886" comment="MozillaFirefox-translations less than 3.5.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056887" comment="MozillaFirefox less than 3.5.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056888" comment="mozilla-xulrunner191-32bit less than 1.9.1.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056889" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056890" comment="mozilla-xulrunner191-translations less than 1.9.1.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056891" comment="mozilla-xulrunner191-x86 less than 1.9.1.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056892" comment="mozilla-xulrunner191 less than 1.9.1.6-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093981" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3981</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3981" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3981" source="CVE"/>
	<description>
	Unspecified vulnerability in the browser engine in Mozilla Firefox before 3.0.16, SeaMonkey before 2.0.1, and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
<!-- f95e0523ee35275bfe5a5ff2cd4fe04f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056893" comment="mozilla-xulrunner190-32bit less than 1.9.0.16-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056894" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.16-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056895" comment="mozilla-xulrunner190-translations less than 1.9.0.16-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056896" comment="mozilla-xulrunner190-x86 less than 1.9.0.16-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056897" comment="mozilla-xulrunner190 less than 1.9.0.16-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093982" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3982</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3982" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3982" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
<!-- 5d919095d6df0dbca3e4ed34b00f367c -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009056886" comment="MozillaFirefox-translations less than 3.5.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056887" comment="MozillaFirefox less than 3.5.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056888" comment="mozilla-xulrunner191-32bit less than 1.9.1.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056889" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056890" comment="mozilla-xulrunner191-translations less than 1.9.1.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056891" comment="mozilla-xulrunner191-x86 less than 1.9.1.6-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009056892" comment="mozilla-xulrunner191 less than 1.9.1.6-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093983" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3983</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3983" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3983" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to send authenticated requests to arbitrary applications by replaying the NTLM credentials of a browser user.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5d919095d6df0dbca3e4ed34b00f367c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056886" comment="MozillaFirefox-translations less than 3.5.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056887" comment="MozillaFirefox less than 3.5.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056888" comment="mozilla-xulrunner191-32bit less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056889" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056890" comment="mozilla-xulrunner191-translations less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056891" comment="mozilla-xulrunner191-x86 less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056892" comment="mozilla-xulrunner191 less than 1.9.1.6-1.1.1"/>
		</criteria>
	</criteria>
	<!-- f95e0523ee35275bfe5a5ff2cd4fe04f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056893" comment="mozilla-xulrunner190-32bit less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056894" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056895" comment="mozilla-xulrunner190-translations less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056896" comment="mozilla-xulrunner190-x86 less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056897" comment="mozilla-xulrunner190 less than 1.9.0.16-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093984" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3984</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3984" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3984" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to spoof an SSL indicator for an http URL or a file URL by setting document.location to an https URL corresponding to a site that responds with a No Content (aka 204) status code and an empty body.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5d919095d6df0dbca3e4ed34b00f367c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056886" comment="MozillaFirefox-translations less than 3.5.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056887" comment="MozillaFirefox less than 3.5.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056888" comment="mozilla-xulrunner191-32bit less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056889" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056890" comment="mozilla-xulrunner191-translations less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056891" comment="mozilla-xulrunner191-x86 less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056892" comment="mozilla-xulrunner191 less than 1.9.1.6-1.1.1"/>
		</criteria>
	</criteria>
	<!-- f95e0523ee35275bfe5a5ff2cd4fe04f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056893" comment="mozilla-xulrunner190-32bit less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056894" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056895" comment="mozilla-xulrunner190-translations less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056896" comment="mozilla-xulrunner190-x86 less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056897" comment="mozilla-xulrunner190 less than 1.9.0.16-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093985" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3985</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3985" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3985" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to associate spoofed content with an invalid URL by setting document.location to this URL, and then writing arbitrary web script or HTML to the associated blank document, a related issue to CVE-2009-2654.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5d919095d6df0dbca3e4ed34b00f367c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056886" comment="MozillaFirefox-translations less than 3.5.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056887" comment="MozillaFirefox less than 3.5.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056888" comment="mozilla-xulrunner191-32bit less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056889" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056890" comment="mozilla-xulrunner191-translations less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056891" comment="mozilla-xulrunner191-x86 less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056892" comment="mozilla-xulrunner191 less than 1.9.1.6-1.1.1"/>
		</criteria>
	</criteria>
	<!-- f95e0523ee35275bfe5a5ff2cd4fe04f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056893" comment="mozilla-xulrunner190-32bit less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056894" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056895" comment="mozilla-xulrunner190-translations less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056896" comment="mozilla-xulrunner190-x86 less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056897" comment="mozilla-xulrunner190 less than 1.9.0.16-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093986" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3986</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3986" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3986" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to execute arbitrary JavaScript with chrome privileges by leveraging a reference to a chrome window from a content window, related to the window.opener property.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5d919095d6df0dbca3e4ed34b00f367c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056886" comment="MozillaFirefox-translations less than 3.5.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056887" comment="MozillaFirefox less than 3.5.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056888" comment="mozilla-xulrunner191-32bit less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056889" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056890" comment="mozilla-xulrunner191-translations less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056891" comment="mozilla-xulrunner191-x86 less than 1.9.1.6-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056892" comment="mozilla-xulrunner191 less than 1.9.1.6-1.1.1"/>
		</criteria>
	</criteria>
	<!-- f95e0523ee35275bfe5a5ff2cd4fe04f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056893" comment="mozilla-xulrunner190-32bit less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056894" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056895" comment="mozilla-xulrunner190-translations less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056896" comment="mozilla-xulrunner190-x86 less than 1.9.0.16-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056897" comment="mozilla-xulrunner190 less than 1.9.0.16-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093988" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-3988</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-3988" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3988" source="CVE"/>
	<description>
	Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly restrict read access to object properties in showModalDialog, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via crafted dialogArguments values.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5c9ba6a33f35e3ab788cbbefde6cf8a6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058351" comment="MozillaFirefox-translations less than 3.5.8-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058352" comment="MozillaFirefox less than 3.5.8-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058353" comment="mozilla-xulrunner191-32bit less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058354" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058355" comment="mozilla-xulrunner191-translations less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058356" comment="mozilla-xulrunner191-x86 less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058357" comment="mozilla-xulrunner191 less than 1.9.1.8-1.1.1"/>
		</criteria>
	</criteria>
	<!-- deb36b8154e27ded345f064786253ca1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058358" comment="mozilla-xulrunner190-32bit less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058359" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058360" comment="mozilla-xulrunner190-translations less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058361" comment="mozilla-xulrunner190-x86 less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058362" comment="mozilla-xulrunner190 less than 1.9.0.18-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094005" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4005</title>
	<affected family="unix">
		<platform>SLE 11 SERVER Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4005" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4005" source="CVE"/>
	<description>
	The collect_rx_frame function in drivers/isdn/hisax/hfc_usb.c in the Linux kernel before 2.6.32-rc7 allows attackers to have an unspecified impact via a crafted HDLC packet that arrives over ISDN and triggers a buffer under-read.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 4971d1bc45dfe19245872ca92e7fe051 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057255" comment="kernel-default-extra less than 2.6.27.39-0.3.2"/>
	</criteria>
	<!-- 51cdeaf4505dbc37870fece945793189 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057255" comment="kernel-default-extra less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057256" comment="kernel-ppc64-extra less than 2.6.27.39-0.3.2"/>
		</criteria>
	</criteria>
	<!-- 5ecbc30d0c137f9f7ce500a198dee54a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057257" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057258" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.39_0.3-7.1.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057259" comment="kernel-default-base less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057260" comment="kernel-default less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057261" comment="kernel-kdump less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057262" comment="kernel-ppc64-base less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057263" comment="kernel-ppc64 less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057264" comment="kernel-source less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057265" comment="kernel-syms less than 2.6.27.39-0.3.2"/>
		</criteria>
	</criteria>
	<!-- 9a0454a0e15d8a3d7e1869913ff2b725 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057233" comment="kernel-xen-extra less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- c9825ea9eb0265fbaf58b4e7f15828d7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
	</criteria>
	<!-- d4c3d61ff4cb77f117d3acbc6602aaeb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057220" comment="kernel-pae-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057233" comment="kernel-xen-extra less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e7c5f7ef7eeb152d788f9406d2374894 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059470" comment="ext4dev-kmp-default less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059471" comment="ext4dev-kmp-pae less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059472" comment="ext4dev-kmp-vmi less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059473" comment="ext4dev-kmp-xen less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057219" comment="kernel-pae-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057221" comment="kernel-pae less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059474" comment="kernel-vmi-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059475" comment="kernel-vmi less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057232" comment="kernel-xen-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057234" comment="kernel-xen less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e87c441668f87fa162f810ea0e06c3ba -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059470" comment="ext4dev-kmp-default less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059473" comment="ext4dev-kmp-xen less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057232" comment="kernel-xen-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057234" comment="kernel-xen less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- ef72143c4837b653dc18408ca8832f96 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057257" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057259" comment="kernel-default-base less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057260" comment="kernel-default less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057264" comment="kernel-source less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057265" comment="kernel-syms less than 2.6.27.39-0.3.2"/>
		</criteria>
	</criteria>
	<!-- f5e83f559ce7469c64852e5d2a3cc38d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059470" comment="ext4dev-kmp-default less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059476" comment="kernel-default-man less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094017" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4017</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4017" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4017" source="CVE"/>
	<description>
	PHP before 5.2.12 and 5.3.x before 5.3.1 does not restrict the number of temporary files created when handling a multipart/form-data POST request, which allows remote attackers to cause a denial of service (resource exhaustion), and makes it easier for remote attackers to exploit local file inclusion vulnerabilities, via multiple requests, related to lack of support for the max_file_uploads directive.
	</description>
 </metadata>
<!-- bfb263e4c75cfb6dca1c2ee69633f369 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009058031" comment="apache2-mod_php5 less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058032" comment="php5-bcmath less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058033" comment="php5-bz2 less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058034" comment="php5-calendar less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058035" comment="php5-ctype less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058036" comment="php5-curl less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058037" comment="php5-dba less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058038" comment="php5-dbase less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058039" comment="php5-dom less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058040" comment="php5-exif less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058041" comment="php5-fastcgi less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058042" comment="php5-ftp less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058043" comment="php5-gd less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058044" comment="php5-gettext less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058045" comment="php5-gmp less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058046" comment="php5-hash less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058047" comment="php5-iconv less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058048" comment="php5-json less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058049" comment="php5-ldap less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058050" comment="php5-mbstring less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058051" comment="php5-mcrypt less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058052" comment="php5-mysql less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058053" comment="php5-odbc less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058054" comment="php5-openssl less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058055" comment="php5-pcntl less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058056" comment="php5-pdo less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058057" comment="php5-pear less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058058" comment="php5-pgsql less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058059" comment="php5-pspell less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058060" comment="php5-shmop less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058061" comment="php5-snmp less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058062" comment="php5-soap less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058063" comment="php5-suhosin less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058064" comment="php5-sysvmsg less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058065" comment="php5-sysvsem less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058066" comment="php5-sysvshm less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058067" comment="php5-tokenizer less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058068" comment="php5-wddx less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058069" comment="php5-xmlreader less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058070" comment="php5-xmlrpc less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058071" comment="php5-xmlwriter less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058072" comment="php5-xsl less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058073" comment="php5-zip less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058074" comment="php5-zlib less than 5.2.6-50.24.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094019" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4019</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4019" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4019" source="CVE"/>
	<description>
	mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with subqueries, and does not (2) preserve certain null_value flags during execution of statements that use the GeomFromWKB function, which allows remote authenticated users to cause a denial of service (daemon crash) via a crafted statement.
	</description>
 </metadata>
<!-- 920486ef8624fdf8d628849a50561aa6 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060043" comment="libmysqlclient15-32bit less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060044" comment="libmysqlclient15-x86 less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060045" comment="libmysqlclient15 less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060046" comment="libmysqlclient_r15 less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060047" comment="mysql-Max less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060048" comment="mysql-client less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060049" comment="mysql less than 5.0.67-13.17.7"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094020" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4020</title>
	<affected family="unix">
		<platform>SLE 11 SERVER Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4020" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4020" source="CVE"/>
	<description>
	Stack-based buffer overflow in the hfs subsystem in the Linux kernel 2.6.32 allows remote attackers to have an unspecified impact via a crafted Hierarchical File System (HFS) filesystem, related to the hfs_readdir function in fs/hfs/dir.c.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 4971d1bc45dfe19245872ca92e7fe051 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057255" comment="kernel-default-extra less than 2.6.27.39-0.3.2"/>
	</criteria>
	<!-- 51cdeaf4505dbc37870fece945793189 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057255" comment="kernel-default-extra less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057256" comment="kernel-ppc64-extra less than 2.6.27.39-0.3.2"/>
		</criteria>
	</criteria>
	<!-- 5ecbc30d0c137f9f7ce500a198dee54a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057257" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057258" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.39_0.3-7.1.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057259" comment="kernel-default-base less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057260" comment="kernel-default less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057261" comment="kernel-kdump less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057262" comment="kernel-ppc64-base less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057263" comment="kernel-ppc64 less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057264" comment="kernel-source less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057265" comment="kernel-syms less than 2.6.27.39-0.3.2"/>
		</criteria>
	</criteria>
	<!-- 9a0454a0e15d8a3d7e1869913ff2b725 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057233" comment="kernel-xen-extra less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- c9825ea9eb0265fbaf58b4e7f15828d7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
	</criteria>
	<!-- d4c3d61ff4cb77f117d3acbc6602aaeb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057220" comment="kernel-pae-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057233" comment="kernel-xen-extra less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e7c5f7ef7eeb152d788f9406d2374894 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059470" comment="ext4dev-kmp-default less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059471" comment="ext4dev-kmp-pae less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059472" comment="ext4dev-kmp-vmi less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059473" comment="ext4dev-kmp-xen less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057219" comment="kernel-pae-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057221" comment="kernel-pae less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059474" comment="kernel-vmi-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059475" comment="kernel-vmi less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057232" comment="kernel-xen-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057234" comment="kernel-xen less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e87c441668f87fa162f810ea0e06c3ba -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059470" comment="ext4dev-kmp-default less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059473" comment="ext4dev-kmp-xen less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057232" comment="kernel-xen-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057234" comment="kernel-xen less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- ef72143c4837b653dc18408ca8832f96 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057257" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057259" comment="kernel-default-base less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057260" comment="kernel-default less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057264" comment="kernel-source less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057265" comment="kernel-syms less than 2.6.27.39-0.3.2"/>
		</criteria>
	</criteria>
	<!-- f5e83f559ce7469c64852e5d2a3cc38d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059470" comment="ext4dev-kmp-default less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059476" comment="kernel-default-man less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094022" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4022</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4022" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4022" source="CVE"/>
	<description>
	Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 440b3d1daa2c9fed4b99f7865ea3a906 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057427" comment="bind-chrootenv less than 9.5.0P2-20.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057428" comment="bind-doc less than 9.5.0P2-20.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057429" comment="bind-libs-32bit less than 9.5.0P2-20.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057430" comment="bind-libs-x86 less than 9.5.0P2-20.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057431" comment="bind-libs less than 9.5.0P2-20.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057432" comment="bind-utils less than 9.5.0P2-20.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057433" comment="bind less than 9.5.0P2-20.7.1"/>
		</criteria>
	</criteria>
	<!-- 815e5fc596ff53d04190524da4e8d4bb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009056411" comment="bind-chrootenv less than 9.5.0P2-20.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056412" comment="bind-doc less than 9.5.0P2-20.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056413" comment="bind-libs-32bit less than 9.5.0P2-20.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056414" comment="bind-libs-x86 less than 9.5.0P2-20.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056415" comment="bind-libs less than 9.5.0P2-20.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056416" comment="bind-utils less than 9.5.0P2-20.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009056417" comment="bind less than 9.5.0P2-20.4.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094028" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4028</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4028" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4028" source="CVE"/>
	<description>
	The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41, when OpenSSL is used, accepts a value of zero for the depth of X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary SSL-based MySQL servers via a crafted certificate, as demonstrated by a certificate presented by a server linked against the yaSSL library.
	</description>
 </metadata>
<!-- 920486ef8624fdf8d628849a50561aa6 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060043" comment="libmysqlclient15-32bit less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060044" comment="libmysqlclient15-x86 less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060045" comment="libmysqlclient15 less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060046" comment="libmysqlclient_r15 less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060047" comment="mysql-Max less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060048" comment="mysql-client less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060049" comment="mysql less than 5.0.67-13.17.7"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094030" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4030</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4030" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4030" source="CVE"/>
	<description>
	MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL data home directory, related to incorrect calculation of the mysql_unpacked_real_data_home value.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4098 and CVE-2008-2079.
	</description>
 </metadata>
<!-- 920486ef8624fdf8d628849a50561aa6 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060043" comment="libmysqlclient15-32bit less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060044" comment="libmysqlclient15-x86 less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060045" comment="libmysqlclient15 less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060046" comment="libmysqlclient_r15 less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060047" comment="mysql-Max less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060048" comment="mysql-client less than 5.0.67-13.17.7"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060049" comment="mysql less than 5.0.67-13.17.7"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094034" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4034</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4034" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4034" source="CVE"/>
	<description>
	PostgreSQL 7.4.x before 7.4.27, 8.0.x before 8.0.23, 8.1.x before 8.1.19, 8.2.x before 8.2.15, 8.3.x before 8.3.9, and 8.4.x before 8.4.2 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-middle attackers to spoof arbitrary SSL-based PostgreSQL servers via a crafted server certificate issued by a legitimate Certification Authority, and (2) allows remote attackers to bypass intended client-hostname restrictions via a crafted client certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
	</description>
 </metadata>
<!-- 60350894f45471126371713fb1946bb0 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009057276" comment="postgresql-contrib less than 8.3.9-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057277" comment="postgresql-docs less than 8.3.9-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057278" comment="postgresql-libs-32bit less than 8.3.9-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057279" comment="postgresql-libs-x86 less than 8.3.9-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057280" comment="postgresql-libs less than 8.3.9-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057281" comment="postgresql-server less than 8.3.9-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057282" comment="postgresql less than 8.3.9-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094035" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4035</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4035" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4035" source="CVE"/>
	<description>
	The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, does not check the return value of the getNextLine function, which allows context-dependent attackers to execute arbitrary code via a PDF file with a crafted Type 1 font that can produce a negative value, leading to a signed-to-unsigned integer conversion error and a buffer overflow.
	</description>
 </metadata>
<!-- bde2b755a6dc83d88dd11394793d4482 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009057042" comment="libpoppler-glib4 less than 0.10.1-1.31.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057043" comment="libpoppler-qt4-3 less than 0.10.1-1.31.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057044" comment="libpoppler4 less than 0.10.1-1.31.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057045" comment="poppler-tools less than 0.10.1-1.31.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094136" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4136</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4136" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4136" source="CVE"/>
	<description>
	PostgreSQL 7.4.x before 7.4.27, 8.0.x before 8.0.23, 8.1.x before 8.1.19, 8.2.x before 8.2.15, 8.3.x before 8.3.9, and 8.4.x before 8.4.2 does not properly manage session-local state during execution of an index function by a database superuser, which allows remote authenticated users to gain privileges via a table with crafted index functions, as demonstrated by functions that modify (1) search_path or (2) a prepared statement, a related issue to CVE-2007-6600 and CVE-2009-3230.
	</description>
 </metadata>
<!-- 60350894f45471126371713fb1946bb0 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009057276" comment="postgresql-contrib less than 8.3.9-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057277" comment="postgresql-docs less than 8.3.9-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057278" comment="postgresql-libs-32bit less than 8.3.9-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057279" comment="postgresql-libs-x86 less than 8.3.9-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057280" comment="postgresql-libs less than 8.3.9-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057281" comment="postgresql-server less than 8.3.9-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057282" comment="postgresql less than 8.3.9-0.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094138" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4138</title>
	<affected family="unix">
		<platform>SLE 11 SERVER Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4138" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4138" source="CVE"/>
	<description>
	drivers/firewire/ohci.c in the Linux kernel before 2.6.32-git9, when packet-per-buffer mode is used, allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unknown other impact via an unspecified ioctl associated with receiving an ISO packet that contains zero in the payload-length field.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 4971d1bc45dfe19245872ca92e7fe051 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057255" comment="kernel-default-extra less than 2.6.27.39-0.3.2"/>
	</criteria>
	<!-- 51cdeaf4505dbc37870fece945793189 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057255" comment="kernel-default-extra less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057256" comment="kernel-ppc64-extra less than 2.6.27.39-0.3.2"/>
		</criteria>
	</criteria>
	<!-- 5ecbc30d0c137f9f7ce500a198dee54a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057257" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057258" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.39_0.3-7.1.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057259" comment="kernel-default-base less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057260" comment="kernel-default less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057261" comment="kernel-kdump less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057262" comment="kernel-ppc64-base less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057263" comment="kernel-ppc64 less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057264" comment="kernel-source less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057265" comment="kernel-syms less than 2.6.27.39-0.3.2"/>
		</criteria>
	</criteria>
	<!-- 9a0454a0e15d8a3d7e1869913ff2b725 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057233" comment="kernel-xen-extra less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- c9825ea9eb0265fbaf58b4e7f15828d7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
	</criteria>
	<!-- d4c3d61ff4cb77f117d3acbc6602aaeb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057220" comment="kernel-pae-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057233" comment="kernel-xen-extra less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e7c5f7ef7eeb152d788f9406d2374894 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059470" comment="ext4dev-kmp-default less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059471" comment="ext4dev-kmp-pae less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059472" comment="ext4dev-kmp-vmi less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059473" comment="ext4dev-kmp-xen less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057219" comment="kernel-pae-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057221" comment="kernel-pae less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059474" comment="kernel-vmi-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059475" comment="kernel-vmi less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057232" comment="kernel-xen-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057234" comment="kernel-xen less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e87c441668f87fa162f810ea0e06c3ba -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059470" comment="ext4dev-kmp-default less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059473" comment="ext4dev-kmp-xen less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057232" comment="kernel-xen-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057234" comment="kernel-xen less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- ef72143c4837b653dc18408ca8832f96 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057257" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057259" comment="kernel-default-base less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057260" comment="kernel-default less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057264" comment="kernel-source less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057265" comment="kernel-syms less than 2.6.27.39-0.3.2"/>
		</criteria>
	</criteria>
	<!-- f5e83f559ce7469c64852e5d2a3cc38d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059470" comment="ext4dev-kmp-default less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059476" comment="kernel-default-man less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094142" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4142</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4142" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4142" source="CVE"/>
	<description>
	The htmlspecialchars function in PHP before 5.2.12 does not properly handle (1) overlong UTF-8 sequences, (2) invalid Shift_JIS sequences, and (3) invalid EUC-JP sequences, which allows remote attackers to conduct cross-site scripting (XSS) attacks by placing a crafted byte sequence before a special character.
	</description>
 </metadata>
<!-- bfb263e4c75cfb6dca1c2ee69633f369 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009058031" comment="apache2-mod_php5 less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058032" comment="php5-bcmath less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058033" comment="php5-bz2 less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058034" comment="php5-calendar less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058035" comment="php5-ctype less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058036" comment="php5-curl less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058037" comment="php5-dba less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058038" comment="php5-dbase less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058039" comment="php5-dom less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058040" comment="php5-exif less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058041" comment="php5-fastcgi less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058042" comment="php5-ftp less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058043" comment="php5-gd less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058044" comment="php5-gettext less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058045" comment="php5-gmp less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058046" comment="php5-hash less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058047" comment="php5-iconv less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058048" comment="php5-json less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058049" comment="php5-ldap less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058050" comment="php5-mbstring less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058051" comment="php5-mcrypt less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058052" comment="php5-mysql less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058053" comment="php5-odbc less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058054" comment="php5-openssl less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058055" comment="php5-pcntl less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058056" comment="php5-pdo less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058057" comment="php5-pear less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058058" comment="php5-pgsql less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058059" comment="php5-pspell less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058060" comment="php5-shmop less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058061" comment="php5-snmp less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058062" comment="php5-soap less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058063" comment="php5-suhosin less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058064" comment="php5-sysvmsg less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058065" comment="php5-sysvsem less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058066" comment="php5-sysvshm less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058067" comment="php5-tokenizer less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058068" comment="php5-wddx less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058069" comment="php5-xmlreader less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058070" comment="php5-xmlrpc less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058071" comment="php5-xmlwriter less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058072" comment="php5-xsl less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058073" comment="php5-zip less than 5.2.6-50.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058074" comment="php5-zlib less than 5.2.6-50.24.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094144" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4144</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4144" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4144" source="CVE"/>
	<description>
	NetworkManager (NM) 0.7.2 does not ensure that the configured Certification Authority (CA) certificate file for a (1) WPA Enterprise or (2) 802.1x network remains present upon a connection attempt, which might allow remote attackers to obtain sensitive information or cause a denial of service (connectivity disruption) by spoofing the identity of a wireless network.
	</description>
 </metadata>
<!-- 776b8b47d07dc7f9d184e6dc49981f25 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057532" comment="NetworkManager-gnome less than 0.7.0.r1053-11.11.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094145" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4145</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4145" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4145" source="CVE"/>
	<description>
	nm-connection-editor in NetworkManager (NM) 0.7.x exports connection objects over D-Bus upon actions in the connection editor GUI, which allows local users to obtain sensitive information by reading D-Bus signals, as demonstrated by using dbus-monitor to discover the password for the WiFi network.
	</description>
 </metadata>
<!-- 776b8b47d07dc7f9d184e6dc49981f25 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057532" comment="NetworkManager-gnome less than 0.7.0.r1053-11.11.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094212" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4212</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4212" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4212" source="CVE"/>
	<description>
	Multiple integer underflows in the (1) AES and (2) RC4 decryption functionality in the crypto library in MIT Kerberos 5 (aka krb5) 1.3 through 1.6.3, and 1.7 before 1.7.1, allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code by providing ciphertext with a length that is too short to be valid.
	</description>
 </metadata>
<!-- f95c0cbef4a252636c67dd8d77f705f6 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009057338" comment="krb5-32bit less than 1.6.3-133.26.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057339" comment="krb5-apps-clients less than 1.6.3-133.26.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057340" comment="krb5-apps-servers less than 1.6.3-133.26.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057341" comment="krb5-client less than 1.6.3-133.26.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057342" comment="krb5-server less than 1.6.3-133.26.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057343" comment="krb5-x86 less than 1.6.3-133.26.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057344" comment="krb5 less than 1.6.3-133.26.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094270" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4270</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2009-4270" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4270" source="CVE"/>
	<description>
	Stack-based buffer overflow in the errprintf function in base/gsmisc.c in ghostscript 8.64 through 8.70 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF file, as originally reported for debug logging code in gdevcups.c in the CUPS output driver.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 050a560119b003b7f093735ee4ea36d0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061853" comment="ghostscript-fonts-other less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061854" comment="ghostscript-fonts-rus less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061855" comment="ghostscript-fonts-std less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061856" comment="ghostscript-library less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061857" comment="ghostscript-omni less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061858" comment="ghostscript-x11 less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061859" comment="libgimpprint less than 4.2.7-32.28.1"/>
		</criteria>
	</criteria>
	<!-- 8ea47e7a8ca134ad54f518d9ea69e5c0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061860" comment="ghostscript-fonts-other less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061861" comment="ghostscript-fonts-rus less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061862" comment="ghostscript-fonts-std less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061863" comment="ghostscript-library less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061864" comment="ghostscript-omni less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061865" comment="ghostscript-x11 less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061866" comment="libgimpprint less than 4.2.7-32.27.26.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094273" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4273</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4273" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4273" source="CVE"/>
	<description>
	stap-server in SystemTap before 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in stap command-line arguments in a request.
	</description>
 </metadata>
<!-- 1b6f8b3aba0a4600d503d94dd164ad1a -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061867" comment="systemtap less than 0.7.1-42.5.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094274" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4274</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4274" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4274" source="CVE"/>
	<description>
	Stack-based buffer overflow in converter/ppm/xpmtoppm.c in netpbm before 10.47.07 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an XPM image file that contains a crafted header field associated with a large color index value.
	</description>
 </metadata>
<!-- c3b02633962feb1c3a979a3952f16b56 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009058585" comment="libnetpbm10-32bit less than 10.26.44-101.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058586" comment="libnetpbm10-x86 less than 10.26.44-101.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058587" comment="libnetpbm10 less than 10.26.44-101.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058588" comment="netpbm less than 10.26.44-101.9.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094307" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4307</title>
	<affected family="unix">
		<platform>SLE 11 SERVER Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4307" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4307" source="CVE"/>
	<description>
	The ext4_fill_flex_info function in fs/ext4/super.c in the Linux kernel before 2.6.32-git6 allows user-assisted remote attackers to cause a denial of service (divide-by-zero error and panic) via a malformed ext4 filesystem containing a super block with a large FLEX_BG group size (aka s_log_groups_per_flex value).
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 4971d1bc45dfe19245872ca92e7fe051 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057255" comment="kernel-default-extra less than 2.6.27.39-0.3.2"/>
	</criteria>
	<!-- 51cdeaf4505dbc37870fece945793189 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057255" comment="kernel-default-extra less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057256" comment="kernel-ppc64-extra less than 2.6.27.39-0.3.2"/>
		</criteria>
	</criteria>
	<!-- 5ecbc30d0c137f9f7ce500a198dee54a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057257" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057258" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.39_0.3-7.1.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057259" comment="kernel-default-base less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057260" comment="kernel-default less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057261" comment="kernel-kdump less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057262" comment="kernel-ppc64-base less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057263" comment="kernel-ppc64 less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057264" comment="kernel-source less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057265" comment="kernel-syms less than 2.6.27.39-0.3.2"/>
		</criteria>
	</criteria>
	<!-- 9a0454a0e15d8a3d7e1869913ff2b725 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057233" comment="kernel-xen-extra less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- c9825ea9eb0265fbaf58b4e7f15828d7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
	</criteria>
	<!-- d4c3d61ff4cb77f117d3acbc6602aaeb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057220" comment="kernel-pae-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057233" comment="kernel-xen-extra less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e7c5f7ef7eeb152d788f9406d2374894 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059470" comment="ext4dev-kmp-default less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059471" comment="ext4dev-kmp-pae less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059472" comment="ext4dev-kmp-vmi less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059473" comment="ext4dev-kmp-xen less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057219" comment="kernel-pae-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057221" comment="kernel-pae less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059474" comment="kernel-vmi-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059475" comment="kernel-vmi less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057232" comment="kernel-xen-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057234" comment="kernel-xen less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e87c441668f87fa162f810ea0e06c3ba -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059470" comment="ext4dev-kmp-default less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059473" comment="ext4dev-kmp-xen less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057232" comment="kernel-xen-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057234" comment="kernel-xen less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- ef72143c4837b653dc18408ca8832f96 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057257" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057259" comment="kernel-default-base less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057260" comment="kernel-default less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057264" comment="kernel-source less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057265" comment="kernel-syms less than 2.6.27.39-0.3.2"/>
		</criteria>
	</criteria>
	<!-- f5e83f559ce7469c64852e5d2a3cc38d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059470" comment="ext4dev-kmp-default less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059476" comment="kernel-default-man less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094308" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4308</title>
	<affected family="unix">
		<platform>SLE 11 SERVER Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4308" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4308" source="CVE"/>
	<description>
	The ext4_decode_error function in fs/ext4/super.c in the ext4 filesystem in the Linux kernel before 2.6.32 allows user-assisted remote attackers to cause a denial of service (NULL pointer dereference), and possibly have unspecified other impact, via a crafted read-only filesystem that lacks a journal.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 4971d1bc45dfe19245872ca92e7fe051 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057255" comment="kernel-default-extra less than 2.6.27.39-0.3.2"/>
	</criteria>
	<!-- 51cdeaf4505dbc37870fece945793189 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057255" comment="kernel-default-extra less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057256" comment="kernel-ppc64-extra less than 2.6.27.39-0.3.2"/>
		</criteria>
	</criteria>
	<!-- 5ecbc30d0c137f9f7ce500a198dee54a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057257" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057258" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.39_0.3-7.1.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057259" comment="kernel-default-base less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057260" comment="kernel-default less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057261" comment="kernel-kdump less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057262" comment="kernel-ppc64-base less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057263" comment="kernel-ppc64 less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057264" comment="kernel-source less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057265" comment="kernel-syms less than 2.6.27.39-0.3.2"/>
		</criteria>
	</criteria>
	<!-- 9a0454a0e15d8a3d7e1869913ff2b725 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057233" comment="kernel-xen-extra less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- c9825ea9eb0265fbaf58b4e7f15828d7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
	</criteria>
	<!-- d4c3d61ff4cb77f117d3acbc6602aaeb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057220" comment="kernel-pae-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057233" comment="kernel-xen-extra less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e7c5f7ef7eeb152d788f9406d2374894 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059470" comment="ext4dev-kmp-default less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059471" comment="ext4dev-kmp-pae less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059472" comment="ext4dev-kmp-vmi less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059473" comment="ext4dev-kmp-xen less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057219" comment="kernel-pae-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057221" comment="kernel-pae less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059474" comment="kernel-vmi-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059475" comment="kernel-vmi less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057232" comment="kernel-xen-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057234" comment="kernel-xen less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e87c441668f87fa162f810ea0e06c3ba -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059470" comment="ext4dev-kmp-default less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059473" comment="ext4dev-kmp-xen less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057232" comment="kernel-xen-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057234" comment="kernel-xen less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- ef72143c4837b653dc18408ca8832f96 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057257" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057259" comment="kernel-default-base less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057260" comment="kernel-default less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057264" comment="kernel-source less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057265" comment="kernel-syms less than 2.6.27.39-0.3.2"/>
		</criteria>
	</criteria>
	<!-- f5e83f559ce7469c64852e5d2a3cc38d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059470" comment="ext4dev-kmp-default less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059476" comment="kernel-default-man less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094355" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4355</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4355" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4355" source="CVE"/>
	<description>
	Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote attackers to cause a denial of service (memory consumption) via vectors that trigger incorrect calls to the CRYPTO_cleanup_all_ex_data function, as demonstrated by use of SSLv3 and PHP with the Apache HTTP Server, a related issue to CVE-2008-1678.
	</description>
 </metadata>
<!-- 1ae6c4e9639b98001a2ac448ab1ed302 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009057434" comment="libopenssl0_9_8-32bit less than 0.9.8h-30.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057435" comment="libopenssl0_9_8-x86 less than 0.9.8h-30.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057436" comment="libopenssl0_9_8 less than 0.9.8h-30.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057437" comment="openssl-doc less than 0.9.8h-30.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057438" comment="openssl less than 0.9.8h-30.18.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094376" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4376</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4376" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4376" source="CVE"/>
	<description>
	Buffer overflow in the daintree_sna_read function in the Daintree SNA file parser in Wireshark 1.2.0 through 1.2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet.
	</description>
 </metadata>
<!-- 963ff40259d4863a011be226650534cb -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058844" comment="wireshark less than 1.0.5-1.34.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094377" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4377</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4377" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4377" source="CVE"/>
	<description>
	The (1) SMB and (2) SMB2 dissectors in Wireshark 0.9.0 through 1.2.4 allow remote attackers to cause a denial of service (crash) via a crafted packet that triggers a NULL pointer dereference, as demonstrated by fuzz-2009-12-07-11141.pcap.
	</description>
 </metadata>
<!-- 963ff40259d4863a011be226650534cb -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058844" comment="wireshark less than 1.0.5-1.34.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094411" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4411</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4411" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4411" source="CVE"/>
	<description>
	The (1) setfacl and (2) getfacl commands in XFS acl 2.2.47, when running in recursive (-R) mode, follow symbolic links even when the --physical (aka -P) or -L option is specified, which might allow local users to modify the ACL for arbitrary files or directories via a symlink attack.
	</description>
 </metadata>
<!-- fef3a822e18985ac5eff08598984741e -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009057533" comment="acl less than 2.2.47-30.5.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057534" comment="libacl-32bit less than 2.2.47-30.5.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057535" comment="libacl-x86 less than 2.2.47-30.5.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057536" comment="libacl less than 2.2.47-30.5.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094492" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4492</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2009-4492" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4492" source="CVE"/>
	<description>
	WEBrick 1.3.1 in Ruby 1.8.6 through patchlevel 383, 1.8.7 through patchlevel 248, 1.8.8dev, 1.9.1 through patchlevel 376, and 1.9.2dev writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.
	</description>
 </metadata>
<!-- 5087d31530e2994f4eda91fda3425c12 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009068617" comment="ruby-doc-html less than 1.8.7.p72-5.28.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009068618" comment="ruby-tk less than 1.8.7.p72-5.28.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009068619" comment="ruby less than 1.8.7.p72-5.28.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094536" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4536</title>
	<affected family="unix">
		<platform>SLE 11 SERVER Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4536" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4536" source="CVE"/>
	<description>
	drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel 2.6.32.3 and earlier handles Ethernet frames that exceed the MTU by processing certain trailing payload data as if it were a complete frame, which allows remote attackers to bypass packet filters via a large packet with a crafted payload.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2009-1385.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1cc9f9878be828ca9494ad136beab1d1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 4971d1bc45dfe19245872ca92e7fe051 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057255" comment="kernel-default-extra less than 2.6.27.39-0.3.2"/>
	</criteria>
	<!-- 51cdeaf4505dbc37870fece945793189 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057255" comment="kernel-default-extra less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057256" comment="kernel-ppc64-extra less than 2.6.27.39-0.3.2"/>
		</criteria>
	</criteria>
	<!-- 5bc8b282021bec5a0602dd1e1fb86cc0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058496" comment="ext4dev-kmp-xen less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 5ecbc30d0c137f9f7ce500a198dee54a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057257" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057258" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.39_0.3-7.1.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057259" comment="kernel-default-base less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057260" comment="kernel-default less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057261" comment="kernel-kdump less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057262" comment="kernel-ppc64-base less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057263" comment="kernel-ppc64 less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057264" comment="kernel-source less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057265" comment="kernel-syms less than 2.6.27.39-0.3.2"/>
		</criteria>
	</criteria>
	<!-- 8de370e0ec03088da9aa16f31064b5c4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058499" comment="ext4dev-kmp-pae less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058500" comment="ext4dev-kmp-vmi less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058496" comment="ext4dev-kmp-xen less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058501" comment="kernel-pae-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058502" comment="kernel-pae less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058503" comment="kernel-vmi-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058504" comment="kernel-vmi less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 9a0454a0e15d8a3d7e1869913ff2b725 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057233" comment="kernel-xen-extra less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- b6015de562091b64634bc48dd8f9db1a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058505" comment="kernel-default-man less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- c9825ea9eb0265fbaf58b4e7f15828d7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
	</criteria>
	<!-- d4c3d61ff4cb77f117d3acbc6602aaeb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057220" comment="kernel-pae-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057233" comment="kernel-xen-extra less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e5c7588310814dc753e7fc885f8955fb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058506" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058507" comment="kernel-kdump less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058508" comment="kernel-ppc64-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058509" comment="kernel-ppc64 less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e7c5f7ef7eeb152d788f9406d2374894 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059470" comment="ext4dev-kmp-default less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059471" comment="ext4dev-kmp-pae less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059472" comment="ext4dev-kmp-vmi less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059473" comment="ext4dev-kmp-xen less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057219" comment="kernel-pae-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057221" comment="kernel-pae less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059474" comment="kernel-vmi-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059475" comment="kernel-vmi less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057232" comment="kernel-xen-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057234" comment="kernel-xen less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e87c441668f87fa162f810ea0e06c3ba -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059470" comment="ext4dev-kmp-default less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059473" comment="ext4dev-kmp-xen less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057232" comment="kernel-xen-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057234" comment="kernel-xen less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- ef72143c4837b653dc18408ca8832f96 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057257" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057259" comment="kernel-default-base less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057260" comment="kernel-default less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057264" comment="kernel-source less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057265" comment="kernel-syms less than 2.6.27.39-0.3.2"/>
		</criteria>
	</criteria>
	<!-- f5e83f559ce7469c64852e5d2a3cc38d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059470" comment="ext4dev-kmp-default less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059476" comment="kernel-default-man less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094537" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4537</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4537" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4537" source="CVE"/>
	<description>
	drivers/net/r8169.c in the r8169 driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to (1) cause a denial of service (temporary network outage) via a packet with a crafted size, in conjunction with certain packets containing A characters and certain packets containing E characters; or (2) cause a denial of service (system crash) via a packet with a crafted size, in conjunction with certain packets containing '\0' characters, related to the value of the status register and erroneous behavior associated with the RxMaxSize register.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2009-1389.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2959a2080579b86be5f71889c23098f9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061702" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061678" comment="kernel-kdump less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061682" comment="kernel-ppc64-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061684" comment="kernel-ppc64 less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 66504af0afe753b5175112b44bc8827d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061703" comment="ext4dev-kmp-pae less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061704" comment="ext4dev-kmp-vmi less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061705" comment="ext4dev-kmp-xen less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061679" comment="kernel-pae-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061681" comment="kernel-pae less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061706" comment="kernel-vmi-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061707" comment="kernel-vmi less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 99ed0d9e003dfe8866db7105d4850a09 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- c8a29eec659b0b2b3e85c610b67beacd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061705" comment="ext4dev-kmp-xen less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- f73f22d4b713e9a7674cc8c4eebf91dd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061708" comment="kernel-default-man less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094538" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4538</title>
	<affected family="unix">
		<platform>SLE 11 SERVER Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4538" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4538" source="CVE"/>
	<description>
	drivers/net/e1000e/netdev.c in the e1000e driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to have an unspecified impact via crafted packets, a related issue to CVE-2009-4537.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1cc9f9878be828ca9494ad136beab1d1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 4971d1bc45dfe19245872ca92e7fe051 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057255" comment="kernel-default-extra less than 2.6.27.39-0.3.2"/>
	</criteria>
	<!-- 51cdeaf4505dbc37870fece945793189 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057255" comment="kernel-default-extra less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057256" comment="kernel-ppc64-extra less than 2.6.27.39-0.3.2"/>
		</criteria>
	</criteria>
	<!-- 5bc8b282021bec5a0602dd1e1fb86cc0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058496" comment="ext4dev-kmp-xen less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 5ecbc30d0c137f9f7ce500a198dee54a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057257" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057258" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.39_0.3-7.1.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057259" comment="kernel-default-base less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057260" comment="kernel-default less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057261" comment="kernel-kdump less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057262" comment="kernel-ppc64-base less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057263" comment="kernel-ppc64 less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057264" comment="kernel-source less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057265" comment="kernel-syms less than 2.6.27.39-0.3.2"/>
		</criteria>
	</criteria>
	<!-- 8de370e0ec03088da9aa16f31064b5c4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058499" comment="ext4dev-kmp-pae less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058500" comment="ext4dev-kmp-vmi less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058496" comment="ext4dev-kmp-xen less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058501" comment="kernel-pae-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058502" comment="kernel-pae less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058503" comment="kernel-vmi-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058504" comment="kernel-vmi less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 9a0454a0e15d8a3d7e1869913ff2b725 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057233" comment="kernel-xen-extra less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- b6015de562091b64634bc48dd8f9db1a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058505" comment="kernel-default-man less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- c9825ea9eb0265fbaf58b4e7f15828d7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
	</criteria>
	<!-- d4c3d61ff4cb77f117d3acbc6602aaeb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057215" comment="kernel-default-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057220" comment="kernel-pae-extra less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057233" comment="kernel-xen-extra less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e5c7588310814dc753e7fc885f8955fb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058506" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058507" comment="kernel-kdump less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058508" comment="kernel-ppc64-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058509" comment="kernel-ppc64 less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e7c5f7ef7eeb152d788f9406d2374894 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059470" comment="ext4dev-kmp-default less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059471" comment="ext4dev-kmp-pae less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059472" comment="ext4dev-kmp-vmi less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059473" comment="ext4dev-kmp-xen less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057219" comment="kernel-pae-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057221" comment="kernel-pae less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059474" comment="kernel-vmi-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059475" comment="kernel-vmi less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057232" comment="kernel-xen-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057234" comment="kernel-xen less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e87c441668f87fa162f810ea0e06c3ba -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059470" comment="ext4dev-kmp-default less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059473" comment="ext4dev-kmp-xen less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057232" comment="kernel-xen-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057234" comment="kernel-xen less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
	<!-- ef72143c4837b653dc18408ca8832f96 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057257" comment="ext4dev-kmp-default less than 0_2.6.27.39_0.3-7.1.23"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057259" comment="kernel-default-base less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057260" comment="kernel-default less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057264" comment="kernel-source less than 2.6.27.39-0.3.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057265" comment="kernel-syms less than 2.6.27.39-0.3.2"/>
		</criteria>
	</criteria>
	<!-- f5e83f559ce7469c64852e5d2a3cc38d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059470" comment="ext4dev-kmp-default less than 0_2.6.27.42_0.1-7.1.24"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057214" comment="kernel-default-base less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059476" comment="kernel-default-man less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057216" comment="kernel-default less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057226" comment="kernel-source less than 2.6.27.42-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057227" comment="kernel-syms less than 2.6.27.42-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094565" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4565</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4565" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4565" source="CVE"/>
	<description>
	sendmail before 8.14.4 does not properly handle a '\0' character in a Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-middle attackers to spoof arbitrary SSL-based SMTP servers via a crafted server certificate issued by a legitimate Certification Authority, and (2) allows remote attackers to bypass intended access restrictions via a crafted client certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
	</description>
 </metadata>
<!-- de03bd34e9ddc0c39e678bf5ae966f96 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058473" comment="sendmail less than 8.14.3-50.20.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094835" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4835</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2009-4835" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4835" source="CVE"/>
	<description>
	The (1) htk_read_header, (2) alaw_init, (3) ulaw_init, (4) pcm_init, (5) float32_init, and (6) sds_read_header functions in libsndfile 1.0.20 allow context-dependent attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted audio file.
	</description>
 </metadata>
<!-- 2e050f9ffe143c431af2f12cbf7a3a42 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009069631" comment="libsndfile-32bit less than 1.0.20-2.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009069632" comment="libsndfile-x86 less than 1.0.20-2.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009069633" comment="libsndfile less than 1.0.20-2.4.1"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009069631" comment="libsndfile-32bit less than 1.0.20-2.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009069633" comment="libsndfile less than 1.0.20-2.4.1"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094895" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4895</title>
	<affected family="unix">
		<platform>SLE 11 SERVER Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2009-4895" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4895" source="CVE"/>
	<description>
	Race condition in the tty_fasync function in drivers/char/tty_io.c in the Linux kernel before 2.6.32.6 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via unknown vectors, related to the put_tty_queue and __f_setown functions.  NOTE: the vulnerability was addressed in a different way in 2.6.32.9.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1a1e84bdf877ca5c38ecac3616374922 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061675" comment="kernel-default-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061680" comment="kernel-pae-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061693" comment="kernel-xen-extra less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 2959a2080579b86be5f71889c23098f9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061702" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061678" comment="kernel-kdump less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061682" comment="kernel-ppc64-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061684" comment="kernel-ppc64 less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 34efb3de15e5405c1817c287028a50e3 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061675" comment="kernel-default-extra less than 2.6.27.48-0.1.1"/>
	</criteria>
	<!-- 3c314aa8e3d1c4878e06108d767c18da -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061675" comment="kernel-default-extra less than 2.6.27.48-0.1.1"/>
	</criteria>
	<!-- 66504af0afe753b5175112b44bc8827d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061703" comment="ext4dev-kmp-pae less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061704" comment="ext4dev-kmp-vmi less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061705" comment="ext4dev-kmp-xen less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061679" comment="kernel-pae-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061681" comment="kernel-pae less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061706" comment="kernel-vmi-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061707" comment="kernel-vmi less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 6a5b519e1125164aefd647adb31ccec8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061675" comment="kernel-default-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061683" comment="kernel-ppc64-extra less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 7c255bf89525f242ab9deddcf14e6517 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061675" comment="kernel-default-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061693" comment="kernel-xen-extra less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 99ed0d9e003dfe8866db7105d4850a09 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- c8a29eec659b0b2b3e85c610b67beacd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061705" comment="ext4dev-kmp-xen less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- f73f22d4b713e9a7674cc8c4eebf91dd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061708" comment="kernel-default-man less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094897" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-4897</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2009-4897" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4897" source="CVE"/>
	<description>
	Buffer overflow in gs/psi/iscan.c in Ghostscript 8.64 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document containing a long name.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 050a560119b003b7f093735ee4ea36d0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061853" comment="ghostscript-fonts-other less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061854" comment="ghostscript-fonts-rus less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061855" comment="ghostscript-fonts-std less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061856" comment="ghostscript-library less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061857" comment="ghostscript-omni less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061858" comment="ghostscript-x11 less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061859" comment="libgimpprint less than 4.2.7-32.28.1"/>
		</criteria>
	</criteria>
	<!-- 8ea47e7a8ca134ad54f518d9ea69e5c0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061860" comment="ghostscript-fonts-other less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061861" comment="ghostscript-fonts-rus less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061862" comment="ghostscript-fonts-std less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061863" comment="ghostscript-library less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061864" comment="ghostscript-omni less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061865" comment="ghostscript-x11 less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061866" comment="libgimpprint less than 4.2.7-32.27.26.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20095063" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2009-5063</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for Teradata</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2009-5063" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-5063" source="CVE"/>
	<description>
	Memory leak in pngwutil.c in libpng before 1.2.39beta5 allows context-dependent attackers to cause a denial of service (memory leak or segmentation fault) via a JPEG image containing an iCCP chunk with a negative embedded profile length.  NOTE: this is due to an incomplete fix for CVE-2006-7244.
	</description>
 </metadata>
<!-- 5b292f48bbbe6202317380a339315fad -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009069805" comment="libpng12-0-32bit less than 1.2.31-5.25.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009069806" comment="libpng12-0-x86 less than 1.2.31-5.25.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009069807" comment="libpng12-0 less than 1.2.31-5.25.1"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009069805" comment="libpng12-0-32bit less than 1.2.31-5.25.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009069807" comment="libpng12-0 less than 1.2.31-5.25.1"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100001" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0001</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0001" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0001" source="CVE"/>
	<description>
	Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit platforms, as used in ncompress and probably others, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted archive that uses LZW compression, leading to an array index error.
	</description>
 </metadata>
<!-- 8388a149c9d32703af6f0ac8782851c4 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057426" comment="gzip less than 1.3.12-69.19.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100003" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0003</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0003" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0003" source="CVE"/>
	<description>
	The print_fatal_signal function in kernel/signal.c in the Linux kernel before 2.6.32.4 on the i386 platform, when print-fatal-signals is enabled, allows local users to discover the contents of arbitrary memory locations by jumping to an address and then reading a log file, and might allow local users to cause a denial of service (system slowdown or crash) by jumping to an address.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1cc9f9878be828ca9494ad136beab1d1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 5bc8b282021bec5a0602dd1e1fb86cc0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058496" comment="ext4dev-kmp-xen less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 8de370e0ec03088da9aa16f31064b5c4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058499" comment="ext4dev-kmp-pae less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058500" comment="ext4dev-kmp-vmi less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058496" comment="ext4dev-kmp-xen less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058501" comment="kernel-pae-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058502" comment="kernel-pae less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058503" comment="kernel-vmi-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058504" comment="kernel-vmi less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- b6015de562091b64634bc48dd8f9db1a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058505" comment="kernel-default-man less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e5c7588310814dc753e7fc885f8955fb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058506" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058507" comment="kernel-kdump less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058508" comment="kernel-ppc64-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058509" comment="kernel-ppc64 less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100007" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0007</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0007" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0007" source="CVE"/>
	<description>
	net/bridge/netfilter/ebtables.c in the ebtables module in the netfilter framework in the Linux kernel before 2.6.33-rc4 does not require the CAP_NET_ADMIN capability for setting or modifying rules, which allows local users to bypass intended access restrictions and configure arbitrary network-traffic filtering via a modified ebtables application.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1cc9f9878be828ca9494ad136beab1d1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 5bc8b282021bec5a0602dd1e1fb86cc0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058496" comment="ext4dev-kmp-xen less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 8de370e0ec03088da9aa16f31064b5c4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058499" comment="ext4dev-kmp-pae less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058500" comment="ext4dev-kmp-vmi less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058496" comment="ext4dev-kmp-xen less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058501" comment="kernel-pae-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058502" comment="kernel-pae less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058503" comment="kernel-vmi-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058504" comment="kernel-vmi less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- b6015de562091b64634bc48dd8f9db1a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058505" comment="kernel-default-man less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e5c7588310814dc753e7fc885f8955fb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058506" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058507" comment="kernel-kdump less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058508" comment="kernel-ppc64-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058509" comment="kernel-ppc64 less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100015" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0015</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-0015" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0015" source="CVE"/>
	<description>
	nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords of NIS accounts by calling the getpwnam function.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5f11ad23d76a12882072f1f4032fd9a4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064033" comment="glibc-32bit less than 2.9-13.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064034" comment="glibc-devel-32bit less than 2.9-13.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064035" comment="glibc-devel less than 2.9-13.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064036" comment="glibc-html less than 2.9-13.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064037" comment="glibc-i18ndata less than 2.9-13.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064038" comment="glibc-info less than 2.9-13.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064039" comment="glibc-locale-32bit less than 2.9-13.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064040" comment="glibc-locale less than 2.9-13.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064041" comment="glibc-profile-32bit less than 2.9-13.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064042" comment="glibc-profile less than 2.9-13.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064043" comment="glibc less than 2.9-13.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064044" comment="nscd less than 2.9-13.11.1"/>
		</criteria>
	</criteria>
	<!-- 6015df6da5266bf10b03367cfb25b171 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009069098" comment="glibc-32bit less than 2.11.1-0.30.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009069099" comment="glibc-devel-32bit less than 2.11.1-0.30.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009069100" comment="glibc-devel less than 2.11.1-0.30.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009069101" comment="glibc-html less than 2.11.1-0.30.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009069102" comment="glibc-i18ndata less than 2.11.1-0.30.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009069103" comment="glibc-info less than 2.11.1-0.30.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009069104" comment="glibc-locale-32bit less than 2.11.1-0.30.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009069105" comment="glibc-locale-x86 less than 2.11.1-0.30.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009069106" comment="glibc-locale less than 2.11.1-0.30.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009069107" comment="glibc-profile-32bit less than 2.11.1-0.30.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009069108" comment="glibc-profile-x86 less than 2.11.1-0.30.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009069109" comment="glibc-profile less than 2.11.1-0.30.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009069110" comment="glibc-x86 less than 2.11.1-0.30.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009069111" comment="glibc less than 2.11.1-0.30.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009069112" comment="nscd less than 2.11.1-0.30.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009069098" comment="glibc-32bit less than 2.11.1-0.30.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009069099" comment="glibc-devel-32bit less than 2.11.1-0.30.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009069100" comment="glibc-devel less than 2.11.1-0.30.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009069101" comment="glibc-html less than 2.11.1-0.30.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009069102" comment="glibc-i18ndata less than 2.11.1-0.30.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009069103" comment="glibc-info less than 2.11.1-0.30.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009069104" comment="glibc-locale-32bit less than 2.11.1-0.30.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009069106" comment="glibc-locale less than 2.11.1-0.30.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009069107" comment="glibc-profile-32bit less than 2.11.1-0.30.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009069109" comment="glibc-profile less than 2.11.1-0.30.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009069111" comment="glibc less than 2.11.1-0.30.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009069112" comment="nscd less than 2.11.1-0.30.1"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100084" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0084</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Java 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>sles11-java.i386</platform>
		<platform>sles11-java.ia64</platform>
		<platform>sles11-java.ppc64</platform>
		<platform>sles11-java.s390x</platform>
		<platform>sles11-java.x86_64</platform>
	</affected>
	<reference ref_id="CVE-2010-0084" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0084" source="CVE"/>
	<description>
	Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 12597bfedbb46982a7db921e22529a3f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062167" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062168" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062169" comment="java-1_4_2-ibm less than 1.4.2_sr13.5-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 22b7b43ee38cfc5dac6ddc1fad1d45e5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061078" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061079" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061080" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061081" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061082" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.7.1"/>
		</criteria>
	</criteria>
	<!-- 86f8e0835cea2b76091e1f68f65ed768 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062167" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062168" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062169" comment="java-1_4_2-ibm less than 1.4.2_sr13.5-0.1.1"/>
		</criteria>
	</criteria>
	<!-- a1c03b73aa6d1ead4ac038bf35d86be9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061083" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061084" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061085" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061086" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061087" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.1.2"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100085" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0085</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Java 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>sles11-java.i386</platform>
		<platform>sles11-java.ia64</platform>
		<platform>sles11-java.ppc64</platform>
		<platform>sles11-java.s390x</platform>
		<platform>sles11-java.x86_64</platform>
	</affected>
	<reference ref_id="CVE-2010-0085" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0085" source="CVE"/>
	<description>
	Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 12597bfedbb46982a7db921e22529a3f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062167" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062168" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062169" comment="java-1_4_2-ibm less than 1.4.2_sr13.5-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 22b7b43ee38cfc5dac6ddc1fad1d45e5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061078" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061079" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061080" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061081" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061082" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.7.1"/>
		</criteria>
	</criteria>
	<!-- 86f8e0835cea2b76091e1f68f65ed768 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062167" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062168" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062169" comment="java-1_4_2-ibm less than 1.4.2_sr13.5-0.1.1"/>
		</criteria>
	</criteria>
	<!-- a1c03b73aa6d1ead4ac038bf35d86be9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061083" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061084" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061085" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061086" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061087" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.1.2"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100087" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0087</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Java 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>sles11-java.i386</platform>
		<platform>sles11-java.ia64</platform>
		<platform>sles11-java.ppc64</platform>
		<platform>sles11-java.s390x</platform>
		<platform>sles11-java.x86_64</platform>
	</affected>
	<reference ref_id="CVE-2010-0087" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0087" source="CVE"/>
	<description>
	Unspecified vulnerability in the Java Web Start, Java Plug-in component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 12597bfedbb46982a7db921e22529a3f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062167" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062168" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062169" comment="java-1_4_2-ibm less than 1.4.2_sr13.5-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 22b7b43ee38cfc5dac6ddc1fad1d45e5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061078" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061079" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061080" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061081" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061082" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.7.1"/>
		</criteria>
	</criteria>
	<!-- 86f8e0835cea2b76091e1f68f65ed768 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062167" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062168" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062169" comment="java-1_4_2-ibm less than 1.4.2_sr13.5-0.1.1"/>
		</criteria>
	</criteria>
	<!-- a1c03b73aa6d1ead4ac038bf35d86be9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061083" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061084" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061085" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061086" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061087" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.1.2"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100088" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0088</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Java 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>sles11-java.i386</platform>
		<platform>sles11-java.ia64</platform>
		<platform>sles11-java.ppc64</platform>
		<platform>sles11-java.s390x</platform>
		<platform>sles11-java.x86_64</platform>
	</affected>
	<reference ref_id="CVE-2010-0088" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0088" source="CVE"/>
	<description>
	Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 12597bfedbb46982a7db921e22529a3f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062167" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062168" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062169" comment="java-1_4_2-ibm less than 1.4.2_sr13.5-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 22b7b43ee38cfc5dac6ddc1fad1d45e5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061078" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061079" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061080" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061081" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061082" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.7.1"/>
		</criteria>
	</criteria>
	<!-- 86f8e0835cea2b76091e1f68f65ed768 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062167" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062168" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062169" comment="java-1_4_2-ibm less than 1.4.2_sr13.5-0.1.1"/>
		</criteria>
	</criteria>
	<!-- a1c03b73aa6d1ead4ac038bf35d86be9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061083" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061084" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061085" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061086" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061087" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.1.2"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100089" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0089</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Java 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>sles11-java.i386</platform>
		<platform>sles11-java.ia64</platform>
		<platform>sles11-java.ppc64</platform>
		<platform>sles11-java.s390x</platform>
		<platform>sles11-java.x86_64</platform>
	</affected>
	<reference ref_id="CVE-2010-0089" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0089" source="CVE"/>
	<description>
	Unspecified vulnerability in the Java Web Start, Java Plug-in component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect availability via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 12597bfedbb46982a7db921e22529a3f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062167" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062168" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062169" comment="java-1_4_2-ibm less than 1.4.2_sr13.5-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 22b7b43ee38cfc5dac6ddc1fad1d45e5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061078" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061079" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061080" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061081" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061082" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.7.1"/>
		</criteria>
	</criteria>
	<!-- 86f8e0835cea2b76091e1f68f65ed768 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062167" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062168" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062169" comment="java-1_4_2-ibm less than 1.4.2_sr13.5-0.1.1"/>
		</criteria>
	</criteria>
	<!-- a1c03b73aa6d1ead4ac038bf35d86be9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061083" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061084" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061085" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061086" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061087" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.1.2"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100090" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0090</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Java 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-0090" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0090" source="CVE"/>
	<description>
	Unspecified vulnerability in the Java Web Start, Java Plug-in component in Oracle Java SE and Java for Business 6 Update 18 allows remote attackers to affect integrity and availability via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 22b7b43ee38cfc5dac6ddc1fad1d45e5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061078" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061079" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061080" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061081" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061082" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.7.1"/>
		</criteria>
	</criteria>
	<!-- a1c03b73aa6d1ead4ac038bf35d86be9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061083" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061084" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061085" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061086" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061087" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.1.2"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100091" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0091</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Java 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>sles11-java.i386</platform>
		<platform>sles11-java.ia64</platform>
		<platform>sles11-java.ppc64</platform>
		<platform>sles11-java.s390x</platform>
		<platform>sles11-java.x86_64</platform>
	</affected>
	<reference ref_id="CVE-2010-0091" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0091" source="CVE"/>
	<description>
	Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 12597bfedbb46982a7db921e22529a3f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062167" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062168" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062169" comment="java-1_4_2-ibm less than 1.4.2_sr13.5-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 22b7b43ee38cfc5dac6ddc1fad1d45e5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061078" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061079" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061080" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061081" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061082" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.7.1"/>
		</criteria>
	</criteria>
	<!-- 86f8e0835cea2b76091e1f68f65ed768 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062167" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062168" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062169" comment="java-1_4_2-ibm less than 1.4.2_sr13.5-0.1.1"/>
		</criteria>
	</criteria>
	<!-- a1c03b73aa6d1ead4ac038bf35d86be9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061083" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061084" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061085" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061086" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061087" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.1.2"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100092" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0092</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Java 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-0092" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0092" source="CVE"/>
	<description>
	Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, and 5.0 Update 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 22b7b43ee38cfc5dac6ddc1fad1d45e5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061078" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061079" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061080" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061081" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061082" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.7.1"/>
		</criteria>
	</criteria>
	<!-- a1c03b73aa6d1ead4ac038bf35d86be9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061083" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061084" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061085" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061086" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061087" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.1.2"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100094" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0094</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Java 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-0094" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0094" source="CVE"/>
	<description>
	Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18 and 5.0 Update 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is due to missing privilege checks during deserialization of RMIConnectionImpl objects, which allows remote attackers to call system-level Java functions via the ClassLoader of a constructor that is being deserialized.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 22b7b43ee38cfc5dac6ddc1fad1d45e5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061078" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061079" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061080" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061081" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061082" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.7.1"/>
		</criteria>
	</criteria>
	<!-- a1c03b73aa6d1ead4ac038bf35d86be9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061083" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061084" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061085" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061086" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061087" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.1.2"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100095" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0095</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Java 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>sles11-java.i386</platform>
		<platform>sles11-java.ia64</platform>
		<platform>sles11-java.ppc64</platform>
		<platform>sles11-java.s390x</platform>
		<platform>sles11-java.x86_64</platform>
	</affected>
	<reference ref_id="CVE-2010-0095" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0095" source="CVE"/>
	<description>
	Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 12597bfedbb46982a7db921e22529a3f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062167" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062168" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062169" comment="java-1_4_2-ibm less than 1.4.2_sr13.5-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 22b7b43ee38cfc5dac6ddc1fad1d45e5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061078" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061079" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061080" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061081" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061082" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.7.1"/>
		</criteria>
	</criteria>
	<!-- 86f8e0835cea2b76091e1f68f65ed768 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062167" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062168" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062169" comment="java-1_4_2-ibm less than 1.4.2_sr13.5-0.1.1"/>
		</criteria>
	</criteria>
	<!-- a1c03b73aa6d1ead4ac038bf35d86be9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061083" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061084" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061085" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061086" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061087" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.1.2"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100097" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0097</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0097" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0097" source="CVE"/>
	<description>
	ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged NXDOMAIN response for an existing domain.
	</description>
 </metadata>
<!-- 440b3d1daa2c9fed4b99f7865ea3a906 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009057427" comment="bind-chrootenv less than 9.5.0P2-20.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057428" comment="bind-doc less than 9.5.0P2-20.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057429" comment="bind-libs-32bit less than 9.5.0P2-20.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057430" comment="bind-libs-x86 less than 9.5.0P2-20.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057431" comment="bind-libs less than 9.5.0P2-20.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057432" comment="bind-utils less than 9.5.0P2-20.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057433" comment="bind less than 9.5.0P2-20.7.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100156" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0156</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0156" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0156" source="CVE"/>
	<description>
	Puppet 0.24.x before 0.24.9 and 0.25.x before 0.25.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/daemonout, (2) /tmp/puppetdoc.txt, (3) /tmp/puppetdoc.tex, or (4) /tmp/puppetdoc.aux temporary file.
	</description>
 </metadata>
<!-- 79091fa279f2a9833e22da9ea3f83d3a -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060819" comment="puppet-server less than 0.24.5-5.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060820" comment="puppet less than 0.24.5-5.7.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100159" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0159</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0159" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0159" source="CVE"/>
	<description>
	The browser engine in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the nsBlockFrame::StealFrame function in layout/generic/nsBlockFrame.cpp, and unspecified other vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5c9ba6a33f35e3ab788cbbefde6cf8a6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058351" comment="MozillaFirefox-translations less than 3.5.8-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058352" comment="MozillaFirefox less than 3.5.8-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058353" comment="mozilla-xulrunner191-32bit less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058354" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058355" comment="mozilla-xulrunner191-translations less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058356" comment="mozilla-xulrunner191-x86 less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058357" comment="mozilla-xulrunner191 less than 1.9.1.8-1.1.1"/>
		</criteria>
	</criteria>
	<!-- deb36b8154e27ded345f064786253ca1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058358" comment="mozilla-xulrunner190-32bit less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058359" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058360" comment="mozilla-xulrunner190-translations less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058361" comment="mozilla-xulrunner190-x86 less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058362" comment="mozilla-xulrunner190 less than 1.9.0.18-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100160" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0160</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0160" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0160" source="CVE"/>
	<description>
	The Web Worker functionality in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly handle array data types for posted messages, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5c9ba6a33f35e3ab788cbbefde6cf8a6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058351" comment="MozillaFirefox-translations less than 3.5.8-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058352" comment="MozillaFirefox less than 3.5.8-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058353" comment="mozilla-xulrunner191-32bit less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058354" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058355" comment="mozilla-xulrunner191-translations less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058356" comment="mozilla-xulrunner191-x86 less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058357" comment="mozilla-xulrunner191 less than 1.9.1.8-1.1.1"/>
		</criteria>
	</criteria>
	<!-- deb36b8154e27ded345f064786253ca1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058358" comment="mozilla-xulrunner190-32bit less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058359" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058360" comment="mozilla-xulrunner190-translations less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058361" comment="mozilla-xulrunner190-x86 less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058362" comment="mozilla-xulrunner190 less than 1.9.0.18-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100162" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0162</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0162" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0162" source="CVE"/>
	<description>
	Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly support the application/octet-stream content type as a protection mechanism against execution of web script in certain circumstances involving SVG and the EMBED element, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via an embedded SVG document.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5c9ba6a33f35e3ab788cbbefde6cf8a6 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058351" comment="MozillaFirefox-translations less than 3.5.8-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058352" comment="MozillaFirefox less than 3.5.8-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058353" comment="mozilla-xulrunner191-32bit less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058354" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058355" comment="mozilla-xulrunner191-translations less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058356" comment="mozilla-xulrunner191-x86 less than 1.9.1.8-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058357" comment="mozilla-xulrunner191 less than 1.9.1.8-1.1.1"/>
		</criteria>
	</criteria>
	<!-- deb36b8154e27ded345f064786253ca1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058358" comment="mozilla-xulrunner190-32bit less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058359" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058360" comment="mozilla-xulrunner190-translations less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058361" comment="mozilla-xulrunner190-x86 less than 1.9.0.18-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058362" comment="mozilla-xulrunner190 less than 1.9.0.18-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100173" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0173</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0173" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0173" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8ead451f2aa5a3390fe43fc3d4eff649 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059477" comment="mozilla-xulrunner190-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059478" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059479" comment="mozilla-xulrunner190-translations less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059480" comment="mozilla-xulrunner190-x86 less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059481" comment="mozilla-xulrunner190 less than 1.9.0.19-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e687f5d3988822ee23e0bd97566703f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059482" comment="MozillaFirefox-translations less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059483" comment="MozillaFirefox less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059484" comment="mozilla-xulrunner191-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059485" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059486" comment="mozilla-xulrunner191-translations less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059487" comment="mozilla-xulrunner191-x86 less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059488" comment="mozilla-xulrunner191 less than 1.9.1.9-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100174" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0174</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0174" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0174" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4; and SeaMonkey before 2.0.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8ead451f2aa5a3390fe43fc3d4eff649 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059477" comment="mozilla-xulrunner190-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059478" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059479" comment="mozilla-xulrunner190-translations less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059480" comment="mozilla-xulrunner190-x86 less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059481" comment="mozilla-xulrunner190 less than 1.9.0.19-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e687f5d3988822ee23e0bd97566703f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059482" comment="MozillaFirefox-translations less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059483" comment="MozillaFirefox less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059484" comment="mozilla-xulrunner191-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059485" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059486" comment="mozilla-xulrunner191-translations less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059487" comment="mozilla-xulrunner191-x86 less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059488" comment="mozilla-xulrunner191 less than 1.9.1.9-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100175" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0175</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0175" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0175" source="CVE"/>
	<description>
	Use-after-free vulnerability in the nsTreeSelection implementation in Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.9, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors that trigger a call to the handler for the select event for XUL tree items.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8ead451f2aa5a3390fe43fc3d4eff649 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059477" comment="mozilla-xulrunner190-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059478" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059479" comment="mozilla-xulrunner190-translations less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059480" comment="mozilla-xulrunner190-x86 less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059481" comment="mozilla-xulrunner190 less than 1.9.0.19-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e687f5d3988822ee23e0bd97566703f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059482" comment="MozillaFirefox-translations less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059483" comment="MozillaFirefox less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059484" comment="mozilla-xulrunner191-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059485" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059486" comment="mozilla-xulrunner191-translations less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059487" comment="mozilla-xulrunner191-x86 less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059488" comment="mozilla-xulrunner191 less than 1.9.1.9-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100176" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0176</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0176" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0176" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4; and SeaMonkey before 2.0.4 do not properly manage reference counts for option elements in a XUL tree optgroup, which might allow remote attackers to execute arbitrary code via unspecified vectors that trigger access to deleted elements, related to a "dangling pointer vulnerability."
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8ead451f2aa5a3390fe43fc3d4eff649 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059477" comment="mozilla-xulrunner190-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059478" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059479" comment="mozilla-xulrunner190-translations less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059480" comment="mozilla-xulrunner190-x86 less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059481" comment="mozilla-xulrunner190 less than 1.9.0.19-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e687f5d3988822ee23e0bd97566703f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059482" comment="MozillaFirefox-translations less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059483" comment="MozillaFirefox less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059484" comment="mozilla-xulrunner191-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059485" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059486" comment="mozilla-xulrunner191-translations less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059487" comment="mozilla-xulrunner191-x86 less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059488" comment="mozilla-xulrunner191 less than 1.9.1.9-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100177" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0177</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0177" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0177" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, frees the contents of the window.navigator.plugins array while a reference to an array element is still active, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors, related to a "dangling pointer vulnerability."
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8ead451f2aa5a3390fe43fc3d4eff649 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059477" comment="mozilla-xulrunner190-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059478" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059479" comment="mozilla-xulrunner190-translations less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059480" comment="mozilla-xulrunner190-x86 less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059481" comment="mozilla-xulrunner190 less than 1.9.0.19-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e687f5d3988822ee23e0bd97566703f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059482" comment="MozillaFirefox-translations less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059483" comment="MozillaFirefox less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059484" comment="mozilla-xulrunner191-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059485" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059486" comment="mozilla-xulrunner191-translations less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059487" comment="mozilla-xulrunner191-x86 less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059488" comment="mozilla-xulrunner191 less than 1.9.1.9-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100178" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0178</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0178" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0178" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, does not prevent applets from interpreting mouse clicks as drag-and-drop actions, which allows remote attackers to execute arbitrary JavaScript with Chrome privileges by loading a chrome: URL and then loading a javascript: URL.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8ead451f2aa5a3390fe43fc3d4eff649 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059477" comment="mozilla-xulrunner190-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059478" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059479" comment="mozilla-xulrunner190-translations less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059480" comment="mozilla-xulrunner190-x86 less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059481" comment="mozilla-xulrunner190 less than 1.9.0.19-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e687f5d3988822ee23e0bd97566703f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059482" comment="MozillaFirefox-translations less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059483" comment="MozillaFirefox less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059484" comment="mozilla-xulrunner191-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059485" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059486" comment="mozilla-xulrunner191-translations less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059487" comment="mozilla-xulrunner191-x86 less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059488" comment="mozilla-xulrunner191 less than 1.9.1.9-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100179" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0179</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-0179" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0179" source="CVE"/>
	<description>
	Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, when the XMLHttpRequestSpy module in the Firebug add-on is used, does not properly handle interaction between the XMLHttpRequestSpy object and chrome privileged objects, which allows remote attackers to execute arbitrary JavaScript via a crafted HTTP response.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 60c97a6dd73ffa7ac423d55d993471d0 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009065329" comment="MozillaFirefox-translations less than 3.6.13-0.7.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065330" comment="MozillaFirefox less than 3.6.13-0.7.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065331" comment="mozilla-xulrunner192-32bit less than 1.9.2.13-1.7.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065332" comment="mozilla-xulrunner192-gnome less than 1.9.2.13-1.7.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065333" comment="mozilla-xulrunner192-translations less than 1.9.2.13-1.7.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065334" comment="mozilla-xulrunner192-x86 less than 1.9.2.13-1.7.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065335" comment="mozilla-xulrunner192 less than 1.9.2.13-1.7.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009065329" comment="MozillaFirefox-translations less than 3.6.13-0.7.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065330" comment="MozillaFirefox less than 3.6.13-0.7.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065331" comment="mozilla-xulrunner192-32bit less than 1.9.2.13-1.7.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065332" comment="mozilla-xulrunner192-gnome less than 1.9.2.13-1.7.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065333" comment="mozilla-xulrunner192-translations less than 1.9.2.13-1.7.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065335" comment="mozilla-xulrunner192 less than 1.9.2.13-1.7.1"/>
			</criteria>
		</criteria></criteria>
	<!-- 8ead451f2aa5a3390fe43fc3d4eff649 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059477" comment="mozilla-xulrunner190-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059478" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059479" comment="mozilla-xulrunner190-translations less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059480" comment="mozilla-xulrunner190-x86 less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059481" comment="mozilla-xulrunner190 less than 1.9.0.19-0.1.1"/>
		</criteria>
	</criteria>
	<!-- b2953cad2a3b3bd6c26f1ac2807a1556 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009065250" comment="mozilla-xulrunner191-32bit less than 1.9.1.16-0.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065253" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.16-0.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065336" comment="mozilla-xulrunner191-translations less than 1.9.1.16-0.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065337" comment="mozilla-xulrunner191-x86 less than 1.9.1.16-0.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065256" comment="mozilla-xulrunner191 less than 1.9.1.16-0.1.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009065250" comment="mozilla-xulrunner191-32bit less than 1.9.1.16-0.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065253" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.16-0.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065336" comment="mozilla-xulrunner191-translations less than 1.9.1.16-0.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065256" comment="mozilla-xulrunner191 less than 1.9.1.16-0.1.1"/>
			</criteria>
		</criteria></criteria>
	<!-- e687f5d3988822ee23e0bd97566703f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059482" comment="MozillaFirefox-translations less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059483" comment="MozillaFirefox less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059484" comment="mozilla-xulrunner191-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059485" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059486" comment="mozilla-xulrunner191-translations less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059487" comment="mozilla-xulrunner191-x86 less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059488" comment="mozilla-xulrunner191 less than 1.9.1.9-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100181" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0181</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0181" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0181" source="CVE"/>
	<description>
	Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, executes a mail application in situations where an IMG element has a SRC attribute that is a redirect to a mailto: URL, which allows remote attackers to cause a denial of service (excessive application launches) via an HTML document with many images.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8ead451f2aa5a3390fe43fc3d4eff649 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059477" comment="mozilla-xulrunner190-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059478" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059479" comment="mozilla-xulrunner190-translations less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059480" comment="mozilla-xulrunner190-x86 less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059481" comment="mozilla-xulrunner190 less than 1.9.0.19-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e687f5d3988822ee23e0bd97566703f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059482" comment="MozillaFirefox-translations less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059483" comment="MozillaFirefox less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059484" comment="mozilla-xulrunner191-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059485" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059486" comment="mozilla-xulrunner191-translations less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059487" comment="mozilla-xulrunner191-x86 less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059488" comment="mozilla-xulrunner191 less than 1.9.1.9-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100182" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0182</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0182" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0182" source="CVE"/>
	<description>
	The XMLDocument::load function in Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 does not perform the expected nsIContentPolicy checks during loading of content by XML documents, which allows attackers to bypass intended access restrictions via crafted content.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 8ead451f2aa5a3390fe43fc3d4eff649 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059477" comment="mozilla-xulrunner190-32bit less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059478" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059479" comment="mozilla-xulrunner190-translations less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059480" comment="mozilla-xulrunner190-x86 less than 1.9.0.19-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059481" comment="mozilla-xulrunner190 less than 1.9.0.19-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e687f5d3988822ee23e0bd97566703f8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009059482" comment="MozillaFirefox-translations less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059483" comment="MozillaFirefox less than 3.5.9-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059484" comment="mozilla-xulrunner191-32bit less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059485" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059486" comment="mozilla-xulrunner191-translations less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059487" comment="mozilla-xulrunner191-x86 less than 1.9.1.9-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009059488" comment="mozilla-xulrunner191 less than 1.9.1.9-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100183" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0183</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-0183" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0183" source="CVE"/>
	<description>
	Use-after-free vulnerability in the nsCycleCollector::MarkRoots function in Mozilla Firefox 3.5.x before 3.5.10 and SeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code via a crafted HTML document, related to an improper frame construction process for menus.
	</description>
 </metadata>
<!-- f9b2b1aaa535612c1bff26161e7cb381 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009061668" comment="MozillaFirefox-translations less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061192" comment="MozillaFirefox less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070643" comment="mozilla-xulrunner191-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070644" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061669" comment="mozilla-xulrunner191-translations less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070645" comment="mozilla-xulrunner191-x86 less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061670" comment="mozilla-xulrunner191 less than 1.9.1.10-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100205" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0205</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-0205" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0205" source="CVE"/>
	<description>
	The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before 1.0.53, 1.2.x before 1.2.43, and 1.4.x before 1.4.1 does not properly handle compressed ancillary-chunk data that has a disproportionately large uncompressed representation, which allows remote attackers to cause a denial of service (memory and CPU consumption, and application hang) via a crafted PNG file, as demonstrated by use of the deflate compression method on data composed of many occurrences of the same character, related to a "decompression bomb" attack.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2ff72c65eaac8a3250b7581cf700e537 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060500" comment="libpng12-0-32bit less than 1.2.31-5.13.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060501" comment="libpng12-0-x86 less than 1.2.31-5.13.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060502" comment="libpng12-0 less than 1.2.31-5.13.1"/>
		</criteria>
	</criteria>
	<!-- 39927ae1b61dda08c4e9dac36efc1440 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060500" comment="libpng12-0-32bit less than 1.2.31-5.13.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060501" comment="libpng12-0-x86 less than 1.2.31-5.13.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060502" comment="libpng12-0 less than 1.2.31-5.13.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100211" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0211</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-0211" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0211" source="CVE"/>
	<description>
	The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a modrdn call with an RDN string containing invalid UTF-8 sequences, which triggers a free of an invalid, uninitialized pointer in the slap_mods_free function, as demonstrated using the Codenomicon LDAPv3 test suite.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 3d0b230dddb8bfaf7b9b6420a2be3879 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062031" comment="libldap-2_4-2-32bit less than 2.4.20-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062032" comment="libldap-2_4-2-x86 less than 2.4.20-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062033" comment="libldap-2_4-2 less than 2.4.20-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062034" comment="openldap2-back-meta less than 2.4.20-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062035" comment="openldap2-client less than 2.4.20-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062036" comment="openldap2 less than 2.4.20-0.5.1"/>
		</criteria>
	</criteria>
	<!-- 5d20411a5d0284c2041d73e082cadc62 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062037" comment="libldap-2_4-2-32bit less than 2.4.12-7.19.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062038" comment="libldap-2_4-2-x86 less than 2.4.12-7.19.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062039" comment="libldap-2_4-2 less than 2.4.12-7.19.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062040" comment="openldap2-back-meta less than 2.4.12-7.19.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062041" comment="openldap2-client less than 2.4.12-7.19.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062042" comment="openldap2 less than 2.4.12-7.19.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100212" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0212</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-0212" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0212" source="CVE"/>
	<description>
	OpenLDAP 2.4.22 allows remote attackers to cause a denial of service (crash) via a modrdn call with a zero-length RDN destination string, which is not properly handled by the smr_normalize function and triggers a NULL pointer dereference in the IA5StringNormalize function in schema_init.c, as demonstrated using the Codenomicon LDAPv3 test suite.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 3d0b230dddb8bfaf7b9b6420a2be3879 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062031" comment="libldap-2_4-2-32bit less than 2.4.20-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062032" comment="libldap-2_4-2-x86 less than 2.4.20-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062033" comment="libldap-2_4-2 less than 2.4.20-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062034" comment="openldap2-back-meta less than 2.4.20-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062035" comment="openldap2-client less than 2.4.20-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062036" comment="openldap2 less than 2.4.20-0.5.1"/>
		</criteria>
	</criteria>
	<!-- 5d20411a5d0284c2041d73e082cadc62 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062037" comment="libldap-2_4-2-32bit less than 2.4.12-7.19.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062038" comment="libldap-2_4-2-x86 less than 2.4.12-7.19.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062039" comment="libldap-2_4-2 less than 2.4.12-7.19.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062040" comment="openldap2-back-meta less than 2.4.12-7.19.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062041" comment="openldap2-client less than 2.4.12-7.19.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062042" comment="openldap2 less than 2.4.12-7.19.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100220" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0220</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0220" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0220" source="CVE"/>
	<description>
	The nsObserverList::FillObserverArray function in xpcom/ds/nsObserverList.cpp in Mozilla Firefox before 3.5.7 allows remote attackers to cause a denial of service (application crash) via a crafted web site that triggers memory consumption and an accompanying Low Memory alert dialog, and also triggers attempted removal of an observer from an empty observers array.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 300024d3172356ca0ae65b91542e36fc -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057537" comment="mozilla-xulrunner190-32bit less than 1.9.0.17-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057538" comment="mozilla-xulrunner190-gnomevfs less than 1.9.0.17-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057539" comment="mozilla-xulrunner190-translations less than 1.9.0.17-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057540" comment="mozilla-xulrunner190-x86 less than 1.9.0.17-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057541" comment="mozilla-xulrunner190 less than 1.9.0.17-0.1.1"/>
		</criteria>
	</criteria>
	<!-- c3933fedd02a93f5348103c05533810e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009057542" comment="MozillaFirefox-translations less than 3.5.7-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057543" comment="MozillaFirefox less than 3.5.7-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057544" comment="mozilla-xulrunner191-32bit less than 1.9.1.7-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057545" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.7-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057546" comment="mozilla-xulrunner191-translations less than 1.9.1.7-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057547" comment="mozilla-xulrunner191-x86 less than 1.9.1.7-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009057548" comment="mozilla-xulrunner191 less than 1.9.1.7-1.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100285" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0285</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0285" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0285" source="CVE"/>
	<description>
	gnome-screensaver 2.14.3, 2.22.2, 2.27.x, 2.28.0, and 2.28.3, when the X configuration enables the extend screen option, allows physically proximate attackers to bypass screen locking, access an unattended workstation, and view half of the GNOME desktop by attaching an external monitor.
	</description>
 </metadata>
<!-- f705327a2d63bde40e29516554760c29 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059225" comment="gnome-screensaver-lang less than 2.24.0-14.27.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059226" comment="gnome-screensaver less than 2.24.0-14.27.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100290" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0290</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0290" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0290" source="CVE"/>
	<description>
	Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains (1) CNAME or (2) DNAME records, which do not have the intended validation before caching, aka Bug 20737.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-4022.
	</description>
 </metadata>
<!-- 440b3d1daa2c9fed4b99f7865ea3a906 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009057427" comment="bind-chrootenv less than 9.5.0P2-20.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057428" comment="bind-doc less than 9.5.0P2-20.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057429" comment="bind-libs-32bit less than 9.5.0P2-20.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057430" comment="bind-libs-x86 less than 9.5.0P2-20.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057431" comment="bind-libs less than 9.5.0P2-20.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057432" comment="bind-utils less than 9.5.0P2-20.7.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009057433" comment="bind less than 9.5.0P2-20.7.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100296" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0296</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-0296" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0296" source="CVE"/>
	<description>
	The encode_name macro in misc/mntent_r.c in the GNU C Library (aka glibc or libc6) 2.11.1 and earlier, as used by ncpmount and mount.cifs, does not properly handle newline characters in mountpoint names, which allows local users to cause a denial of service (mtab corruption), or possibly modify mount options and gain privileges, via a crafted mount request.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5f11ad23d76a12882072f1f4032fd9a4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064033" comment="glibc-32bit less than 2.9-13.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064034" comment="glibc-devel-32bit less than 2.9-13.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064035" comment="glibc-devel less than 2.9-13.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064036" comment="glibc-html less than 2.9-13.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064037" comment="glibc-i18ndata less than 2.9-13.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064038" comment="glibc-info less than 2.9-13.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064039" comment="glibc-locale-32bit less than 2.9-13.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064040" comment="glibc-locale less than 2.9-13.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064041" comment="glibc-profile-32bit less than 2.9-13.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064042" comment="glibc-profile less than 2.9-13.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064043" comment="glibc less than 2.9-13.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064044" comment="nscd less than 2.9-13.11.1"/>
		</criteria>
	</criteria>
	<!-- c1fdb4af91c950cd02ba7b76cde49c3b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009070646" comment="glibc-32bit less than 2.11.1-0.18.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070647" comment="glibc-devel-32bit less than 2.11.1-0.18.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070648" comment="glibc-devel less than 2.11.1-0.18.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070649" comment="glibc-html less than 2.11.1-0.18.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070650" comment="glibc-i18ndata less than 2.11.1-0.18.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070651" comment="glibc-info less than 2.11.1-0.18.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070652" comment="glibc-locale-32bit less than 2.11.1-0.18.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070653" comment="glibc-locale-x86 less than 2.11.1-0.18.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070654" comment="glibc-locale less than 2.11.1-0.18.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070655" comment="glibc-profile-32bit less than 2.11.1-0.18.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070656" comment="glibc-profile-x86 less than 2.11.1-0.18.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070657" comment="glibc-profile less than 2.11.1-0.18.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070658" comment="glibc-x86 less than 2.11.1-0.18.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070659" comment="glibc less than 2.11.1-0.18.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070660" comment="nscd less than 2.11.1-0.18.2"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100302" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0302</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0302" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0302" source="CVE"/>
	<description>
	Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS before 1.4.4, when kqueue or epoll is used, allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, related to improperly maintaining a reference count. NOTE: some of these details are obtained from third party information. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-3553.
	</description>
 </metadata>
<!-- a3fa76d8e915d3f22a35726188aa910b -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009058941" comment="cups-client less than 1.3.9-8.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058942" comment="cups-libs-32bit less than 1.3.9-8.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058943" comment="cups-libs-x86 less than 1.3.9-8.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058944" comment="cups-libs less than 1.3.9-8.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058945" comment="cups less than 1.3.9-8.30.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100304" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0304</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0304" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0304" source="CVE"/>
	<description>
	Multiple buffer overflows in the LWRES dissector in Wireshark 0.9.15 through 1.0.10 and 1.2.0 through 1.2.5 allow remote attackers to cause a denial of service (crash) via a malformed packet, as demonstrated using a stack-based buffer overflow to the dissect_getaddrsbyname_request function.
	</description>
 </metadata>
<!-- 963ff40259d4863a011be226650534cb -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058844" comment="wireshark less than 1.0.5-1.34.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100307" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0307</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0307" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0307" source="CVE"/>
	<description>
	The load_elf_binary function in fs/binfmt_elf.c in the Linux kernel before 2.6.32.8 on the x86_64 platform does not ensure that the ELF interpreter is available before a call to the SET_PERSONALITY macro, which allows local users to cause a denial of service (system crash) via a 32-bit application that attempts to execute a 64-bit application and then triggers a segmentation fault, as demonstrated by amd64_killer, related to the flush_old_exec function.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1cc9f9878be828ca9494ad136beab1d1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 5bc8b282021bec5a0602dd1e1fb86cc0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058496" comment="ext4dev-kmp-xen less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 8de370e0ec03088da9aa16f31064b5c4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058499" comment="ext4dev-kmp-pae less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058500" comment="ext4dev-kmp-vmi less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058496" comment="ext4dev-kmp-xen less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058501" comment="kernel-pae-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058502" comment="kernel-pae less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058503" comment="kernel-vmi-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058504" comment="kernel-vmi less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- b6015de562091b64634bc48dd8f9db1a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058505" comment="kernel-default-man less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e5c7588310814dc753e7fc885f8955fb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058506" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058507" comment="kernel-kdump less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058508" comment="kernel-ppc64-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058509" comment="kernel-ppc64 less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100308" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0308</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0308" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0308" source="CVE"/>
	<description>
	lib/rfc1035.c in Squid 2.x, 3.0 through 3.0.STABLE22, and 3.1 through 3.1.0.15 allows remote attackers to cause a denial of service (assertion failure) via a crafted DNS packet that only contains a header.
	</description>
 </metadata>
<!-- e7ccdbbe46c91059fa6548099ec50325 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059011" comment="squid less than 2.7.STABLE5-2.4.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100393" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0393</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0393" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0393" source="CVE"/>
	<description>
	The _cupsGetlang function, as used by lppasswd.c in lppasswd in CUPS 1.2.2, 1.3.7, 1.3.9, and 1.4.1, relies on an environment variable to determine the file that provides localized message strings, which allows local users to gain privileges via a file that contains crafted localization data with format string specifiers.
	</description>
 </metadata>
<!-- a3fa76d8e915d3f22a35726188aa910b -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009058941" comment="cups-client less than 1.3.9-8.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058942" comment="cups-libs-32bit less than 1.3.9-8.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058943" comment="cups-libs-x86 less than 1.3.9-8.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058944" comment="cups-libs less than 1.3.9-8.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058945" comment="cups less than 1.3.9-8.30.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100395" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0395</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-0395" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0395" source="CVE"/>
	<description>
	OpenOffice.org 2.x and 3.0 before 3.2.1 allows user-assisted remote attackers to bypass Python macro security restrictions and execute arbitrary Python code via a crafted OpenDocument Text (ODT) file that triggers code execution when the macro directory structure is previewed.
	</description>
 </metadata>
<!-- 487e402b82edcff0b929d3dc16a55c82 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009061429" comment="libpython2_6-1_0-32bit less than 2.6.0-8.9.20"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061430" comment="libpython2_6-1_0 less than 2.6.0-8.9.20"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100397" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0397</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-0397" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0397" source="CVE"/>
	<description>
	The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly have unspecified other impact via a crafted argument.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 192c274ce8afb5e5f6a207e8c4e39e5d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062323" comment="apache2-mod_php5 less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062324" comment="php5-bcmath less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062325" comment="php5-bz2 less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062326" comment="php5-calendar less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062327" comment="php5-ctype less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062328" comment="php5-curl less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062329" comment="php5-dba less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062330" comment="php5-dbase less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062331" comment="php5-dom less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062332" comment="php5-exif less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062333" comment="php5-fastcgi less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062334" comment="php5-ftp less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062335" comment="php5-gd less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062336" comment="php5-gettext less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062337" comment="php5-gmp less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062338" comment="php5-hash less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062339" comment="php5-iconv less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062340" comment="php5-json less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062341" comment="php5-ldap less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062342" comment="php5-mbstring less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062343" comment="php5-mcrypt less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062344" comment="php5-mysql less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062345" comment="php5-odbc less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062346" comment="php5-openssl less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062347" comment="php5-pcntl less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062348" comment="php5-pdo less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062349" comment="php5-pear less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062350" comment="php5-pgsql less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062351" comment="php5-pspell less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062352" comment="php5-shmop less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062353" comment="php5-snmp less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062354" comment="php5-soap less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062355" comment="php5-suhosin less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062356" comment="php5-sysvmsg less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062357" comment="php5-sysvsem less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062358" comment="php5-sysvshm less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062359" comment="php5-tokenizer less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062360" comment="php5-wddx less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062361" comment="php5-xmlreader less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062362" comment="php5-xmlrpc less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062363" comment="php5-xmlwriter less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062364" comment="php5-xsl less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062365" comment="php5-zip less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062366" comment="php5-zlib less than 5.2.14-0.1.1"/>
		</criteria>
	</criteria>
	<!-- d9f07e551f70d0ed3756c02a021f2fec -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062323" comment="apache2-mod_php5 less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062324" comment="php5-bcmath less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062325" comment="php5-bz2 less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062326" comment="php5-calendar less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062327" comment="php5-ctype less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062328" comment="php5-curl less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062329" comment="php5-dba less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062330" comment="php5-dbase less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062331" comment="php5-dom less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062332" comment="php5-exif less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062333" comment="php5-fastcgi less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062334" comment="php5-ftp less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062335" comment="php5-gd less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062336" comment="php5-gettext less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062337" comment="php5-gmp less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062338" comment="php5-hash less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062339" comment="php5-iconv less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062340" comment="php5-json less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062341" comment="php5-ldap less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062342" comment="php5-mbstring less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062343" comment="php5-mcrypt less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062344" comment="php5-mysql less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062345" comment="php5-odbc less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062346" comment="php5-openssl less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062347" comment="php5-pcntl less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062348" comment="php5-pdo less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062349" comment="php5-pear less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062350" comment="php5-pgsql less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062351" comment="php5-pspell less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062352" comment="php5-shmop less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062353" comment="php5-snmp less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062354" comment="php5-soap less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062355" comment="php5-suhosin less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062356" comment="php5-sysvmsg less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062357" comment="php5-sysvsem less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062358" comment="php5-sysvshm less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062359" comment="php5-tokenizer less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062360" comment="php5-wddx less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062361" comment="php5-xmlreader less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062362" comment="php5-xmlrpc less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062363" comment="php5-xmlwriter less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062364" comment="php5-xsl less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062365" comment="php5-zip less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062366" comment="php5-zlib less than 5.2.14-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100405" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0405</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-0405" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0405" source="CVE"/>
	<description>
	Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and libbzip2 before 1.0.6 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted compressed file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 123cd276cbae1468f2b50c9cef92be0a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063184" comment="bzip2-doc less than 1.0.5-34.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063185" comment="bzip2 less than 1.0.5-34.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063186" comment="libbz2-1-32bit less than 1.0.5-34.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063187" comment="libbz2-1-x86 less than 1.0.5-34.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063188" comment="libbz2-1 less than 1.0.5-34.1.1"/>
		</criteria>
	</criteria>
	<!-- 5e3804e832da6c82fc607378dd2897e6 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063184" comment="bzip2-doc less than 1.0.5-34.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063185" comment="bzip2 less than 1.0.5-34.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063186" comment="libbz2-1-32bit less than 1.0.5-34.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063187" comment="libbz2-1-x86 less than 1.0.5-34.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063188" comment="libbz2-1 less than 1.0.5-34.1.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063184" comment="bzip2-doc less than 1.0.5-34.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063185" comment="bzip2 less than 1.0.5-34.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063186" comment="libbz2-1-32bit less than 1.0.5-34.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063188" comment="libbz2-1 less than 1.0.5-34.1.1"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100407" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0407</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-0407" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0407" source="CVE"/>
	<description>
	Multiple buffer overflows in the MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 allow local users to gain privileges via crafted message data, which is improperly demarshalled.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1aae07165beeecaf80a4ad95aea3dafa -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009070661" comment="pcsc-lite-32bit less than 1.4.102-1.31.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070662" comment="pcsc-lite-x86 less than 1.4.102-1.31.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063350" comment="pcsc-lite less than 1.4.102-1.31.2"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009070661" comment="pcsc-lite-32bit less than 1.4.102-1.31.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063350" comment="pcsc-lite less than 1.4.102-1.31.2"/>
			</criteria>
		</criteria></criteria>
	<!-- e9cad3b00872763bd334e851d50993b2 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062627" comment="pcsc-lite-32bit less than 1.4.102-1.31.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062628" comment="pcsc-lite-x86 less than 1.4.102-1.31.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062629" comment="pcsc-lite less than 1.4.102-1.31.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100408" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0408</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0408" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0408" source="CVE"/>
	<description>
	The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain situations in which a client sends no request body, which allows remote attackers to cause a denial of service (backend server outage) via a crafted request, related to use of a 500 error code instead of the appropriate 400 error code.
	</description>
 </metadata>
<!-- 57330fac6ee35b7c97ac319b9d8c934e -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059864" comment="apache2-doc less than 2.2.10-2.23.22.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059865" comment="apache2-example-pages less than 2.2.10-2.23.22.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059866" comment="apache2-prefork less than 2.2.10-2.23.22.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059867" comment="apache2-utils less than 2.2.10-2.23.22.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059868" comment="apache2-worker less than 2.2.10-2.23.22.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059869" comment="apache2 less than 2.2.10-2.23.22.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100409" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0409</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0409" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0409" source="CVE"/>
	<description>
	Buffer overflow in the GMIME_UUENCODE_LEN macro in gmime/gmime-encodings.h in GMime before 2.4.15 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via input data for a uuencode operation.
	</description>
 </metadata>
<!-- 4a50644a493369f63a3b64e93a29e6c7 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009058363" comment="gmime-doc less than 2.2.23-1.41.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058364" comment="gmime less than 2.2.23-1.41.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058365" comment="libgmime-2_0-3 less than 2.2.23-1.41.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100410" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0410</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0410" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0410" source="CVE"/>
	<description>
	drivers/connector/connector.c in the Linux kernel before 2.6.32.8 allows local users to cause a denial of service (memory consumption and system crash) by sending the kernel many NETLINK_CONNECTOR messages.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1cc9f9878be828ca9494ad136beab1d1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 5bc8b282021bec5a0602dd1e1fb86cc0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058496" comment="ext4dev-kmp-xen less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 8de370e0ec03088da9aa16f31064b5c4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058499" comment="ext4dev-kmp-pae less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058500" comment="ext4dev-kmp-vmi less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058496" comment="ext4dev-kmp-xen less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058501" comment="kernel-pae-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058502" comment="kernel-pae less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058503" comment="kernel-vmi-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058504" comment="kernel-vmi less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- b6015de562091b64634bc48dd8f9db1a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058505" comment="kernel-default-man less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e5c7588310814dc753e7fc885f8955fb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058506" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058507" comment="kernel-kdump less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058508" comment="kernel-ppc64-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058509" comment="kernel-ppc64 less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100411" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0411</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0411" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0411" source="CVE"/>
	<description>
	Multiple integer signedness errors in the (1) __get_argv and (2) __get_compat_argv functions in tapset/aux_syscalls.stp in SystemTap 1.1 allow local users to cause a denial of service (script crash, or system crash or hang) via a process with a large number of arguments, leading to a buffer overflow.
	</description>
 </metadata>
<!-- 1b6f8b3aba0a4600d503d94dd164ad1a -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061867" comment="systemtap less than 0.7.1-42.5.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100415" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0415</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0415" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0415" source="CVE"/>
	<description>
	The do_pages_move function in mm/migrate.c in the Linux kernel before 2.6.33-rc7 does not validate node values, which allows local users to read arbitrary kernel memory locations, cause a denial of service (OOPS), and possibly have unspecified other impact by specifying a node that is not part of the kernel's node set.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1cc9f9878be828ca9494ad136beab1d1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 5bc8b282021bec5a0602dd1e1fb86cc0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058496" comment="ext4dev-kmp-xen less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 8de370e0ec03088da9aa16f31064b5c4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058499" comment="ext4dev-kmp-pae less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058500" comment="ext4dev-kmp-vmi less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058496" comment="ext4dev-kmp-xen less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058501" comment="kernel-pae-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058502" comment="kernel-pae less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058503" comment="kernel-vmi-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058504" comment="kernel-vmi less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- b6015de562091b64634bc48dd8f9db1a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058505" comment="kernel-default-man less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e5c7588310814dc753e7fc885f8955fb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058506" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058507" comment="kernel-kdump less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058508" comment="kernel-ppc64-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058509" comment="kernel-ppc64 less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100424" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0424</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0424" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0424" source="CVE"/>
	<description>
	The edit_cmd function in crontab.c in (1) cronie before 1.4.4 and (2) Vixie cron (vixie-cron) allows local users to change the modification times of arbitrary files, and consequently cause a denial of service, via a symlink attack on a temporary file in the /tmp directory.
	</description>
 </metadata>
<!-- 7cf9f62c2ff35beb69feaf4d1bce62d8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058917" comment="cron less than 4.1-194.19.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100426" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0426</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0426" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0426" source="CVE"/>
	<description>
	sudo 1.6.x before 1.6.9p21 and 1.7.x before 1.7.2p4, when a pseudo-command is enabled, permits a match between the name of the pseudo-command and the name of an executable file in an arbitrary directory, which allows local users to gain privileges via a crafted executable file, as demonstrated by a file named sudoedit in a user's home directory.
	</description>
 </metadata>
<!-- c8c6fbc73a661cae2a40cf505fb5aa0b -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058612" comment="sudo less than 1.6.9p17-21.3.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100427" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0427</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0427" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0427" source="CVE"/>
	<description>
	sudo 1.6.x before 1.6.9p21, when the runas_default option is used, does not properly set group memberships, which allows local users to gain privileges via a sudo command.
	</description>
 </metadata>
<!-- c8c6fbc73a661cae2a40cf505fb5aa0b -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009058612" comment="sudo less than 1.6.9p17-21.3.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100434" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0434</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0434" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0434" source="CVE"/>
	<description>
	The ap_read_request function in server/protocol.c in the Apache HTTP Server 2.2.x before 2.2.15, when a multithreaded MPM is used, does not properly handle headers in subrequests in certain circumstances involving a parent request that has a body, which might allow remote attackers to obtain sensitive information via a crafted request that triggers access to memory locations associated with an earlier request.
	</description>
 </metadata>
<!-- 57330fac6ee35b7c97ac319b9d8c934e -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059864" comment="apache2-doc less than 2.2.10-2.23.22.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059865" comment="apache2-example-pages less than 2.2.10-2.23.22.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059866" comment="apache2-prefork less than 2.2.10-2.23.22.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059867" comment="apache2-utils less than 2.2.10-2.23.22.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059868" comment="apache2-worker less than 2.2.10-2.23.22.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059869" comment="apache2 less than 2.2.10-2.23.22.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100436" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0436</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0436" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0436" source="CVE"/>
	<description>
	Race condition in backend/ctrl.c in KDM in KDE Software Compilation (SC) 2.2.0 through 4.4.2 allows local users to change the permissions of arbitrary files, and consequently gain privileges, by blocking the removal of a certain directory that contains a control socket, related to improper interaction with ksm.
	</description>
 </metadata>
<!-- ab2f899bb4f8e06c4770285b8bdb7fbf -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059657" comment="kde4-kdm less than 4.1.3-18.8.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059658" comment="kde4-kgreeter-plugins less than 4.1.3-18.8.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059659" comment="kde4-kwin less than 4.1.3-18.8.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059660" comment="kdebase4-workspace-ksysguardd less than 4.1.3-18.8.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059661" comment="kdebase4-workspace less than 4.1.3-18.8.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100540" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0540</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for Teradata</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-0540" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0540" source="CVE"/>
	<description>
	Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, allows remote attackers to hijack the authentication of administrators for requests that change settings.
	</description>
 </metadata>
<!-- e50c58ccd03dea996e547017df4bffff -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009070956" comment="cups-client less than 1.3.9-8.44.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070957" comment="cups-libs-32bit less than 1.3.9-8.44.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070958" comment="cups-libs-x86 less than 1.3.9-8.44.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070959" comment="cups-libs less than 1.3.9-8.44.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070960" comment="cups less than 1.3.9-8.44.1"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009070956" comment="cups-client less than 1.3.9-8.44.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070957" comment="cups-libs-32bit less than 1.3.9-8.44.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070959" comment="cups-libs less than 1.3.9-8.44.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070960" comment="cups less than 1.3.9-8.44.1"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100541" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0541</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-0541" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0541" source="CVE"/>
	<description>
	Cross-site scripting (XSS) vulnerability in the WEBrick HTTP server in Ruby in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, allows remote attackers to inject arbitrary web script or HTML via a crafted URI that triggers a UTF-7 error page.
	</description>
 </metadata>
<!-- 5087d31530e2994f4eda91fda3425c12 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009068617" comment="ruby-doc-html less than 1.8.7.p72-5.28.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009068618" comment="ruby-tk less than 1.8.7.p72-5.28.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009068619" comment="ruby less than 1.8.7.p72-5.28.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100542" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0542</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-0542" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0542" source="CVE"/>
	<description>
	The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem in CUPS before 1.4.4 does not check the return values of certain calloc calls, which allows remote attackers to cause a denial of service (NULL pointer dereference or heap memory corruption) or possibly execute arbitrary code via a crafted file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- d603aeff8a309d9d04651d4469e31973 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064776" comment="cups-client less than 1.3.9-8.37.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064777" comment="cups-libs-32bit less than 1.3.9-8.37.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064778" comment="cups-libs-x86 less than 1.3.9-8.37.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064779" comment="cups-libs less than 1.3.9-8.37.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064780" comment="cups less than 1.3.9-8.37.1"/>
		</criteria>
	</criteria>
	<!-- e290f3059978b800480c09727b4b714a -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064776" comment="cups-client less than 1.3.9-8.37.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064777" comment="cups-libs-32bit less than 1.3.9-8.37.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064778" comment="cups-libs-x86 less than 1.3.9-8.37.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064779" comment="cups-libs less than 1.3.9-8.37.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064780" comment="cups less than 1.3.9-8.37.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064776" comment="cups-client less than 1.3.9-8.37.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064777" comment="cups-libs-32bit less than 1.3.9-8.37.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064779" comment="cups-libs less than 1.3.9-8.37.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064780" comment="cups less than 1.3.9-8.37.1"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100547" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0547</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0547" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0547" source="CVE"/>
	<description>
	client/mount.cifs.c in mount.cifs in smbfs in Samba 3.4.5 and earlier does not verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of service (mtab corruption) via a crafted string.
	</description>
 </metadata>
<!-- dcc8a519c5c6d5ce485655060c83d71a -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059012" comment="cifs-mount less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059013" comment="ldapsmb less than 1.34b-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059014" comment="libsmbclient0-32bit less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059015" comment="libsmbclient0-x86 less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059016" comment="libsmbclient0 less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059017" comment="libtalloc1-32bit less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059018" comment="libtalloc1-x86 less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059019" comment="libtalloc1 less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059020" comment="libtdb1-32bit less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059021" comment="libtdb1-x86 less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059022" comment="libtdb1 less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059023" comment="libwbclient0-32bit less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059024" comment="libwbclient0-x86 less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059025" comment="libwbclient0 less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059026" comment="samba-32bit less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059027" comment="samba-client-32bit less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059028" comment="samba-client-x86 less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059029" comment="samba-client less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059030" comment="samba-krb-printing less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059031" comment="samba-winbind-32bit less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059032" comment="samba-winbind-x86 less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059033" comment="samba-winbind less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059034" comment="samba-x86 less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059035" comment="samba less than 3.2.7-11.9.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100622" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0622</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0622" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0622" source="CVE"/>
	<description>
	The wake_futex_pi function in kernel/futex.c in the Linux kernel before 2.6.33-rc7 does not properly handle certain unlock operations for a Priority Inheritance (PI) futex, which allows local users to cause a denial of service (OOPS) and possibly have unspecified other impact via vectors involving modification of the futex value from user space.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1cc9f9878be828ca9494ad136beab1d1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 5bc8b282021bec5a0602dd1e1fb86cc0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058496" comment="ext4dev-kmp-xen less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 8de370e0ec03088da9aa16f31064b5c4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058499" comment="ext4dev-kmp-pae less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058500" comment="ext4dev-kmp-vmi less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058496" comment="ext4dev-kmp-xen less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058501" comment="kernel-pae-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058502" comment="kernel-pae less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058503" comment="kernel-vmi-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058504" comment="kernel-vmi less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- b6015de562091b64634bc48dd8f9db1a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058505" comment="kernel-default-man less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e5c7588310814dc753e7fc885f8955fb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058506" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058507" comment="kernel-kdump less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058508" comment="kernel-ppc64-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058509" comment="kernel-ppc64 less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100624" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0624</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0624" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0624" source="CVE"/>
	<description>
	Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.11 allows remote rmt servers to cause a denial of service (memory corruption) or possibly execute arbitrary code by sending more data than was requested, related to archive filenames that contain a : (colon) character.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- a8068f50be3aa5856bfbafbb986ccede -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060021" comment="tar less than 1.20-23.23.1"/>
	</criteria>
	<!-- b00019e2d90a9075cadf119bab5ef806 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060050" comment="cpio-lang less than 2.9-75.27.24.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060051" comment="cpio less than 2.9-75.27.24.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100629" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0629</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0629" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0629" source="CVE"/>
	<description>
	Use-after-free vulnerability in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote authenticated users to cause a denial of service (daemon crash) via a request from a kadmin client that sends an invalid API version number.
	</description>
 </metadata>
<!-- b80f25d43febd27bf80775d0df4efc48 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059523" comment="krb5-32bit less than 1.6.3-133.27.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059524" comment="krb5-apps-clients less than 1.6.3-133.27.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059525" comment="krb5-apps-servers less than 1.6.3-133.27.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059526" comment="krb5-client less than 1.6.3-133.27.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059527" comment="krb5-server less than 1.6.3-133.27.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059528" comment="krb5-x86 less than 1.6.3-133.27.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059529" comment="krb5 less than 1.6.3-133.27.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100639" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0639</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for Teradata</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-0639" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0639" source="CVE"/>
	<description>
	The htcpHandleTstRequest function in htcp.c in Squid 2.x before 2.6.STABLE24 and 2.7 before 2.7.STABLE8, and htcp.cc in 3.0 before 3.0.STABLE24, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via crafted packets to the HTCP port.
	</description>
 </metadata>
<!-- 33ea09ca8f99a79e086ea4de5ad83dcd -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009072757" comment="squid less than 2.7.STABLE5-2.10.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100654" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0654</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-0654" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0654" source="CVE"/>
	<description>
	Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 permit cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote attackers to obtain sensitive information via a crafted document.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0d0d8706df2d64128121ceea3338a129 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061813" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
	<!-- f23d3ef3410fecb23cf62a058d285514 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061813" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100732" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0732</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0732" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0732" source="CVE"/>
	<description>
	gdk/gdkwindow.c in GTK+ before 2.18.5, as used in gnome-screensaver before 2.28.1, performs implicit paints on windows of type GDK_WINDOW_FOREIGN, which triggers an X error in certain circumstances and consequently allows physically proximate attackers to bypass screen locking and access an unattended workstation by pressing the Enter key many times.
	</description>
 </metadata>
<!-- f705327a2d63bde40e29516554760c29 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059225" comment="gnome-screensaver-lang less than 2.24.0-14.27.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059226" comment="gnome-screensaver less than 2.24.0-14.27.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100733" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0733</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-0733" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0733" source="CVE"/>
	<description>
	Integer overflow in src/backend/executor/nodeHash.c in PostgreSQL 8.4.1 and earlier, and 8.5 through 8.5alpha2, allows remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with many LEFT JOIN clauses, related to certain hashtable size calculations.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1623a9038b26e4b2fb345e388ebf6ca9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061271" comment="postgresql-contrib less than 8.3.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061272" comment="postgresql-docs less than 8.3.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061273" comment="postgresql-libs-32bit less than 8.3.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061274" comment="postgresql-libs-x86 less than 8.3.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061275" comment="postgresql-libs less than 8.3.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061276" comment="postgresql-server less than 8.3.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061277" comment="postgresql less than 8.3.11-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 3583616cbc2a604051aee34d4ba07c2c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061277" comment="postgresql less than 8.3.11-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100743" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0743</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-0743" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0743" source="CVE"/>
	<description>
	Multiple format string vulnerabilities in isns.c in (1) Linux SCSI target framework (aka tgt or scsi-target-utils) 1.0.3, 0.9.5, and earlier and (2) iSCSI Enterprise Target (aka iscsitarget) 0.4.16 allow remote attackers to cause a denial of service (tgtd daemon crash) or possibly have unspecified other impact via vectors that involve the isns_attr_query and qry_rsp_handle functions, and are related to (a) client appearance and (b) client disappearance messages.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1d0f181fabeecec7ee58bfd9c3780c48 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062375" comment="tgt less than 0.9.0-1.27.1"/>
	</criteria>
	<!-- 204272c38ed26d94a6c1cfc810001299 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062376" comment="tgt less than 0.9.10-0.6.1"/>
	</criteria>
	<!-- 4e58ced289f629acb8d772b382ef45d5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062377" comment="iscsitarget-kmp-default less than 0.4.15_2.6.27.48_0.6-94.14.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062378" comment="iscsitarget-kmp-pae less than 0.4.15_2.6.27.48_0.6-94.14.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062379" comment="iscsitarget-kmp-ppc64 less than 0.4.15_2.6.27.48_0.6-94.14.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062380" comment="iscsitarget-kmp-vmi less than 0.4.15_2.6.27.48_0.6-94.14.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062381" comment="iscsitarget-kmp-xen less than 0.4.15_2.6.27.48_0.6-94.14.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062382" comment="iscsitarget less than 0.4.15-94.14.1"/>
		</criteria>
	</criteria>
	<!-- b2720d1cb13b664616006efc437aaeb0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062383" comment="iscsitarget-kmp-default less than 1.4.19_2.6.32.13_0.5-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062384" comment="iscsitarget-kmp-pae less than 1.4.19_2.6.32.13_0.5-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062385" comment="iscsitarget-kmp-ppc64 less than 1.4.19_2.6.32.13_0.5-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062386" comment="iscsitarget-kmp-xen less than 1.4.19_2.6.32.13_0.5-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062387" comment="iscsitarget less than 1.4.19-0.7.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100771" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0771</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Java 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-0771" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0771" source="CVE"/>
	<description>
	** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.
	</description>
 </metadata>
<!-- 99e3a681bfd3aa624a61230811cf88e5 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009065622" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr9.0-0.2.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009065623" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr9.0-0.2.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009065624" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr9.0-0.2.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009065625" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr9.0-0.2.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009065626" comment="java-1_6_0-ibm less than 1.6.0_sr9.0-0.2.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100787" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0787</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0787" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0787" source="CVE"/>
	<description>
	client/mount.cifs.c in mount.cifs in smbfs in Samba 3.0.22, 3.0.28a, 3.2.3, 3.3.2, 3.4.0, and 3.4.5 allows local users to mount a CIFS share on an arbitrary mountpoint, and gain privileges, via a symlink attack on the mountpoint directory file.
	</description>
 </metadata>
<!-- 38b274074b3d5ef4abafff31fa80e561 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060901" comment="cifs-mount less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060902" comment="ldapsmb less than 1.34b-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060903" comment="libsmbclient0-32bit less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060904" comment="libsmbclient0-x86 less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060905" comment="libsmbclient0 less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060906" comment="libtalloc1-32bit less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060907" comment="libtalloc1-x86 less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060908" comment="libtalloc1 less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060909" comment="libtdb1-32bit less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060910" comment="libtdb1-x86 less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060911" comment="libtdb1 less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060912" comment="libwbclient0-32bit less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060913" comment="libwbclient0-x86 less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060914" comment="libwbclient0 less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060915" comment="samba-32bit less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060916" comment="samba-client-32bit less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060917" comment="samba-client-x86 less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060918" comment="samba-client less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060919" comment="samba-krb-printing less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060920" comment="samba-winbind-32bit less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060921" comment="samba-winbind-x86 less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060922" comment="samba-winbind less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060923" comment="samba-x86 less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060924" comment="samba less than 3.2.7-11.20.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100830" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0830</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-0830" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0830" source="CVE"/>
	<description>
	Integer signedness error in the elf_get_dynamic_info function in elf/dynamic-link.h in ld.so in the GNU C Library (aka glibc or libc6) 2.0.1 through 2.11.1, when the --verify option is used, allows user-assisted remote attackers to execute arbitrary code via a crafted ELF program with a negative value for a certain d_tag structure member in the ELF header.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5f11ad23d76a12882072f1f4032fd9a4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064033" comment="glibc-32bit less than 2.9-13.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064034" comment="glibc-devel-32bit less than 2.9-13.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064035" comment="glibc-devel less than 2.9-13.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064036" comment="glibc-html less than 2.9-13.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064037" comment="glibc-i18ndata less than 2.9-13.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064038" comment="glibc-info less than 2.9-13.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064039" comment="glibc-locale-32bit less than 2.9-13.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064040" comment="glibc-locale less than 2.9-13.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064041" comment="glibc-profile-32bit less than 2.9-13.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064042" comment="glibc-profile less than 2.9-13.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064043" comment="glibc less than 2.9-13.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064044" comment="nscd less than 2.9-13.11.1"/>
		</criteria>
	</criteria>
	<!-- c1fdb4af91c950cd02ba7b76cde49c3b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009070646" comment="glibc-32bit less than 2.11.1-0.18.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070647" comment="glibc-devel-32bit less than 2.11.1-0.18.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070648" comment="glibc-devel less than 2.11.1-0.18.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070649" comment="glibc-html less than 2.11.1-0.18.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070650" comment="glibc-i18ndata less than 2.11.1-0.18.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070651" comment="glibc-info less than 2.11.1-0.18.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070652" comment="glibc-locale-32bit less than 2.11.1-0.18.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070653" comment="glibc-locale-x86 less than 2.11.1-0.18.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070654" comment="glibc-locale less than 2.11.1-0.18.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070655" comment="glibc-profile-32bit less than 2.11.1-0.18.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070656" comment="glibc-profile-x86 less than 2.11.1-0.18.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070657" comment="glibc-profile less than 2.11.1-0.18.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070658" comment="glibc-x86 less than 2.11.1-0.18.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070659" comment="glibc less than 2.11.1-0.18.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070660" comment="nscd less than 2.11.1-0.18.2"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100837" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0837</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Java 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-0837" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0837" source="CVE"/>
	<description>
	Unspecified vulnerability in the Pack200 component in Oracle Java SE and Java for Business 6 Update 18, 5.0, Update, and 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 22b7b43ee38cfc5dac6ddc1fad1d45e5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061078" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061079" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061080" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061081" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061082" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.7.1"/>
		</criteria>
	</criteria>
	<!-- a1c03b73aa6d1ead4ac038bf35d86be9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061083" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061084" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061085" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061086" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061087" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.1.2"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100838" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0838</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Java 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-0838" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0838" source="CVE"/>
	<description>
	Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0, Update, and 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is a stack-based buffer overflow using an untrusted size value in the readMabCurveData function in the CMM module in the JVM.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 22b7b43ee38cfc5dac6ddc1fad1d45e5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061078" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061079" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061080" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061081" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061082" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.7.1"/>
		</criteria>
	</criteria>
	<!-- a1c03b73aa6d1ead4ac038bf35d86be9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061083" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061084" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061085" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061086" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061087" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.1.2"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100839" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0839</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Java 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>sles11-java.i386</platform>
		<platform>sles11-java.ia64</platform>
		<platform>sles11-java.ppc64</platform>
		<platform>sles11-java.s390x</platform>
		<platform>sles11-java.x86_64</platform>
	</affected>
	<reference ref_id="CVE-2010-0839" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0839" source="CVE"/>
	<description>
	Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 12597bfedbb46982a7db921e22529a3f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062167" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062168" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062169" comment="java-1_4_2-ibm less than 1.4.2_sr13.5-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 22b7b43ee38cfc5dac6ddc1fad1d45e5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061078" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061079" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061080" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061081" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061082" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.7.1"/>
		</criteria>
	</criteria>
	<!-- 86f8e0835cea2b76091e1f68f65ed768 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062167" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062168" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062169" comment="java-1_4_2-ibm less than 1.4.2_sr13.5-0.1.1"/>
		</criteria>
	</criteria>
	<!-- a1c03b73aa6d1ead4ac038bf35d86be9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061083" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061084" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061085" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061086" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061087" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.1.2"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100840" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0840</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Java 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>sles11-java.i386</platform>
		<platform>sles11-java.ia64</platform>
		<platform>sles11-java.ppc64</platform>
		<platform>sles11-java.s390x</platform>
		<platform>sles11-java.x86_64</platform>
	</affected>
	<reference ref_id="CVE-2010-0840" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0840" source="CVE"/>
	<description>
	Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is related to improper checks when executing privileged methods in the Java Runtime Environment (JRE), which allows attackers to execute arbitrary code via (1) an untrusted object that extends the trusted class but has not modified a certain method, or (2) "a similar trust issue with interfaces," aka "Trusted Methods Chaining Remote Code Execution Vulnerability."
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 12597bfedbb46982a7db921e22529a3f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062167" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062168" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062169" comment="java-1_4_2-ibm less than 1.4.2_sr13.5-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 22b7b43ee38cfc5dac6ddc1fad1d45e5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061078" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061079" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061080" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061081" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061082" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.7.1"/>
		</criteria>
	</criteria>
	<!-- 86f8e0835cea2b76091e1f68f65ed768 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062167" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062168" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062169" comment="java-1_4_2-ibm less than 1.4.2_sr13.5-0.1.1"/>
		</criteria>
	</criteria>
	<!-- a1c03b73aa6d1ead4ac038bf35d86be9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061083" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061084" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061085" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061086" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061087" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.1.2"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100841" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0841</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Java 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>sles11-java.i386</platform>
		<platform>sles11-java.ia64</platform>
		<platform>sles11-java.ppc64</platform>
		<platform>sles11-java.s390x</platform>
		<platform>sles11-java.x86_64</platform>
	</affected>
	<reference ref_id="CVE-2010-0841" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0841" source="CVE"/>
	<description>
	Unspecified vulnerability in the ImageIO component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is an integer overflow in the Java Runtime Environment that allows remote attackers to execute arbitrary code via a JPEG image that contains subsample dimensions with large values, related to JPEGImageReader and "stepX".
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 12597bfedbb46982a7db921e22529a3f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062167" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062168" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062169" comment="java-1_4_2-ibm less than 1.4.2_sr13.5-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 22b7b43ee38cfc5dac6ddc1fad1d45e5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061078" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061079" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061080" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061081" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061082" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.7.1"/>
		</criteria>
	</criteria>
	<!-- 86f8e0835cea2b76091e1f68f65ed768 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062167" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062168" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062169" comment="java-1_4_2-ibm less than 1.4.2_sr13.5-0.1.1"/>
		</criteria>
	</criteria>
	<!-- a1c03b73aa6d1ead4ac038bf35d86be9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061083" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061084" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061085" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061086" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061087" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.1.2"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100842" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0842</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Java 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>sles11-java.i386</platform>
		<platform>sles11-java.ia64</platform>
		<platform>sles11-java.ppc64</platform>
		<platform>sles11-java.s390x</platform>
		<platform>sles11-java.x86_64</platform>
	</affected>
	<reference ref_id="CVE-2010-0842" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0842" source="CVE"/>
	<description>
	Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is an uncontrolled array index that allows remote attackers to execute arbitrary code via a MIDI file with a crafted MixerSequencer object, related to the GM_Song structure.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 12597bfedbb46982a7db921e22529a3f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062167" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062168" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062169" comment="java-1_4_2-ibm less than 1.4.2_sr13.5-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 22b7b43ee38cfc5dac6ddc1fad1d45e5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061078" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061079" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061080" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061081" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061082" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.7.1"/>
		</criteria>
	</criteria>
	<!-- 86f8e0835cea2b76091e1f68f65ed768 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062167" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062168" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062169" comment="java-1_4_2-ibm less than 1.4.2_sr13.5-0.1.1"/>
		</criteria>
	</criteria>
	<!-- a1c03b73aa6d1ead4ac038bf35d86be9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061083" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061084" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061085" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061086" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061087" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.1.2"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100843" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0843</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Java 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>sles11-java.i386</platform>
		<platform>sles11-java.ia64</platform>
		<platform>sles11-java.ppc64</platform>
		<platform>sles11-java.s390x</platform>
		<platform>sles11-java.x86_64</platform>
	</affected>
	<reference ref_id="CVE-2010-0843" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0843" source="CVE"/>
	<description>
	Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is related to XNewPtr and improper handling of an integer parameter when allocating heap memory in the com.sun.media.sound libraries, which allows remote attackers to execute arbitrary code.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 12597bfedbb46982a7db921e22529a3f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062167" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062168" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062169" comment="java-1_4_2-ibm less than 1.4.2_sr13.5-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 22b7b43ee38cfc5dac6ddc1fad1d45e5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061078" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061079" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061080" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061081" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061082" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.7.1"/>
		</criteria>
	</criteria>
	<!-- 86f8e0835cea2b76091e1f68f65ed768 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062167" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062168" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062169" comment="java-1_4_2-ibm less than 1.4.2_sr13.5-0.1.1"/>
		</criteria>
	</criteria>
	<!-- a1c03b73aa6d1ead4ac038bf35d86be9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061083" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061084" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061085" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061086" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061087" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.1.2"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100844" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0844</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Java 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>sles11-java.i386</platform>
		<platform>sles11-java.ia64</platform>
		<platform>sles11-java.ppc64</platform>
		<platform>sles11-java.s390x</platform>
		<platform>sles11-java.x86_64</platform>
	</affected>
	<reference ref_id="CVE-2010-0844" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0844" source="CVE"/>
	<description>
	Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is for improper parsing of a crafted MIDI stream when creating a MixerSequencer object, which causes a pointer to be corrupted and allows a NULL byte to be written to arbitrary memory.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 12597bfedbb46982a7db921e22529a3f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062167" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062168" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062169" comment="java-1_4_2-ibm less than 1.4.2_sr13.5-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 22b7b43ee38cfc5dac6ddc1fad1d45e5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061078" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061079" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061080" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061081" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061082" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.7.1"/>
		</criteria>
	</criteria>
	<!-- 86f8e0835cea2b76091e1f68f65ed768 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062167" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062168" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062169" comment="java-1_4_2-ibm less than 1.4.2_sr13.5-0.1.1"/>
		</criteria>
	</criteria>
	<!-- a1c03b73aa6d1ead4ac038bf35d86be9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061083" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061084" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061085" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061086" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061087" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.1.2"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100846" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0846</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Java 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>sles11-java.i386</platform>
		<platform>sles11-java.ia64</platform>
		<platform>sles11-java.ppc64</platform>
		<platform>sles11-java.s390x</platform>
		<platform>sles11-java.x86_64</platform>
	</affected>
	<reference ref_id="CVE-2010-0846" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0846" source="CVE"/>
	<description>
	Unspecified vulnerability in the ImageIO component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is a heap-based buffer overflow that allows remote attackers to execute arbitrary code, related to an "invalid assignment" and inconsistent length values in a JPEG image encoder (JPEGImageEncoderImpl).
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 12597bfedbb46982a7db921e22529a3f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062167" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062168" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062169" comment="java-1_4_2-ibm less than 1.4.2_sr13.5-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 22b7b43ee38cfc5dac6ddc1fad1d45e5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061078" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061079" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061080" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061081" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061082" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.7.1"/>
		</criteria>
	</criteria>
	<!-- 86f8e0835cea2b76091e1f68f65ed768 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062167" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062168" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062169" comment="java-1_4_2-ibm less than 1.4.2_sr13.5-0.1.1"/>
		</criteria>
	</criteria>
	<!-- a1c03b73aa6d1ead4ac038bf35d86be9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061083" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061084" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061085" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061086" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061087" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.1.2"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100847" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0847</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Java 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>sles11-java.i386</platform>
		<platform>sles11-java.ia64</platform>
		<platform>sles11-java.ppc64</platform>
		<platform>sles11-java.s390x</platform>
		<platform>sles11-java.x86_64</platform>
	</affected>
	<reference ref_id="CVE-2010-0847" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0847" source="CVE"/>
	<description>
	Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is a heap-based buffer overflow that allows arbitrary code execution via a crafted image.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 12597bfedbb46982a7db921e22529a3f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062167" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062168" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062169" comment="java-1_4_2-ibm less than 1.4.2_sr13.5-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 22b7b43ee38cfc5dac6ddc1fad1d45e5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061078" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061079" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061080" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061081" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061082" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.7.1"/>
		</criteria>
	</criteria>
	<!-- 86f8e0835cea2b76091e1f68f65ed768 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062167" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062168" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062169" comment="java-1_4_2-ibm less than 1.4.2_sr13.5-0.1.1"/>
		</criteria>
	</criteria>
	<!-- a1c03b73aa6d1ead4ac038bf35d86be9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061083" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061084" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061085" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061086" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061087" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.1.2"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100848" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0848</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Java 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>sles11-java.i386</platform>
		<platform>sles11-java.ia64</platform>
		<platform>sles11-java.ppc64</platform>
		<platform>sles11-java.s390x</platform>
		<platform>sles11-java.x86_64</platform>
	</affected>
	<reference ref_id="CVE-2010-0848" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0848" source="CVE"/>
	<description>
	Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 12597bfedbb46982a7db921e22529a3f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062167" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062168" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062169" comment="java-1_4_2-ibm less than 1.4.2_sr13.5-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 22b7b43ee38cfc5dac6ddc1fad1d45e5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061078" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061079" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061080" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061081" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061082" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.7.1"/>
		</criteria>
	</criteria>
	<!-- 86f8e0835cea2b76091e1f68f65ed768 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062167" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062168" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062169" comment="java-1_4_2-ibm less than 1.4.2_sr13.5-0.1.1"/>
		</criteria>
	</criteria>
	<!-- a1c03b73aa6d1ead4ac038bf35d86be9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061083" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061084" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061085" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061086" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061087" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.1.2"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100849" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0849</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Java 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>sles11-java.i386</platform>
		<platform>sles11-java.ia64</platform>
		<platform>sles11-java.ppc64</platform>
		<platform>sles11-java.s390x</platform>
		<platform>sles11-java.x86_64</platform>
	</affected>
	<reference ref_id="CVE-2010-0849" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0849" source="CVE"/>
	<description>
	Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is a heap-based buffer overflow in a decoding routine used by the JPEGImageDecoderImpl interface, which allows code execution via a crafted JPEG image.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 12597bfedbb46982a7db921e22529a3f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062167" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062168" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062169" comment="java-1_4_2-ibm less than 1.4.2_sr13.5-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 22b7b43ee38cfc5dac6ddc1fad1d45e5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061078" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061079" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061080" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061081" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061082" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.7.1"/>
		</criteria>
	</criteria>
	<!-- 86f8e0835cea2b76091e1f68f65ed768 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062167" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062168" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.5-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062169" comment="java-1_4_2-ibm less than 1.4.2_sr13.5-0.1.1"/>
		</criteria>
	</criteria>
	<!-- a1c03b73aa6d1ead4ac038bf35d86be9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061083" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061084" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061085" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061086" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr8.0-0.1.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061087" comment="java-1_6_0-ibm less than 1.6.0_sr8.0-0.1.2"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100926" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-0926</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-0926" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0926" source="CVE"/>
	<description>
	The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, and 3.5.x before 3.5.0rc3, when a writable share exists, allows remote authenticated users to leverage a directory traversal vulnerability, and access arbitrary files, by using the symlink command in smbclient to create a symlink containing .. (dot dot) sequences, related to the combination of the unix extensions and wide links options.
	</description>
 </metadata>
<!-- dcc8a519c5c6d5ce485655060c83d71a -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009059012" comment="cifs-mount less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059013" comment="ldapsmb less than 1.34b-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059014" comment="libsmbclient0-32bit less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059015" comment="libsmbclient0-x86 less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059016" comment="libsmbclient0 less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059017" comment="libtalloc1-32bit less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059018" comment="libtalloc1-x86 less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059019" comment="libtalloc1 less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059020" comment="libtdb1-32bit less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059021" comment="libtdb1-x86 less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059022" comment="libtdb1 less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059023" comment="libwbclient0-32bit less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059024" comment="libwbclient0-x86 less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059025" comment="libwbclient0 less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059026" comment="samba-32bit less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059027" comment="samba-client-32bit less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059028" comment="samba-client-x86 less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059029" comment="samba-client less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059030" comment="samba-krb-printing less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059031" comment="samba-winbind-32bit less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059032" comment="samba-winbind-x86 less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059033" comment="samba-winbind less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059034" comment="samba-x86 less than 3.2.7-11.9.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009059035" comment="samba less than 3.2.7-11.9.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101000" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1000</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-1000" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1000" source="CVE"/>
	<description>
	Directory traversal vulnerability in KGet in KDE SC 4.0.0 through 4.4.3 allows remote attackers to create arbitrary files via directory traversal sequences in the name attribute of a file element in a metalink file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2fb2523f388f4f507725821f053b7b30 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009065196" comment="kdenetwork4-filesharing less than 4.3.5-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065197" comment="kget less than 4.3.5-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065198" comment="kopete less than 4.3.5-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065199" comment="krdc less than 4.3.5-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065200" comment="krfb less than 4.3.5-0.4.1"/>
		</criteria>
	</criteria>
	<!-- fb44440d868c7c3b0efae521994af0a4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009065165" comment="kde4-kget less than 4.1.3-7.9.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065166" comment="kde4-knewsticker less than 4.1.3-7.9.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065167" comment="kde4-kopete less than 4.1.3-7.9.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065168" comment="kde4-krdc less than 4.1.3-7.9.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065169" comment="kde4-krfb less than 4.1.3-7.9.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065170" comment="kdenetwork4-filesharing less than 4.1.3-7.9.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101085" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1085</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-1085" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1085" source="CVE"/>
	<description>
	The azx_position_ok function in hda_intel.c in Linux kernel 2.6.33-rc4 and earlier, when running on the AMD780V chip set, allows context-dependent attackers to cause a denial of service (crash) via unknown manipulations that trigger a divide-by-zero error.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1cc9f9878be828ca9494ad136beab1d1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 5bc8b282021bec5a0602dd1e1fb86cc0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058496" comment="ext4dev-kmp-xen less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 8de370e0ec03088da9aa16f31064b5c4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058499" comment="ext4dev-kmp-pae less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058500" comment="ext4dev-kmp-vmi less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058496" comment="ext4dev-kmp-xen less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058501" comment="kernel-pae-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058502" comment="kernel-pae less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058503" comment="kernel-vmi-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058504" comment="kernel-vmi less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058497" comment="kernel-xen-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058498" comment="kernel-xen less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- b6015de562091b64634bc48dd8f9db1a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058505" comment="kernel-default-man less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e5c7588310814dc753e7fc885f8955fb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009058491" comment="ext4dev-kmp-default less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058506" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.45_0.1-7.1.26"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058492" comment="kernel-default-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058493" comment="kernel-default less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058507" comment="kernel-kdump less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058508" comment="kernel-ppc64-base less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058509" comment="kernel-ppc64 less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058494" comment="kernel-source less than 2.6.27.45-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009058495" comment="kernel-syms less than 2.6.27.45-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101087" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1087</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-1087" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1087" source="CVE"/>
	<description>
	The nfs_wait_on_request function in fs/nfs/pagelist.c in Linux kernel 2.6.x through 2.6.33-rc5 allows attackers to cause a denial of service (Oops) via unknown vectors related to truncating a file and an operation that is not interruptible.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2959a2080579b86be5f71889c23098f9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061702" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061678" comment="kernel-kdump less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061682" comment="kernel-ppc64-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061684" comment="kernel-ppc64 less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 66504af0afe753b5175112b44bc8827d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061703" comment="ext4dev-kmp-pae less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061704" comment="ext4dev-kmp-vmi less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061705" comment="ext4dev-kmp-xen less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061679" comment="kernel-pae-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061681" comment="kernel-pae less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061706" comment="kernel-vmi-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061707" comment="kernel-vmi less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 99ed0d9e003dfe8866db7105d4850a09 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- c8a29eec659b0b2b3e85c610b67beacd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061705" comment="ext4dev-kmp-xen less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- f73f22d4b713e9a7674cc8c4eebf91dd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061708" comment="kernel-default-man less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101121" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1121</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1121" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1121" source="CVE"/>
	<description>
	Mozilla Firefox 3.6.x before 3.6.3 does not properly manage the scopes of DOM nodes that are moved from one document to another, which allows remote attackers to conduct use-after-free attacks and execute arbitrary code via unspecified vectors involving improper interaction with garbage collection, as demonstrated by Nils during a Pwn2Own competition at CanSecWest 2010.
	</description>
 </metadata>
<!-- f9b2b1aaa535612c1bff26161e7cb381 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009061668" comment="MozillaFirefox-translations less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061192" comment="MozillaFirefox less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070643" comment="mozilla-xulrunner191-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070644" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061669" comment="mozilla-xulrunner191-translations less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070645" comment="mozilla-xulrunner191-x86 less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061670" comment="mozilla-xulrunner191 less than 1.9.1.10-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101125" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1125</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1125" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1125" source="CVE"/>
	<description>
	The JavaScript implementation in Mozilla Firefox 3.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, allows remote attackers to send selected keystrokes to a form field in a hidden frame, instead of the intended form field in a visible frame, via certain calls to the focus method.
	</description>
 </metadata>
<!-- f9b2b1aaa535612c1bff26161e7cb381 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009061668" comment="MozillaFirefox-translations less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061192" comment="MozillaFirefox less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070643" comment="mozilla-xulrunner191-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070644" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061669" comment="mozilla-xulrunner191-translations less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070645" comment="mozilla-xulrunner191-x86 less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061670" comment="mozilla-xulrunner191 less than 1.9.1.10-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101162" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1162</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-1162" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1162" source="CVE"/>
	<description>
	The release_one_tty function in drivers/char/tty_io.c in the Linux kernel before 2.6.34-rc4 omits certain required calls to the put_pid function, which has unspecified impact and local attack vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2959a2080579b86be5f71889c23098f9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061702" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061678" comment="kernel-kdump less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061682" comment="kernel-ppc64-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061684" comment="kernel-ppc64 less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 66504af0afe753b5175112b44bc8827d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061703" comment="ext4dev-kmp-pae less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061704" comment="ext4dev-kmp-vmi less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061705" comment="ext4dev-kmp-xen less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061679" comment="kernel-pae-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061681" comment="kernel-pae less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061706" comment="kernel-vmi-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061707" comment="kernel-vmi less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 99ed0d9e003dfe8866db7105d4850a09 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- c8a29eec659b0b2b3e85c610b67beacd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061705" comment="ext4dev-kmp-xen less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- f73f22d4b713e9a7674cc8c4eebf91dd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061708" comment="kernel-default-man less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101166" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1166</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-1166" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1166" source="CVE"/>
	<description>
	The fbComposite function in fbpict.c in the Render extension in the X server in X.Org X11R7.1 allows remote authenticated users to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a crafted request, related to an incorrect macro definition.
	</description>
 </metadata>
<!-- 0174468eca4a0d10570a92e001f081dd -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009063235" comment="xorg-x11-Xvnc less than 7.4-27.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009063236" comment="xorg-x11-server-extra less than 7.4-27.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009063237" comment="xorg-x11-server less than 7.4-27.24.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101168" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1168</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1168" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1168" source="CVE"/>
	<description>
	The Safe (aka Safe.pm) module before 2.25 for Perl allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access restrictions, and inject and execute arbitrary code, via vectors involving implicitly called methods and implicitly blessed objects, as demonstrated by the (a) DESTROY and (b) AUTOLOAD methods, related to "automagic methods."
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 20ed7ae57e909277c40c8e5c6d74b113 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061998" comment="perl-32bit less than 5.10.0-64.48.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061999" comment="perl-base less than 5.10.0-64.48.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062000" comment="perl-doc less than 5.10.0-64.48.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062001" comment="perl-x86 less than 5.10.0-64.48.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062002" comment="perl less than 5.10.0-64.48.1"/>
		</criteria>
	</criteria>
	<!-- fc6f7dab4b52caad2fdcf02ae40651a3 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062003" comment="perl-32bit less than 5.10.0-64.44.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062004" comment="perl-base less than 5.10.0-64.44.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062005" comment="perl-doc less than 5.10.0-64.44.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062006" comment="perl-x86 less than 5.10.0-64.44.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062007" comment="perl less than 5.10.0-64.44.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101169" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1169</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1169" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1169" source="CVE"/>
	<description>
	PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, 8.4 before 8.4.4, and 9.0 Beta before 9.0 Beta 2 does not properly restrict PL/perl procedures, which allows remote authenticated users, with database-creation privileges, to execute arbitrary Perl code via a crafted script, related to the Safe module (aka Safe.pm) for Perl. NOTE: some sources report that this issue is the same as CVE-2010-1447.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1623a9038b26e4b2fb345e388ebf6ca9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061271" comment="postgresql-contrib less than 8.3.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061272" comment="postgresql-docs less than 8.3.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061273" comment="postgresql-libs-32bit less than 8.3.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061274" comment="postgresql-libs-x86 less than 8.3.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061275" comment="postgresql-libs less than 8.3.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061276" comment="postgresql-server less than 8.3.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061277" comment="postgresql less than 8.3.11-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 3583616cbc2a604051aee34d4ba07c2c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061277" comment="postgresql less than 8.3.11-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101170" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1170</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1170" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1170" source="CVE"/>
	<description>
	The PL/Tcl implementation in PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, 8.4 before 8.4.4, and 9.0 Beta before 9.0 Beta 2 loads Tcl code from the pltcl_modules table regardless of the table's ownership and permissions, which allows remote authenticated users, with database-creation privileges, to execute arbitrary Tcl code by creating this table and inserting a crafted Tcl script.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1623a9038b26e4b2fb345e388ebf6ca9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061271" comment="postgresql-contrib less than 8.3.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061272" comment="postgresql-docs less than 8.3.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061273" comment="postgresql-libs-32bit less than 8.3.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061274" comment="postgresql-libs-x86 less than 8.3.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061275" comment="postgresql-libs less than 8.3.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061276" comment="postgresql-server less than 8.3.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061277" comment="postgresql less than 8.3.11-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 3583616cbc2a604051aee34d4ba07c2c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061277" comment="postgresql less than 8.3.11-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101172" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1172</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-1172" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1172" source="CVE"/>
	<description>
	DBus-GLib 0.73 disregards the access flag of exported GObject properties, which allows local users to bypass intended access restrictions and possibly cause a denial of service by modifying properties, as demonstrated by properties of the (1) DeviceKit-Power, (2) NetworkManager, and (3) ModemManager services.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0cf7b7dbbdf78d0e48405afacc77e953 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009070663" comment="NetworkManager-glib less than 0.7.0.r4359-15.25.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070664" comment="NetworkManager less than 0.7.0.r4359-15.25.1"/>
		</criteria>
	</criteria>
	<!-- 21a8a97ab9a50a767beec4f66444c8fb -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063818" comment="dbus-1-glib-32bit less than 0.76-34.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063819" comment="dbus-1-glib-x86 less than 0.76-34.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063820" comment="dbus-1-glib less than 0.76-34.4.1"/>
		</criteria>
	</criteria>
	<!-- 6ebbb42d94bbf91e258916a349f1d793 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064045" comment="NetworkManager-glib less than 0.7.0.r4359-15.20.10.12"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064046" comment="NetworkManager less than 0.7.0.r4359-15.20.10.12"/>
		</criteria>
	</criteria>
	<!-- 7d54ac00be064ed8a9d0f93e8a7a259f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064413" comment="gdm-branding-upstream less than 2.24.0-24.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064414" comment="gdm-lang less than 2.24.0-24.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064415" comment="gdm less than 2.24.0-24.28.1"/>
		</criteria>
	</criteria>
	<!-- 82a8dce49738846083382071155ad5b3 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064416" comment="gdm-branding-upstream less than 2.24.0-24.39.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064417" comment="gdm-lang less than 2.24.0-24.39.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064418" comment="gdm less than 2.24.0-24.39.1"/>
		</criteria>
	</criteria>
	<!-- f13b7d380aa83e653649de2c3932f66d -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063821" comment="dbus-1-glib-32bit less than 0.76-34.7.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063822" comment="dbus-1-glib-x86 less than 0.76-34.7.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063823" comment="dbus-1-glib less than 0.76-34.7.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063821" comment="dbus-1-glib-32bit less than 0.76-34.7.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063823" comment="dbus-1-glib less than 0.76-34.7.1"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101173" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1173</title>
	<affected family="unix">
		<platform>SLE 11 SERVER Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-1173" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1173" source="CVE"/>
	<description>
	The sctp_process_unk_param function in net/sctp/sm_make_chunk.c in the Linux kernel 2.6.33.3 and earlier, when SCTP is enabled, allows remote attackers to cause a denial of service (system crash) via an SCTPChunkInit packet containing multiple invalid parameters that require a large amount of error data.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0e4cb330aea8c4851b064f19e6d4e99c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009070665" comment="btrfs-kmp-default less than 0_2.6.32.13_0.4-0.3.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070666" comment="ext4dev-kmp-default less than 0_2.6.32.13_0.4-7.3.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070667" comment="kernel-default-base less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070668" comment="kernel-default-devel less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070669" comment="kernel-default-man less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070670" comment="kernel-default less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070671" comment="kernel-source less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070672" comment="kernel-syms less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070673" comment="kernel-trace-base less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070674" comment="kernel-trace-devel less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070675" comment="kernel-trace less than 2.6.32.13-0.4.1"/>
		</criteria>
	</criteria>
	<!-- 22846882965710e8a968106e5fa9b938 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009070665" comment="btrfs-kmp-default less than 0_2.6.32.13_0.4-0.3.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070676" comment="btrfs-kmp-pae less than 0_2.6.32.13_0.4-0.3.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070677" comment="btrfs-kmp-xen less than 0_2.6.32.13_0.4-0.3.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070666" comment="ext4dev-kmp-default less than 0_2.6.32.13_0.4-7.3.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070678" comment="ext4dev-kmp-pae less than 0_2.6.32.13_0.4-7.3.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070679" comment="ext4dev-kmp-xen less than 0_2.6.32.13_0.4-7.3.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070680" comment="hyper-v-kmp-default less than 0_2.6.32.13_0.4-0.7.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070681" comment="hyper-v-kmp-pae less than 0_2.6.32.13_0.4-0.7.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070667" comment="kernel-default-base less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070668" comment="kernel-default-devel less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070670" comment="kernel-default less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070682" comment="kernel-pae-base less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070683" comment="kernel-pae-devel less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070684" comment="kernel-pae less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070671" comment="kernel-source less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070672" comment="kernel-syms less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070673" comment="kernel-trace-base less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070674" comment="kernel-trace-devel less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070675" comment="kernel-trace less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070685" comment="kernel-xen-base less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070686" comment="kernel-xen-devel less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070687" comment="kernel-xen less than 2.6.32.13-0.4.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009070665" comment="btrfs-kmp-default less than 0_2.6.32.13_0.4-0.3.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070676" comment="btrfs-kmp-pae less than 0_2.6.32.13_0.4-0.3.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070666" comment="ext4dev-kmp-default less than 0_2.6.32.13_0.4-7.3.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070678" comment="ext4dev-kmp-pae less than 0_2.6.32.13_0.4-7.3.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070680" comment="hyper-v-kmp-default less than 0_2.6.32.13_0.4-0.7.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070681" comment="hyper-v-kmp-pae less than 0_2.6.32.13_0.4-0.7.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070667" comment="kernel-default-base less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070668" comment="kernel-default-devel less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070670" comment="kernel-default less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070682" comment="kernel-pae-base less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070683" comment="kernel-pae-devel less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070684" comment="kernel-pae less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070671" comment="kernel-source less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070672" comment="kernel-syms less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070673" comment="kernel-trace-base less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070674" comment="kernel-trace-devel less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070675" comment="kernel-trace less than 2.6.32.13-0.4.1"/>
			</criteria>
		</criteria></criteria>
	<!-- 329cdfcfbddc09b14ba9975bbf6d87e8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009070665" comment="btrfs-kmp-default less than 0_2.6.32.13_0.4-0.3.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070666" comment="ext4dev-kmp-default less than 0_2.6.32.13_0.4-7.3.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070688" comment="ext4dev-kmp-ppc64 less than 0_2.6.32.13_0.4-7.3.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070667" comment="kernel-default-base less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070668" comment="kernel-default-devel less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070670" comment="kernel-default less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070689" comment="kernel-ppc64-base less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070690" comment="kernel-ppc64-devel less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070691" comment="kernel-ppc64 less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070671" comment="kernel-source less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070672" comment="kernel-syms less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070673" comment="kernel-trace-base less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070674" comment="kernel-trace-devel less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070675" comment="kernel-trace less than 2.6.32.13-0.4.1"/>
		</criteria>
	</criteria>
	<!-- 6d234b253abdbb9f30537479384ed1bd -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009070665" comment="btrfs-kmp-default less than 0_2.6.32.13_0.4-0.3.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070677" comment="btrfs-kmp-xen less than 0_2.6.32.13_0.4-0.3.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070666" comment="ext4dev-kmp-default less than 0_2.6.32.13_0.4-7.3.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070679" comment="ext4dev-kmp-xen less than 0_2.6.32.13_0.4-7.3.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070680" comment="hyper-v-kmp-default less than 0_2.6.32.13_0.4-0.7.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070667" comment="kernel-default-base less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070668" comment="kernel-default-devel less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070670" comment="kernel-default less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070671" comment="kernel-source less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070672" comment="kernel-syms less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070673" comment="kernel-trace-base less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070674" comment="kernel-trace-devel less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070675" comment="kernel-trace less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070685" comment="kernel-xen-base less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070686" comment="kernel-xen-devel less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070687" comment="kernel-xen less than 2.6.32.13-0.4.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009070665" comment="btrfs-kmp-default less than 0_2.6.32.13_0.4-0.3.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070666" comment="ext4dev-kmp-default less than 0_2.6.32.13_0.4-7.3.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070680" comment="hyper-v-kmp-default less than 0_2.6.32.13_0.4-0.7.3"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070667" comment="kernel-default-base less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070668" comment="kernel-default-devel less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070670" comment="kernel-default less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070671" comment="kernel-source less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070672" comment="kernel-syms less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070673" comment="kernel-trace-base less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070674" comment="kernel-trace-devel less than 2.6.32.13-0.4.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009070675" comment="kernel-trace less than 2.6.32.13-0.4.1"/>
			</criteria>
		</criteria></criteria>
	<!-- d8e7470ce034188e261ccb5e82b64416 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009070665" comment="btrfs-kmp-default less than 0_2.6.32.13_0.4-0.3.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070666" comment="ext4dev-kmp-default less than 0_2.6.32.13_0.4-7.3.3"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070667" comment="kernel-default-base less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070668" comment="kernel-default-devel less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070670" comment="kernel-default less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070671" comment="kernel-source less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070672" comment="kernel-syms less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070673" comment="kernel-trace-base less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070674" comment="kernel-trace-devel less than 2.6.32.13-0.4.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070675" comment="kernel-trace less than 2.6.32.13-0.4.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101192" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1192</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-1192" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1192" source="CVE"/>
	<description>
	libESMTP, probably 1.0.4 and earlier, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
	</description>
 </metadata>
<!-- c9c4add13bf4daee40ad37e5761a99be -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060265" comment="libesmtp less than 1.0.4-157.15.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101194" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1194</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-1194" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1194" source="CVE"/>
	<description>
	The match_component function in smtp-tls.c in libESMTP 1.0.3.r1, and possibly other versions including 1.0.4, treats two strings as equal if one is a substring of the other, which allows remote attackers to spoof trusted certificates via a crafted subjectAltName.
	</description>
 </metadata>
<!-- c9c4add13bf4daee40ad37e5761a99be -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060265" comment="libesmtp less than 1.0.4-157.15.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101196" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1196</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1196" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1196" source="CVE"/>
	<description>
	Integer overflow in the nsGenericDOMDataNode::SetTextInternal function in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code via a DOM node with a long text value that triggers a heap-based buffer overflow.
	</description>
 </metadata>
<!-- f9b2b1aaa535612c1bff26161e7cb381 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009061668" comment="MozillaFirefox-translations less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061192" comment="MozillaFirefox less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070643" comment="mozilla-xulrunner191-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070644" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061669" comment="mozilla-xulrunner191-translations less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070645" comment="mozilla-xulrunner191-x86 less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061670" comment="mozilla-xulrunner191 less than 1.9.1.10-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101197" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1197</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1197" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1197" source="CVE"/>
	<description>
	Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, does not properly handle situations in which both "Content-Disposition: attachment" and "Content-Type: multipart" are present in HTTP headers, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an uploaded HTML document.
	</description>
 </metadata>
<!-- f9b2b1aaa535612c1bff26161e7cb381 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009061668" comment="MozillaFirefox-translations less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061192" comment="MozillaFirefox less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070643" comment="mozilla-xulrunner191-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070644" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061669" comment="mozilla-xulrunner191-translations less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070645" comment="mozilla-xulrunner191-x86 less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061670" comment="mozilla-xulrunner191 less than 1.9.1.10-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101198" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1198</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1198" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1198" source="CVE"/>
	<description>
	Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, allows remote attackers to execute arbitrary code via vectors involving multiple plugin instances.
	</description>
 </metadata>
<!-- f9b2b1aaa535612c1bff26161e7cb381 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009061668" comment="MozillaFirefox-translations less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061192" comment="MozillaFirefox less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070643" comment="mozilla-xulrunner191-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070644" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061669" comment="mozilla-xulrunner191-translations less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070645" comment="mozilla-xulrunner191-x86 less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061670" comment="mozilla-xulrunner191 less than 1.9.1.10-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101199" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1199</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1199" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1199" source="CVE"/>
	<description>
	Integer overflow in the XSLT node sorting implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code via a large text value for a node.
	</description>
 </metadata>
<!-- f9b2b1aaa535612c1bff26161e7cb381 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009061668" comment="MozillaFirefox-translations less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061192" comment="MozillaFirefox less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070643" comment="mozilla-xulrunner191-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070644" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061669" comment="mozilla-xulrunner191-translations less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070645" comment="mozilla-xulrunner191-x86 less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061670" comment="mozilla-xulrunner191 less than 1.9.1.10-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101200" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1200</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1200" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1200" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
<!-- f9b2b1aaa535612c1bff26161e7cb381 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009061668" comment="MozillaFirefox-translations less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061192" comment="MozillaFirefox less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070643" comment="mozilla-xulrunner191-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070644" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061669" comment="mozilla-xulrunner191-translations less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070645" comment="mozilla-xulrunner191-x86 less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061670" comment="mozilla-xulrunner191 less than 1.9.1.10-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101201" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1201</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1201" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1201" source="CVE"/>
	<description>
	Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.10, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
<!-- f9b2b1aaa535612c1bff26161e7cb381 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009061668" comment="MozillaFirefox-translations less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061192" comment="MozillaFirefox less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070643" comment="mozilla-xulrunner191-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070644" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061669" comment="mozilla-xulrunner191-translations less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070645" comment="mozilla-xulrunner191-x86 less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061670" comment="mozilla-xulrunner191 less than 1.9.1.10-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101202" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1202</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1202" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1202" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
<!-- f9b2b1aaa535612c1bff26161e7cb381 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009061668" comment="MozillaFirefox-translations less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061192" comment="MozillaFirefox less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070643" comment="mozilla-xulrunner191-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070644" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061669" comment="mozilla-xulrunner191-translations less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070645" comment="mozilla-xulrunner191-x86 less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061670" comment="mozilla-xulrunner191 less than 1.9.1.10-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101203" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1203</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1203" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1203" source="CVE"/>
	<description>
	The JavaScript engine in Mozilla Firefox 3.6.x before 3.6.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors that trigger an assertion failure in jstracer.cpp.
	</description>
 </metadata>
<!-- f9b2b1aaa535612c1bff26161e7cb381 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009061668" comment="MozillaFirefox-translations less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061192" comment="MozillaFirefox less than 3.5.10-0.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070643" comment="mozilla-xulrunner191-32bit less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070644" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061669" comment="mozilla-xulrunner191-translations less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070645" comment="mozilla-xulrunner191-x86 less than 1.9.1.10-1.1.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061670" comment="mozilla-xulrunner191 less than 1.9.1.10-1.1.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101205" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1205</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-1205" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1205" source="CVE"/>
	<description>
	Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 05599e35a510ca089ac92c0708d24d96 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062258" comment="libpng12-0-32bit less than 1.2.31-5.18.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062259" comment="libpng12-0-x86 less than 1.2.31-5.18.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062260" comment="libpng12-0 less than 1.2.31-5.18.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062258" comment="libpng12-0-32bit less than 1.2.31-5.18.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062260" comment="libpng12-0 less than 1.2.31-5.18.1"/>
			</criteria>
		</criteria></criteria>
	<!-- 0d0d8706df2d64128121ceea3338a129 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061813" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 1827d5255702922bfdc18e59d59e6a20 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062258" comment="libpng12-0-32bit less than 1.2.31-5.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062259" comment="libpng12-0-x86 less than 1.2.31-5.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062260" comment="libpng12-0 less than 1.2.31-5.18.1"/>
		</criteria>
	</criteria>
	<!-- f23d3ef3410fecb23cf62a058d285514 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061813" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101206" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1206</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1206" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1206" source="CVE"/>
	<description>
	The startDocumentLoad function in browser/base/content/browser.js in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, does not properly implement the Same Origin Policy in certain circumstances related to the about:blank document and a document that is currently loading, which allows (1) remote web servers to conduct spoofing attacks via vectors involving a 204 (aka No Content) status code, and allows (2) remote attackers to conduct spoofing attacks via vectors involving a window.stop call.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0d0d8706df2d64128121ceea3338a129 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061813" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
	<!-- f23d3ef3410fecb23cf62a058d285514 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061813" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101208" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1208</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1208" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1208" source="CVE"/>
	<description>
	Use-after-free vulnerability in the attribute-cloning functionality in the DOM implementation in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via vectors related to deletion of an event attribute node with a nonzero reference count.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0d0d8706df2d64128121ceea3338a129 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061813" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
	<!-- f23d3ef3410fecb23cf62a058d285514 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061813" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101209" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1209</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1209" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1209" source="CVE"/>
	<description>
	Use-after-free vulnerability in the NodeIterator implementation in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via a crafted NodeFilter that detaches DOM nodes, related to the NodeIterator interface and a javascript callback.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0d0d8706df2d64128121ceea3338a129 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061813" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
	<!-- f23d3ef3410fecb23cf62a058d285514 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061813" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101211" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1211</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1211" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1211" source="CVE"/>
	<description>
	Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0d0d8706df2d64128121ceea3338a129 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061813" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
	<!-- f23d3ef3410fecb23cf62a058d285514 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061813" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101213" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1213</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1213" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1213" source="CVE"/>
	<description>
	The importScripts Web Worker method in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 does not verify that content is valid JavaScript code, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted HTML document.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0d0d8706df2d64128121ceea3338a129 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061813" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
	<!-- f23d3ef3410fecb23cf62a058d285514 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061813" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101214" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1214</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1214" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1214" source="CVE"/>
	<description>
	Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via plugin content with many parameter elements.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0d0d8706df2d64128121ceea3338a129 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061813" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
	<!-- f23d3ef3410fecb23cf62a058d285514 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061813" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101321" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1321</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Java 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-1321" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1321" source="CVE"/>
	<description>
	The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (aka krb5) through 1.7.1 and 1.8 before 1.8.2, as used in kadmind and other applications, does not properly check for invalid GSS-API tokens, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via an AP-REQ message in which the authenticator's checksum field is missing.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 7d2fb2e31f042d9b40de3903d2d7d5fd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060710" comment="krb5-32bit less than 1.6.3-133.33.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060711" comment="krb5-apps-clients less than 1.6.3-133.33.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060712" comment="krb5-apps-servers less than 1.6.3-133.33.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060713" comment="krb5-client less than 1.6.3-133.33.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060714" comment="krb5-server less than 1.6.3-133.33.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060715" comment="krb5-x86 less than 1.6.3-133.33.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060716" comment="krb5 less than 1.6.3-133.33.1"/>
		</criteria>
	</criteria>
	<!-- 8ea804135f46af2e987ad9def4eb1b3e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009066019" comment="java-1_4_2-ibm-jdbc less than 1.4.2_sr13.8-1.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066020" comment="java-1_4_2-ibm-plugin less than 1.4.2_sr13.8-1.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066021" comment="java-1_4_2-ibm less than 1.4.2_sr13.8-1.5.1"/>
		</criteria>
	</criteria>
	<!-- 99e3a681bfd3aa624a61230811cf88e5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009065622" comment="java-1_6_0-ibm-alsa less than 1.6.0_sr9.0-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065623" comment="java-1_6_0-ibm-fonts less than 1.6.0_sr9.0-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065624" comment="java-1_6_0-ibm-jdbc less than 1.6.0_sr9.0-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065625" comment="java-1_6_0-ibm-plugin less than 1.6.0_sr9.0-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065626" comment="java-1_6_0-ibm less than 1.6.0_sr9.0-0.2.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101323" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1323</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-1323" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1323" source="CVE"/>
	<description>
	MIT Kerberos 5 (aka krb5) 1.3.x, 1.4.x, 1.5.x, 1.6.x, 1.7.x, and 1.8.x through 1.8.3 does not properly determine the acceptability of checksums, which might allow remote attackers to modify user-visible prompt text, modify a response to a Key Distribution Center (KDC), or forge a KRB-SAFE message via certain checksums that (1) are unkeyed or (2) use RC4 keys.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 23219794593188e3b87f7770060cff7a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064607" comment="krb5-32bit less than 1.6.3-133.39.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064608" comment="krb5-apps-clients less than 1.6.3-133.39.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064609" comment="krb5-apps-servers less than 1.6.3-133.39.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064610" comment="krb5-client less than 1.6.3-133.39.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064611" comment="krb5-server less than 1.6.3-133.39.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064612" comment="krb5-x86 less than 1.6.3-133.39.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064613" comment="krb5 less than 1.6.3-133.39.1"/>
		</criteria>
	</criteria>
	<!-- 2c00c569cf8c668fd2c6865d49aaf3ed -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064607" comment="krb5-32bit less than 1.6.3-133.39.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064608" comment="krb5-apps-clients less than 1.6.3-133.39.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064609" comment="krb5-apps-servers less than 1.6.3-133.39.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064610" comment="krb5-client less than 1.6.3-133.39.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064611" comment="krb5-server less than 1.6.3-133.39.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064612" comment="krb5-x86 less than 1.6.3-133.39.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064613" comment="krb5 less than 1.6.3-133.39.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064607" comment="krb5-32bit less than 1.6.3-133.39.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064608" comment="krb5-apps-clients less than 1.6.3-133.39.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064609" comment="krb5-apps-servers less than 1.6.3-133.39.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064610" comment="krb5-client less than 1.6.3-133.39.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064611" comment="krb5-server less than 1.6.3-133.39.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064613" comment="krb5 less than 1.6.3-133.39.1"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101324" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1324</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-1324" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1324" source="CVE"/>
	<description>
	MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x through 1.8.3 does not properly determine the acceptability of checksums, which might allow remote attackers to forge GSS tokens, gain privileges, or have unspecified other impact via (1) an unkeyed checksum, (2) an unkeyed PAC checksum, or (3) a KrbFastArmoredReq checksum based on an RC4 key.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 23219794593188e3b87f7770060cff7a -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064607" comment="krb5-32bit less than 1.6.3-133.39.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064608" comment="krb5-apps-clients less than 1.6.3-133.39.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064609" comment="krb5-apps-servers less than 1.6.3-133.39.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064610" comment="krb5-client less than 1.6.3-133.39.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064611" comment="krb5-server less than 1.6.3-133.39.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064612" comment="krb5-x86 less than 1.6.3-133.39.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064613" comment="krb5 less than 1.6.3-133.39.1"/>
		</criteria>
	</criteria>
	<!-- 2c00c569cf8c668fd2c6865d49aaf3ed -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064607" comment="krb5-32bit less than 1.6.3-133.39.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064608" comment="krb5-apps-clients less than 1.6.3-133.39.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064609" comment="krb5-apps-servers less than 1.6.3-133.39.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064610" comment="krb5-client less than 1.6.3-133.39.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064611" comment="krb5-server less than 1.6.3-133.39.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064612" comment="krb5-x86 less than 1.6.3-133.39.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064613" comment="krb5 less than 1.6.3-133.39.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064607" comment="krb5-32bit less than 1.6.3-133.39.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064608" comment="krb5-apps-clients less than 1.6.3-133.39.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064609" comment="krb5-apps-servers less than 1.6.3-133.39.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064610" comment="krb5-client less than 1.6.3-133.39.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064611" comment="krb5-server less than 1.6.3-133.39.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064613" comment="krb5 less than 1.6.3-133.39.1"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101437" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1437</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-1437" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1437" source="CVE"/>
	<description>
	Race condition in the find_keyring_by_name function in security/keys/keyring.c in the Linux kernel 2.6.34-rc5 and earlier allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via keyctl session commands that trigger access to a dead keyring that is undergoing deletion by the key_cleanup function.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2959a2080579b86be5f71889c23098f9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061702" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061678" comment="kernel-kdump less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061682" comment="kernel-ppc64-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061684" comment="kernel-ppc64 less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 66504af0afe753b5175112b44bc8827d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061703" comment="ext4dev-kmp-pae less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061704" comment="ext4dev-kmp-vmi less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061705" comment="ext4dev-kmp-xen less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061679" comment="kernel-pae-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061681" comment="kernel-pae less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061706" comment="kernel-vmi-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061707" comment="kernel-vmi less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 99ed0d9e003dfe8866db7105d4850a09 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- c8a29eec659b0b2b3e85c610b67beacd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061705" comment="ext4dev-kmp-xen less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- f73f22d4b713e9a7674cc8c4eebf91dd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061708" comment="kernel-default-man less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101446" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1446</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-1446" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1446" source="CVE"/>
	<description>
	arch/powerpc/mm/fsl_booke_mmu.c in KGDB in the Linux kernel 2.6.30 and other versions before 2.6.33, when running on PowerPC, does not properly perform a security check for access to a kernel page, which allows local users to overwrite arbitrary kernel memory, related to Fsl booke.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2959a2080579b86be5f71889c23098f9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061702" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061678" comment="kernel-kdump less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061682" comment="kernel-ppc64-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061684" comment="kernel-ppc64 less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 66504af0afe753b5175112b44bc8827d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061703" comment="ext4dev-kmp-pae less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061704" comment="ext4dev-kmp-vmi less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061705" comment="ext4dev-kmp-xen less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061679" comment="kernel-pae-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061681" comment="kernel-pae less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061706" comment="kernel-vmi-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061707" comment="kernel-vmi less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 99ed0d9e003dfe8866db7105d4850a09 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- c8a29eec659b0b2b3e85c610b67beacd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061705" comment="ext4dev-kmp-xen less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- f73f22d4b713e9a7674cc8c4eebf91dd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061708" comment="kernel-default-man less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101447" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1447</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1447" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1447" source="CVE"/>
	<description>
	The Safe (aka Safe.pm) module 2.26, and certain earlier versions, for Perl, as used in PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, 8.4 before 8.4.4, and 9.0 Beta before 9.0 Beta 2, allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access restrictions, and inject and execute arbitrary code, via vectors involving subroutine references and delayed execution.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 20ed7ae57e909277c40c8e5c6d74b113 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061998" comment="perl-32bit less than 5.10.0-64.48.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061999" comment="perl-base less than 5.10.0-64.48.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062000" comment="perl-doc less than 5.10.0-64.48.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062001" comment="perl-x86 less than 5.10.0-64.48.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062002" comment="perl less than 5.10.0-64.48.1"/>
		</criteria>
	</criteria>
	<!-- fc6f7dab4b52caad2fdcf02ae40651a3 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062003" comment="perl-32bit less than 5.10.0-64.44.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062004" comment="perl-base less than 5.10.0-64.44.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062005" comment="perl-doc less than 5.10.0-64.44.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062006" comment="perl-x86 less than 5.10.0-64.44.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062007" comment="perl less than 5.10.0-64.44.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101452" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1452</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for Teradata</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-1452" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1452" source="CVE"/>
	<description>
	The (1) mod_cache and (2) mod_dav modules in the Apache HTTP Server 2.2.x before 2.2.16 allow remote attackers to cause a denial of service (process crash) via a request that lacks a path.
	</description>
 </metadata>
<!-- 6d016ff9e4b33261dfa077a857856638 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009070287" comment="apache2-doc less than 2.2.10-2.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070288" comment="apache2-example-pages less than 2.2.10-2.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070289" comment="apache2-prefork less than 2.2.10-2.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070290" comment="apache2-utils less than 2.2.10-2.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070291" comment="apache2-worker less than 2.2.10-2.30.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009070292" comment="apache2 less than 2.2.10-2.30.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101455" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1455</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-1455" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1455" source="CVE"/>
	<description>
	The DOCSIS dissector in Wireshark 0.9.6 through 1.0.12 and 1.2.0 through 1.2.7 allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed packet trace file.
	</description>
 </metadata>
<!-- 6e5fc6e202651e8b93c830786b3ea82f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066948" comment="wireshark less than 1.4.4-0.2.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101459" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1459</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1459" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1459" source="CVE"/>
	<description>
	The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by the __VIEWSTATE parameter to 2.0/menu/menu1.aspx in the XSP sample project.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 055ed9dbd62292a40d356dcbe57b5733 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060503" comment="mono-core less than 2.0.1-1.20.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060504" comment="mono-data-postgresql less than 2.0.1-1.20.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060505" comment="mono-data-sqlite less than 2.0.1-1.20.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060506" comment="mono-data less than 2.0.1-1.20.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060507" comment="mono-locale-extras less than 2.0.1-1.20.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060508" comment="mono-nunit less than 2.0.1-1.20.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060509" comment="mono-web less than 2.0.1-1.20.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060510" comment="mono-winforms less than 2.0.1-1.20.1"/>
		</criteria>
	</criteria>
	<!-- a9c344651b16899f6cc23f4e77a26a21 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060801" comment="mono-core less than 2.0.1-1.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060802" comment="mono-data-postgresql less than 2.0.1-1.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060803" comment="mono-data-sqlite less than 2.0.1-1.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060804" comment="mono-data less than 2.0.1-1.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060805" comment="mono-locale-extras less than 2.0.1-1.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060806" comment="mono-nunit less than 2.0.1-1.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060807" comment="mono-web less than 2.0.1-1.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009060808" comment="mono-winforms less than 2.0.1-1.26.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101526" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1526</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-1526" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1526" source="CVE"/>
	<description>
	Multiple integer overflows in libgdiplus 2.6.7, as used in Mono, allow attackers to execute arbitrary code via (1) a crafted TIFF file, related to the gdip_load_tiff_image function in tiffcodec.c; (2) a crafted JPEG file, related to the gdip_load_jpeg_image_internal function in jpegcodec.c; or (3) a crafted BMP file, related to the gdip_read_bmp_image function in bmpcodec.c, leading to heap-based buffer overflows.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 496c6871f3bf4f76f48a079d50e33a77 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063122" comment="libgdiplus0 less than 2.0-11.20.1"/>
	</criteria>
	<!-- 596590317a41da978b922e975ea21a2f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063122" comment="libgdiplus0 less than 2.0-11.20.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101585" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1585</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-1585" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1585" source="CVE"/>
	<description>
	The nsIScriptableUnescapeHTML.parseFragment method in the ParanoidFragmentSink protection mechanism in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 does not properly sanitize HTML in a chrome document, which makes it easier for remote attackers to execute arbitrary JavaScript with chrome privileges via a javascript: URI in input to an extension, as demonstrated by a javascript:alert sequence in (1) the HREF attribute of an A element or (2) the ACTION attribute of a FORM element.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5b3126494e7cb37fbd4e5a7a4552f1b5 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009066062" comment="mozilla-xulrunner191-32bit less than 1.9.1.17-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066063" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.17-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066064" comment="mozilla-xulrunner191-translations less than 1.9.1.17-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066065" comment="mozilla-xulrunner191-x86 less than 1.9.1.17-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066066" comment="mozilla-xulrunner191 less than 1.9.1.17-0.2.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009066062" comment="mozilla-xulrunner191-32bit less than 1.9.1.17-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066063" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.17-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066064" comment="mozilla-xulrunner191-translations less than 1.9.1.17-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066066" comment="mozilla-xulrunner191 less than 1.9.1.17-0.2.1"/>
			</criteria>
		</criteria></criteria>
	<!-- d48e349f4201c980257257ac4c9d7559 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009066067" comment="MozillaFirefox-translations less than 3.6.15-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066068" comment="MozillaFirefox less than 3.6.15-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066069" comment="mozilla-xulrunner192-32bit less than 1.9.2.15-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066070" comment="mozilla-xulrunner192-gnome less than 1.9.2.15-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066071" comment="mozilla-xulrunner192-translations less than 1.9.2.15-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066072" comment="mozilla-xulrunner192-x86 less than 1.9.2.15-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066073" comment="mozilla-xulrunner192 less than 1.9.2.15-0.2.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009066067" comment="MozillaFirefox-translations less than 3.6.15-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066068" comment="MozillaFirefox less than 3.6.15-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066069" comment="mozilla-xulrunner192-32bit less than 1.9.2.15-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066070" comment="mozilla-xulrunner192-gnome less than 1.9.2.15-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066071" comment="mozilla-xulrunner192-translations less than 1.9.2.15-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066073" comment="mozilla-xulrunner192 less than 1.9.2.15-0.2.1"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101623" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1623</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-1623" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1623" source="CVE"/>
	<description>
	Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.10, as used in the mod_reqtimeout module in the Apache HTTP Server and other software, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors related to the destruction of an APR bucket.
	</description>
 </metadata>
<!-- 5e06fa1f1bd27b53b67b9cf61d78c0eb -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009069399" comment="libapr-util1-32bit less than 1.3.4-12.22.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009069400" comment="libapr-util1 less than 1.3.4-12.22.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009069401" comment="libapr-util1 less than 1.3.4-12.22.21.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009069402" comment="libapr1-32bit less than 1.3.3-11.18.17.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009069403" comment="libapr1 less than 1.3.3-11.18.17.1"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009069400" comment="libapr-util1 less than 1.3.4-12.22.21.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009069401" comment="libapr-util1 less than 1.3.4-12.22.21.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009069403" comment="libapr1 less than 1.3.3-11.18.17.1"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101626" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1626</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-1626" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1626" source="CVE"/>
	<description>
	MySQL before 5.1.46 allows local users to delete the data and index files of another user's MyISAM table via a symlink attack in conjunction with the DROP TABLE command, a different vulnerability than CVE-2008-4098 and CVE-2008-7247.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1873ab41de744ae673270530913eb01c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063483" comment="libmysqlclient15-32bit less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063484" comment="libmysqlclient15-x86 less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063485" comment="libmysqlclient15 less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063486" comment="libmysqlclient_r15 less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063487" comment="mysql-Max less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063488" comment="mysql-client less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063489" comment="mysql less than 5.0.67-13.26.1"/>
		</criteria>
	</criteria>
	<!-- 471c09c97921274cec802d6f971c4d92 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063483" comment="libmysqlclient15-32bit less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063484" comment="libmysqlclient15-x86 less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063485" comment="libmysqlclient15 less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063486" comment="libmysqlclient_r15 less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063487" comment="mysql-Max less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063488" comment="mysql-client less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063489" comment="mysql less than 5.0.67-13.26.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063483" comment="libmysqlclient15-32bit less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063485" comment="libmysqlclient15 less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063486" comment="libmysqlclient_r15 less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063487" comment="mysql-Max less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063488" comment="mysql-client less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063489" comment="mysql less than 5.0.67-13.26.1"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101628" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1628</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1628" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1628" source="CVE"/>
	<description>
	Ghostscript 8.64, 8.70, and possibly other versions allows context-dependent attackers to execute arbitrary code via a PostScript file containing unlimited recursive procedure invocations, which trigger memory corruption in the stack of the interpreter.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 050a560119b003b7f093735ee4ea36d0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061853" comment="ghostscript-fonts-other less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061854" comment="ghostscript-fonts-rus less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061855" comment="ghostscript-fonts-std less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061856" comment="ghostscript-library less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061857" comment="ghostscript-omni less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061858" comment="ghostscript-x11 less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061859" comment="libgimpprint less than 4.2.7-32.28.1"/>
		</criteria>
	</criteria>
	<!-- 8ea47e7a8ca134ad54f518d9ea69e5c0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061860" comment="ghostscript-fonts-other less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061861" comment="ghostscript-fonts-rus less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061862" comment="ghostscript-fonts-std less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061863" comment="ghostscript-library less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061864" comment="ghostscript-omni less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061865" comment="ghostscript-x11 less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061866" comment="libgimpprint less than 4.2.7-32.27.26.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101634" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1634</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-1634" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1634" source="CVE"/>
	<description>
	Multiple integer overflows in audioop.c in the audioop module in Python 2.6, 2.7, 3.1, and 3.2 allow context-dependent attackers to cause a denial of service (application crash) via a large fragment, as demonstrated by a call to audioop.lin2lin with a long string in the first argument, leading to a buffer overflow.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-3143.5.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2aff67bb465d1d97e63189fa1499680b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064997" comment="libpython2_6-1_0-32bit less than 2.6.0-8.8.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064998" comment="libpython2_6-1_0-x86 less than 2.6.0-8.8.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064999" comment="libpython2_6-1_0 less than 2.6.0-8.8.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065000" comment="python-32bit less than 2.6.0-8.9.6.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065001" comment="python-base-32bit less than 2.6.0-8.8.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065002" comment="python-base-x86 less than 2.6.0-8.8.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065003" comment="python-base less than 2.6.0-8.8.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065004" comment="python-curses less than 2.6.0-8.9.6.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065005" comment="python-demo less than 2.6.0-8.9.6.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065006" comment="python-gdbm less than 2.6.0-8.9.6.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065007" comment="python-idle less than 2.6.0-8.9.6.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065008" comment="python-tk less than 2.6.0-8.9.6.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065009" comment="python-x86 less than 2.6.0-8.9.6.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065010" comment="python-xml less than 2.6.0-8.8.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065011" comment="python less than 2.6.0-8.9.6.2"/>
		</criteria>
	</criteria>
	<!-- bf45eab61dc9da04aa81b9581e8eab85 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009065012" comment="libpython2_6-1_0-32bit less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065013" comment="libpython2_6-1_0-x86 less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065014" comment="libpython2_6-1_0 less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065015" comment="python-32bit less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065016" comment="python-base-32bit less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065017" comment="python-base-x86 less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065018" comment="python-base less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065019" comment="python-curses less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065020" comment="python-demo less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065021" comment="python-gdbm less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065022" comment="python-idle less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065023" comment="python-tk less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065024" comment="python-x86 less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065025" comment="python-xml less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065026" comment="python less than 2.6.0-8.10.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009065012" comment="libpython2_6-1_0-32bit less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065014" comment="libpython2_6-1_0 less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065015" comment="python-32bit less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065016" comment="python-base-32bit less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065018" comment="python-base less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065019" comment="python-curses less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065020" comment="python-demo less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065021" comment="python-gdbm less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065022" comment="python-idle less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065023" comment="python-tk less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065025" comment="python-xml less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065026" comment="python less than 2.6.0-8.10.1"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101635" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1635</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1635" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1635" source="CVE"/>
	<description>
	The chain_reply function in process.c in smbd in Samba before 3.4.8 and 3.5.x before 3.5.2 allows remote attackers to cause a denial of service (NULL pointer dereference and process crash) via a Negotiate Protocol request with a certain 0x0003 field value followed by a Session Setup AndX request with a certain 0x8003 field value.
	</description>
 </metadata>
<!-- a35d137f63812ef26e72ebf6bc667db4 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009062261" comment="cifs-mount less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062262" comment="ldapsmb less than 1.34b-11.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062263" comment="libsmbclient0-32bit less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062264" comment="libsmbclient0-x86 less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062265" comment="libsmbclient0 less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062266" comment="libtalloc1-32bit less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062267" comment="libtalloc1-x86 less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062268" comment="libtalloc1 less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062269" comment="libtdb1-32bit less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062270" comment="libtdb1-x86 less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062271" comment="libtdb1 less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062272" comment="libwbclient0-32bit less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062273" comment="libwbclient0-x86 less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062274" comment="libwbclient0 less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062275" comment="samba-32bit less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062276" comment="samba-client-32bit less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062277" comment="samba-client-x86 less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062278" comment="samba-client less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062279" comment="samba-doc less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062280" comment="samba-krb-printing less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062281" comment="samba-winbind-32bit less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062282" comment="samba-winbind-x86 less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062283" comment="samba-winbind less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062284" comment="samba-x86 less than 3.4.3-1.18.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062285" comment="samba less than 3.4.3-1.18.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101639" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1639</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1639" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1639" source="CVE"/>
	<description>
	The cli_pdf function in libclamav/pdf.c in ClamAV before 0.96.1 allows remote attackers to cause a denial of service (crash) via a malformed PDF file, related to an inconsistency in the calculated stream length and the real stream length.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 20f5aca22421a30b30c0800846b2cee7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061754" comment="clamav less than 0.96.1-0.1.1"/>
	</criteria>
	<!-- 37527c910209c36cd43ddbbcbba1c5e1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061754" comment="clamav less than 0.96.1-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101640" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1640</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1640" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1640" source="CVE"/>
	<description>
	Off-by-one error in the parseicon function in libclamav/pe_icons.c in ClamAV 0.96 allows remote attackers to cause a denial of service (crash) via a crafted PE icon that triggers an out-of-bounds read, related to improper rounding during scaling.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 20f5aca22421a30b30c0800846b2cee7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061754" comment="clamav less than 0.96.1-0.1.1"/>
	</criteria>
	<!-- 37527c910209c36cd43ddbbcbba1c5e1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061754" comment="clamav less than 0.96.1-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101641" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1641</title>
	<affected family="unix">
		<platform>SLE 11 SERVER Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1641" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1641" source="CVE"/>
	<description>
	The do_gfs2_set_flags function in fs/gfs2/file.c in the Linux kernel before 2.6.34-git10 does not verify the ownership of a file, which allows local users to bypass intended access restrictions via a SETFLAGS ioctl request.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 01f44594f9d8615a4c725ad4472abb2b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061868" comment="btrfs-kmp-default less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061869" comment="btrfs-kmp-xen less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061870" comment="ext4dev-kmp-default less than 0_2.6.32.13_0.5-7.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061871" comment="ext4dev-kmp-xen less than 0_2.6.32.13_0.5-7.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061872" comment="hyper-v-kmp-default less than 0_2.6.32.13_0.5-0.7.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061873" comment="kernel-default-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061874" comment="kernel-default-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061875" comment="kernel-default less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061876" comment="kernel-source less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061877" comment="kernel-syms less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061878" comment="kernel-trace-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061879" comment="kernel-trace-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061880" comment="kernel-trace less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061881" comment="kernel-xen-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061882" comment="kernel-xen-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061883" comment="kernel-xen less than 2.6.32.13-0.5.1"/>
		</criteria>
	</criteria>
	<!-- 06ee9fa41e8722a56ab4c7b8f6a7be72 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061868" comment="btrfs-kmp-default less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061870" comment="ext4dev-kmp-default less than 0_2.6.32.13_0.5-7.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061873" comment="kernel-default-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061874" comment="kernel-default-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061884" comment="kernel-default-man less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061875" comment="kernel-default less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061876" comment="kernel-source less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061877" comment="kernel-syms less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061878" comment="kernel-trace-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061879" comment="kernel-trace-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061880" comment="kernel-trace less than 2.6.32.13-0.5.1"/>
		</criteria>
	</criteria>
	<!-- 18bb8606d302505049983784dc2eae07 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061868" comment="btrfs-kmp-default less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061870" comment="ext4dev-kmp-default less than 0_2.6.32.13_0.5-7.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061873" comment="kernel-default-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061874" comment="kernel-default-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061875" comment="kernel-default less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061876" comment="kernel-source less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061877" comment="kernel-syms less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061878" comment="kernel-trace-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061879" comment="kernel-trace-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061880" comment="kernel-trace less than 2.6.32.13-0.5.1"/>
		</criteria>
	</criteria>
	<!-- 2959a2080579b86be5f71889c23098f9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061702" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061678" comment="kernel-kdump less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061682" comment="kernel-ppc64-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061684" comment="kernel-ppc64 less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 2c10f83a368b9104456f6181c617a477 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061868" comment="btrfs-kmp-default less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061870" comment="ext4dev-kmp-default less than 0_2.6.32.13_0.5-7.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061885" comment="ext4dev-kmp-ppc64 less than 0_2.6.32.13_0.5-7.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061873" comment="kernel-default-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061874" comment="kernel-default-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061875" comment="kernel-default less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061886" comment="kernel-ppc64-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061887" comment="kernel-ppc64-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061888" comment="kernel-ppc64 less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061876" comment="kernel-source less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061877" comment="kernel-syms less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061878" comment="kernel-trace-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061879" comment="kernel-trace-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061880" comment="kernel-trace less than 2.6.32.13-0.5.1"/>
		</criteria>
	</criteria>
	<!-- 66504af0afe753b5175112b44bc8827d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061703" comment="ext4dev-kmp-pae less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061704" comment="ext4dev-kmp-vmi less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061705" comment="ext4dev-kmp-xen less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061679" comment="kernel-pae-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061681" comment="kernel-pae less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061706" comment="kernel-vmi-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061707" comment="kernel-vmi less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 99ed0d9e003dfe8866db7105d4850a09 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- c8a29eec659b0b2b3e85c610b67beacd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061705" comment="ext4dev-kmp-xen less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- caf966715fc66f993dd8892aa75742ad -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061868" comment="btrfs-kmp-default less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061889" comment="btrfs-kmp-pae less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061869" comment="btrfs-kmp-xen less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061870" comment="ext4dev-kmp-default less than 0_2.6.32.13_0.5-7.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061890" comment="ext4dev-kmp-pae less than 0_2.6.32.13_0.5-7.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061871" comment="ext4dev-kmp-xen less than 0_2.6.32.13_0.5-7.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061872" comment="hyper-v-kmp-default less than 0_2.6.32.13_0.5-0.7.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061891" comment="hyper-v-kmp-pae less than 0_2.6.32.13_0.5-0.7.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061873" comment="kernel-default-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061874" comment="kernel-default-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061875" comment="kernel-default less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061892" comment="kernel-pae-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061893" comment="kernel-pae-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061894" comment="kernel-pae less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061876" comment="kernel-source less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061877" comment="kernel-syms less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061878" comment="kernel-trace-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061879" comment="kernel-trace-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061880" comment="kernel-trace less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061881" comment="kernel-xen-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061882" comment="kernel-xen-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061883" comment="kernel-xen less than 2.6.32.13-0.5.1"/>
		</criteria>
	</criteria>
	<!-- f73f22d4b713e9a7674cc8c4eebf91dd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061708" comment="kernel-default-man less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101643" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1643</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-1643" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1643" source="CVE"/>
	<description>
	mm/shmem.c in the Linux kernel before 2.6.28-rc3, when strict overcommit is enabled, does not properly handle the export of shmemfs objects by knfsd, which allows attackers to cause a denial of service (NULL pointer dereference and knfsd crash) or possibly have unspecified other impact via unknown vectors.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2959a2080579b86be5f71889c23098f9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061702" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061678" comment="kernel-kdump less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061682" comment="kernel-ppc64-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061684" comment="kernel-ppc64 less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 66504af0afe753b5175112b44bc8827d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061703" comment="ext4dev-kmp-pae less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061704" comment="ext4dev-kmp-vmi less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061705" comment="ext4dev-kmp-xen less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061679" comment="kernel-pae-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061681" comment="kernel-pae less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061706" comment="kernel-vmi-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061707" comment="kernel-vmi less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 99ed0d9e003dfe8866db7105d4850a09 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- c8a29eec659b0b2b3e85c610b67beacd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061705" comment="ext4dev-kmp-xen less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- f73f22d4b713e9a7674cc8c4eebf91dd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061708" comment="kernel-default-man less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101674" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1674</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-1674" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1674" source="CVE"/>
	<description>
	The extended-community parser in bgpd in Quagga before 0.99.18 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed Extended Communities attribute.
	</description>
 </metadata>
<!-- 1d86854c93d3c1a2cb8a819db9b2c8a8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066668" comment="quagga less than 0.99.15-0.4.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101675" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1675</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-1675" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1675" source="CVE"/>
	<description>
	bgpd in Quagga before 0.99.18 allows remote attackers to cause a denial of service (session reset) via a malformed AS_PATHLIMIT path attribute.
	</description>
 </metadata>
<!-- 1d86854c93d3c1a2cb8a819db9b2c8a8 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066668" comment="quagga less than 0.99.15-0.4.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101748" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1748</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-1748" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1748" source="CVE"/>
	<description>
	The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request, as demonstated by the (1) /admin?OP=redirect&amp;URL=% and (2) /admin?URL=/admin/&amp;OP=% URIs.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- d603aeff8a309d9d04651d4469e31973 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064776" comment="cups-client less than 1.3.9-8.37.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064777" comment="cups-libs-32bit less than 1.3.9-8.37.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064778" comment="cups-libs-x86 less than 1.3.9-8.37.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064779" comment="cups-libs less than 1.3.9-8.37.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064780" comment="cups less than 1.3.9-8.37.1"/>
		</criteria>
	</criteria>
	<!-- e290f3059978b800480c09727b4b714a -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064776" comment="cups-client less than 1.3.9-8.37.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064777" comment="cups-libs-32bit less than 1.3.9-8.37.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064778" comment="cups-libs-x86 less than 1.3.9-8.37.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064779" comment="cups-libs less than 1.3.9-8.37.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064780" comment="cups less than 1.3.9-8.37.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064776" comment="cups-client less than 1.3.9-8.37.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064777" comment="cups-libs-32bit less than 1.3.9-8.37.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064779" comment="cups-libs less than 1.3.9-8.37.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064780" comment="cups less than 1.3.9-8.37.1"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101797" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1797</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-1797" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1797" source="CVE"/>
	<description>
	Multiple stack-based buffer overflows in the cff_decoder_parse_charstrings function in the CFF Type2 CharStrings interpreter in cff/cffgload.c in FreeType before 2.4.2, as used in Apple iOS before 4.0.2 on the iPhone and iPod touch and before 3.2.2 on the iPad, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted CFF opcodes in embedded fonts in a PDF document, as demonstrated by JailbreakMe. NOTE: some of these details are obtained from third party information.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 7bcc9a1fade88c7620df728424de42c5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062064" comment="freetype2-x86 less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
	<!-- f28613bd3eb0b0f8e83bbf97c432760b -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062064" comment="freetype2-x86 less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101848" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1848</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-1848" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1848" source="CVE"/>
	<description>
	Directory traversal vulnerability in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to bypass intended table grants to read field definitions of arbitrary tables, and on 5.1 to read or delete content of arbitrary tables, via a .. (dot dot) in a table name.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1873ab41de744ae673270530913eb01c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063483" comment="libmysqlclient15-32bit less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063484" comment="libmysqlclient15-x86 less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063485" comment="libmysqlclient15 less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063486" comment="libmysqlclient_r15 less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063487" comment="mysql-Max less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063488" comment="mysql-client less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063489" comment="mysql less than 5.0.67-13.26.1"/>
		</criteria>
	</criteria>
	<!-- 471c09c97921274cec802d6f971c4d92 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063483" comment="libmysqlclient15-32bit less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063484" comment="libmysqlclient15-x86 less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063485" comment="libmysqlclient15 less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063486" comment="libmysqlclient_r15 less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063487" comment="mysql-Max less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063488" comment="mysql-client less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063489" comment="mysql less than 5.0.67-13.26.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063483" comment="libmysqlclient15-32bit less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063485" comment="libmysqlclient15 less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063486" comment="libmysqlclient_r15 less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063487" comment="mysql-Max less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063488" comment="mysql-client less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063489" comment="mysql less than 5.0.67-13.26.1"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101849" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1849</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-1849" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1849" source="CVE"/>
	<description>
	The my_net_skip_rest function in sql/net_serv.cc in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by sending a large number of packets that exceed the maximum length.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1873ab41de744ae673270530913eb01c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063483" comment="libmysqlclient15-32bit less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063484" comment="libmysqlclient15-x86 less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063485" comment="libmysqlclient15 less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063486" comment="libmysqlclient_r15 less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063487" comment="mysql-Max less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063488" comment="mysql-client less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063489" comment="mysql less than 5.0.67-13.26.1"/>
		</criteria>
	</criteria>
	<!-- 471c09c97921274cec802d6f971c4d92 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063483" comment="libmysqlclient15-32bit less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063484" comment="libmysqlclient15-x86 less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063485" comment="libmysqlclient15 less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063486" comment="libmysqlclient_r15 less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063487" comment="mysql-Max less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063488" comment="mysql-client less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063489" comment="mysql less than 5.0.67-13.26.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063483" comment="libmysqlclient15-32bit less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063485" comment="libmysqlclient15 less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063486" comment="libmysqlclient_r15 less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063487" comment="mysql-Max less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063488" comment="mysql-client less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063489" comment="mysql less than 5.0.67-13.26.1"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101850" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1850</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-1850" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1850" source="CVE"/>
	<description>
	Buffer overflow in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to execute arbitrary code via a COM_FIELD_LIST command with a long table name.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1873ab41de744ae673270530913eb01c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063483" comment="libmysqlclient15-32bit less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063484" comment="libmysqlclient15-x86 less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063485" comment="libmysqlclient15 less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063486" comment="libmysqlclient_r15 less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063487" comment="mysql-Max less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063488" comment="mysql-client less than 5.0.67-13.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063489" comment="mysql less than 5.0.67-13.26.1"/>
		</criteria>
	</criteria>
	<!-- 471c09c97921274cec802d6f971c4d92 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063483" comment="libmysqlclient15-32bit less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063484" comment="libmysqlclient15-x86 less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063485" comment="libmysqlclient15 less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063486" comment="libmysqlclient_r15 less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063487" comment="mysql-Max less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063488" comment="mysql-client less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063489" comment="mysql less than 5.0.67-13.26.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063483" comment="libmysqlclient15-32bit less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063485" comment="libmysqlclient15 less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063486" comment="libmysqlclient_r15 less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063487" comment="mysql-Max less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063488" comment="mysql-client less than 5.0.67-13.26.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063489" comment="mysql less than 5.0.67-13.26.1"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101866" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1866</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1866" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1866" source="CVE"/>
	<description>
	The dechunk filter in PHP 5.3 through 5.3.2, when decoding an HTTP chunked encoding stream, allows context-dependent attackers to cause a denial of service (crash) and possibly trigger memory corruption via a negative chunk size, which bypasses a signed comparison, related to an integer overflow in the chunk size decoder.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 192c274ce8afb5e5f6a207e8c4e39e5d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062323" comment="apache2-mod_php5 less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062324" comment="php5-bcmath less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062325" comment="php5-bz2 less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062326" comment="php5-calendar less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062327" comment="php5-ctype less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062328" comment="php5-curl less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062329" comment="php5-dba less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062330" comment="php5-dbase less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062331" comment="php5-dom less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062332" comment="php5-exif less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062333" comment="php5-fastcgi less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062334" comment="php5-ftp less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062335" comment="php5-gd less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062336" comment="php5-gettext less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062337" comment="php5-gmp less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062338" comment="php5-hash less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062339" comment="php5-iconv less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062340" comment="php5-json less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062341" comment="php5-ldap less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062342" comment="php5-mbstring less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062343" comment="php5-mcrypt less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062344" comment="php5-mysql less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062345" comment="php5-odbc less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062346" comment="php5-openssl less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062347" comment="php5-pcntl less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062348" comment="php5-pdo less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062349" comment="php5-pear less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062350" comment="php5-pgsql less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062351" comment="php5-pspell less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062352" comment="php5-shmop less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062353" comment="php5-snmp less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062354" comment="php5-soap less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062355" comment="php5-suhosin less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062356" comment="php5-sysvmsg less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062357" comment="php5-sysvsem less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062358" comment="php5-sysvshm less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062359" comment="php5-tokenizer less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062360" comment="php5-wddx less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062361" comment="php5-xmlreader less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062362" comment="php5-xmlrpc less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062363" comment="php5-xmlwriter less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062364" comment="php5-xsl less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062365" comment="php5-zip less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062366" comment="php5-zlib less than 5.2.14-0.1.1"/>
		</criteria>
	</criteria>
	<!-- d9f07e551f70d0ed3756c02a021f2fec -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062323" comment="apache2-mod_php5 less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062324" comment="php5-bcmath less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062325" comment="php5-bz2 less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062326" comment="php5-calendar less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062327" comment="php5-ctype less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062328" comment="php5-curl less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062329" comment="php5-dba less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062330" comment="php5-dbase less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062331" comment="php5-dom less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062332" comment="php5-exif less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062333" comment="php5-fastcgi less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062334" comment="php5-ftp less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062335" comment="php5-gd less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062336" comment="php5-gettext less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062337" comment="php5-gmp less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062338" comment="php5-hash less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062339" comment="php5-iconv less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062340" comment="php5-json less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062341" comment="php5-ldap less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062342" comment="php5-mbstring less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062343" comment="php5-mcrypt less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062344" comment="php5-mysql less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062345" comment="php5-odbc less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062346" comment="php5-openssl less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062347" comment="php5-pcntl less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062348" comment="php5-pdo less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062349" comment="php5-pear less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062350" comment="php5-pgsql less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062351" comment="php5-pspell less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062352" comment="php5-shmop less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062353" comment="php5-snmp less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062354" comment="php5-soap less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062355" comment="php5-suhosin less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062356" comment="php5-sysvmsg less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062357" comment="php5-sysvsem less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062358" comment="php5-sysvshm less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062359" comment="php5-tokenizer less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062360" comment="php5-wddx less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062361" comment="php5-xmlreader less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062362" comment="php5-xmlrpc less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062363" comment="php5-xmlwriter less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062364" comment="php5-xsl less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062365" comment="php5-zip less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062366" comment="php5-zlib less than 5.2.14-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101869" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1869</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1869" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1869" source="CVE"/>
	<description>
	Stack-based buffer overflow in the parser function in GhostScript 8.70 and 8.64 allows context-dependent attackers to execute arbitrary code via a crafted PostScript file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 050a560119b003b7f093735ee4ea36d0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061853" comment="ghostscript-fonts-other less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061854" comment="ghostscript-fonts-rus less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061855" comment="ghostscript-fonts-std less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061856" comment="ghostscript-library less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061857" comment="ghostscript-omni less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061858" comment="ghostscript-x11 less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061859" comment="libgimpprint less than 4.2.7-32.28.1"/>
		</criteria>
	</criteria>
	<!-- 8ea47e7a8ca134ad54f518d9ea69e5c0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061860" comment="ghostscript-fonts-other less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061861" comment="ghostscript-fonts-rus less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061862" comment="ghostscript-fonts-std less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061863" comment="ghostscript-library less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061864" comment="ghostscript-omni less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061865" comment="ghostscript-x11 less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061866" comment="libgimpprint less than 4.2.7-32.27.26.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101975" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-1975</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-1975" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1975" source="CVE"/>
	<description>
	PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, and 8.4 before 8.4.4 does not properly check privileges during certain RESET ALL operations, which allows remote authenticated users to remove arbitrary parameter settings via a (1) ALTER USER or (2) ALTER DATABASE statement.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1623a9038b26e4b2fb345e388ebf6ca9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061271" comment="postgresql-contrib less than 8.3.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061272" comment="postgresql-docs less than 8.3.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061273" comment="postgresql-libs-32bit less than 8.3.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061274" comment="postgresql-libs-x86 less than 8.3.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061275" comment="postgresql-libs less than 8.3.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061276" comment="postgresql-server less than 8.3.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061277" comment="postgresql less than 8.3.11-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 3583616cbc2a604051aee34d4ba07c2c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061277" comment="postgresql less than 8.3.11-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102055" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2055</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2055" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2055" source="CVE"/>
	<description>
	Ghostscript 8.71 and earlier reads initialization files from the current working directory, which allows local users to execute arbitrary PostScript commands via a Trojan horse file, related to improper support for the -P- option to the gs program.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 050a560119b003b7f093735ee4ea36d0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061853" comment="ghostscript-fonts-other less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061854" comment="ghostscript-fonts-rus less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061855" comment="ghostscript-fonts-std less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061856" comment="ghostscript-library less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061857" comment="ghostscript-omni less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061858" comment="ghostscript-x11 less than 8.62-32.28.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061859" comment="libgimpprint less than 4.2.7-32.28.1"/>
		</criteria>
	</criteria>
	<!-- 8ea47e7a8ca134ad54f518d9ea69e5c0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061860" comment="ghostscript-fonts-other less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061861" comment="ghostscript-fonts-rus less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061862" comment="ghostscript-fonts-std less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061863" comment="ghostscript-library less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061864" comment="ghostscript-omni less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061865" comment="ghostscript-x11 less than 8.62-32.27.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061866" comment="libgimpprint less than 4.2.7-32.27.26.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102059" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2059</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2059" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2059" source="CVE"/>
	<description>
	lib/fsm.c in RPM 4.8.0 and unspecified 4.7.x and 4.6.x versions, and RPM before 4.4.3, does not properly reset the metadata of an executable file during replacement of the file in an RPM package upgrade, which might allow local users to gain privileges by creating a hard link to a vulnerable (1) setuid or (2) setgid file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 32f4960f9da43da922885fefb185f7d9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062630" comment="popt-32bit less than 1.7-37.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062631" comment="popt-x86 less than 1.7-37.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062632" comment="popt less than 1.7-37.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062633" comment="rpm-32bit less than 4.4.2.3-37.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062634" comment="rpm-x86 less than 4.4.2.3-37.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062635" comment="rpm less than 4.4.2.3-37.18.1"/>
		</criteria>
	</criteria>
	<!-- 63795266ceb69301f2e2befb061ad04f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062630" comment="popt-32bit less than 1.7-37.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062631" comment="popt-x86 less than 1.7-37.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062632" comment="popt less than 1.7-37.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062633" comment="rpm-32bit less than 4.4.2.3-37.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062634" comment="rpm-x86 less than 4.4.2.3-37.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062635" comment="rpm less than 4.4.2.3-37.18.1"/>
		</criteria>
	</criteria>
	<!-- a609488caffd89cdc3149aaed0a4cf7c -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064944" comment="popt-32bit less than 1.7-37.25.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064945" comment="popt-x86 less than 1.7-37.25.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064946" comment="popt less than 1.7-37.25.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064947" comment="rpm-32bit less than 4.4.2.3-37.25.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064948" comment="rpm-x86 less than 4.4.2.3-37.25.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064949" comment="rpm less than 4.4.2.3-37.25.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064944" comment="popt-32bit less than 1.7-37.25.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064946" comment="popt less than 1.7-37.25.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064947" comment="rpm-32bit less than 4.4.2.3-37.25.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064949" comment="rpm less than 4.4.2.3-37.25.1"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102063" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2063</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
	</affected>
	<reference ref_id="CVE-2010-2063" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2063" source="CVE"/>
	<description>
	Buffer overflow in the SMB1 packet chaining implementation in the chain_reply function in process.c in smbd in Samba 3.0.x before 3.3.13 allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a crafted field in a packet.
	</description>
 </metadata>
<!-- 38b274074b3d5ef4abafff31fa80e561 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060901" comment="cifs-mount less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060902" comment="ldapsmb less than 1.34b-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060903" comment="libsmbclient0-32bit less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060904" comment="libsmbclient0-x86 less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060905" comment="libsmbclient0 less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060906" comment="libtalloc1-32bit less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060907" comment="libtalloc1-x86 less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060908" comment="libtalloc1 less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060909" comment="libtdb1-32bit less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060910" comment="libtdb1-x86 less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060911" comment="libtdb1 less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060912" comment="libwbclient0-32bit less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060913" comment="libwbclient0-x86 less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060914" comment="libwbclient0 less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060915" comment="samba-32bit less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060916" comment="samba-client-32bit less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060917" comment="samba-client-x86 less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060918" comment="samba-client less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060919" comment="samba-krb-printing less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060920" comment="samba-winbind-32bit less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060921" comment="samba-winbind-x86 less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060922" comment="samba-winbind less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060923" comment="samba-x86 less than 3.2.7-11.20.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009060924" comment="samba less than 3.2.7-11.20.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102066" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2066</title>
	<affected family="unix">
		<platform>SLE 11 SERVER Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2066" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2066" source="CVE"/>
	<description>
	The mext_check_arguments function in fs/ext4/move_extent.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a MOVE_EXT ioctl call that specifies this file as a donor.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 01f44594f9d8615a4c725ad4472abb2b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061868" comment="btrfs-kmp-default less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061869" comment="btrfs-kmp-xen less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061870" comment="ext4dev-kmp-default less than 0_2.6.32.13_0.5-7.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061871" comment="ext4dev-kmp-xen less than 0_2.6.32.13_0.5-7.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061872" comment="hyper-v-kmp-default less than 0_2.6.32.13_0.5-0.7.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061873" comment="kernel-default-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061874" comment="kernel-default-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061875" comment="kernel-default less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061876" comment="kernel-source less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061877" comment="kernel-syms less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061878" comment="kernel-trace-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061879" comment="kernel-trace-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061880" comment="kernel-trace less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061881" comment="kernel-xen-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061882" comment="kernel-xen-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061883" comment="kernel-xen less than 2.6.32.13-0.5.1"/>
		</criteria>
	</criteria>
	<!-- 06ee9fa41e8722a56ab4c7b8f6a7be72 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061868" comment="btrfs-kmp-default less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061870" comment="ext4dev-kmp-default less than 0_2.6.32.13_0.5-7.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061873" comment="kernel-default-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061874" comment="kernel-default-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061884" comment="kernel-default-man less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061875" comment="kernel-default less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061876" comment="kernel-source less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061877" comment="kernel-syms less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061878" comment="kernel-trace-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061879" comment="kernel-trace-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061880" comment="kernel-trace less than 2.6.32.13-0.5.1"/>
		</criteria>
	</criteria>
	<!-- 18bb8606d302505049983784dc2eae07 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061868" comment="btrfs-kmp-default less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061870" comment="ext4dev-kmp-default less than 0_2.6.32.13_0.5-7.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061873" comment="kernel-default-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061874" comment="kernel-default-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061875" comment="kernel-default less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061876" comment="kernel-source less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061877" comment="kernel-syms less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061878" comment="kernel-trace-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061879" comment="kernel-trace-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061880" comment="kernel-trace less than 2.6.32.13-0.5.1"/>
		</criteria>
	</criteria>
	<!-- 2c10f83a368b9104456f6181c617a477 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061868" comment="btrfs-kmp-default less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061870" comment="ext4dev-kmp-default less than 0_2.6.32.13_0.5-7.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061885" comment="ext4dev-kmp-ppc64 less than 0_2.6.32.13_0.5-7.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061873" comment="kernel-default-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061874" comment="kernel-default-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061875" comment="kernel-default less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061886" comment="kernel-ppc64-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061887" comment="kernel-ppc64-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061888" comment="kernel-ppc64 less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061876" comment="kernel-source less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061877" comment="kernel-syms less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061878" comment="kernel-trace-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061879" comment="kernel-trace-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061880" comment="kernel-trace less than 2.6.32.13-0.5.1"/>
		</criteria>
	</criteria>
	<!-- caf966715fc66f993dd8892aa75742ad -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061868" comment="btrfs-kmp-default less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061889" comment="btrfs-kmp-pae less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061869" comment="btrfs-kmp-xen less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061870" comment="ext4dev-kmp-default less than 0_2.6.32.13_0.5-7.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061890" comment="ext4dev-kmp-pae less than 0_2.6.32.13_0.5-7.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061871" comment="ext4dev-kmp-xen less than 0_2.6.32.13_0.5-7.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061872" comment="hyper-v-kmp-default less than 0_2.6.32.13_0.5-0.7.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061891" comment="hyper-v-kmp-pae less than 0_2.6.32.13_0.5-0.7.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061873" comment="kernel-default-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061874" comment="kernel-default-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061875" comment="kernel-default less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061892" comment="kernel-pae-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061893" comment="kernel-pae-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061894" comment="kernel-pae less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061876" comment="kernel-source less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061877" comment="kernel-syms less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061878" comment="kernel-trace-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061879" comment="kernel-trace-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061880" comment="kernel-trace less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061881" comment="kernel-xen-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061882" comment="kernel-xen-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061883" comment="kernel-xen less than 2.6.32.13-0.5.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102074" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2074</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2074" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2074" source="CVE"/>
	<description>
	istream.c in w3m 0.5.2 and possibly other versions, when ssl_verify_server is enabled, does not properly handle a '\0' character in a domain name in the (1) subject's Common Name or (2) Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- e1f25a08a12598e8317948de7f9884c3 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061665" comment="w3m less than 0.5.2-128.18.1"/>
	</criteria>
	<!-- ebf1dbef4636e519d87ba8de9c445943 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061666" comment="w3m less than 0.5.2-132.2.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102077" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2077</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2077" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2077" source="CVE"/>
	<description>
	** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2010-1640.  Reason: This candidate is a duplicate of CVE-2010-1640.  Notes: All CVE users should reference CVE-2010-1640 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 20f5aca22421a30b30c0800846b2cee7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061754" comment="clamav less than 0.96.1-0.1.1"/>
	</criteria>
	<!-- 37527c910209c36cd43ddbbcbba1c5e1 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061754" comment="clamav less than 0.96.1-0.1.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102089" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2089</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2089" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2089" source="CVE"/>
	<description>
	The audioop module in Python 2.7 and 3.2 does not verify the relationships between size arguments and byte string lengths, which allows context-dependent attackers to cause a denial of service (memory corruption and application crash) via crafted arguments, as demonstrated by a call to audioop.reverse with a one-byte string, a different vulnerability than CVE-2010-1634.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 2aff67bb465d1d97e63189fa1499680b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064997" comment="libpython2_6-1_0-32bit less than 2.6.0-8.8.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064998" comment="libpython2_6-1_0-x86 less than 2.6.0-8.8.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064999" comment="libpython2_6-1_0 less than 2.6.0-8.8.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065000" comment="python-32bit less than 2.6.0-8.9.6.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065001" comment="python-base-32bit less than 2.6.0-8.8.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065002" comment="python-base-x86 less than 2.6.0-8.8.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065003" comment="python-base less than 2.6.0-8.8.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065004" comment="python-curses less than 2.6.0-8.9.6.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065005" comment="python-demo less than 2.6.0-8.9.6.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065006" comment="python-gdbm less than 2.6.0-8.9.6.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065007" comment="python-idle less than 2.6.0-8.9.6.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065008" comment="python-tk less than 2.6.0-8.9.6.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065009" comment="python-x86 less than 2.6.0-8.9.6.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065010" comment="python-xml less than 2.6.0-8.8.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065011" comment="python less than 2.6.0-8.9.6.2"/>
		</criteria>
	</criteria>
	<!-- bf45eab61dc9da04aa81b9581e8eab85 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009065012" comment="libpython2_6-1_0-32bit less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065013" comment="libpython2_6-1_0-x86 less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065014" comment="libpython2_6-1_0 less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065015" comment="python-32bit less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065016" comment="python-base-32bit less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065017" comment="python-base-x86 less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065018" comment="python-base less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065019" comment="python-curses less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065020" comment="python-demo less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065021" comment="python-gdbm less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065022" comment="python-idle less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065023" comment="python-tk less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065024" comment="python-x86 less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065025" comment="python-xml less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065026" comment="python less than 2.6.0-8.10.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009065012" comment="libpython2_6-1_0-32bit less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065014" comment="libpython2_6-1_0 less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065015" comment="python-32bit less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065016" comment="python-base-32bit less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065018" comment="python-base less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065019" comment="python-curses less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065020" comment="python-demo less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065021" comment="python-gdbm less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065022" comment="python-idle less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065023" comment="python-tk less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065025" comment="python-xml less than 2.6.0-8.10.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065026" comment="python less than 2.6.0-8.10.1"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102094" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2094</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2094" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2094" source="CVE"/>
	<description>
	Multiple format string vulnerabilities in the phar extension in PHP 5.3 before 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) and possibly execute arbitrary code via a crafted phar:// URI that is not properly handled by the (1) phar_stream_flush, (2) phar_wrapper_unlink, (3) phar_parse_url, or (4) phar_wrapper_open_url functions in ext/phar/stream.c; and the (5) phar_wrapper_open_dir function in ext/phar/dirstream.c, which triggers errors in the php_stream_wrapper_log_error function.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 192c274ce8afb5e5f6a207e8c4e39e5d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062323" comment="apache2-mod_php5 less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062324" comment="php5-bcmath less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062325" comment="php5-bz2 less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062326" comment="php5-calendar less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062327" comment="php5-ctype less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062328" comment="php5-curl less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062329" comment="php5-dba less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062330" comment="php5-dbase less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062331" comment="php5-dom less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062332" comment="php5-exif less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062333" comment="php5-fastcgi less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062334" comment="php5-ftp less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062335" comment="php5-gd less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062336" comment="php5-gettext less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062337" comment="php5-gmp less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062338" comment="php5-hash less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062339" comment="php5-iconv less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062340" comment="php5-json less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062341" comment="php5-ldap less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062342" comment="php5-mbstring less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062343" comment="php5-mcrypt less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062344" comment="php5-mysql less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062345" comment="php5-odbc less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062346" comment="php5-openssl less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062347" comment="php5-pcntl less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062348" comment="php5-pdo less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062349" comment="php5-pear less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062350" comment="php5-pgsql less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062351" comment="php5-pspell less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062352" comment="php5-shmop less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062353" comment="php5-snmp less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062354" comment="php5-soap less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062355" comment="php5-suhosin less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062356" comment="php5-sysvmsg less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062357" comment="php5-sysvsem less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062358" comment="php5-sysvshm less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062359" comment="php5-tokenizer less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062360" comment="php5-wddx less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062361" comment="php5-xmlreader less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062362" comment="php5-xmlrpc less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062363" comment="php5-xmlwriter less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062364" comment="php5-xsl less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062365" comment="php5-zip less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062366" comment="php5-zlib less than 5.2.14-0.1.1"/>
		</criteria>
	</criteria>
	<!-- d9f07e551f70d0ed3756c02a021f2fec -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062323" comment="apache2-mod_php5 less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062324" comment="php5-bcmath less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062325" comment="php5-bz2 less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062326" comment="php5-calendar less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062327" comment="php5-ctype less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062328" comment="php5-curl less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062329" comment="php5-dba less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062330" comment="php5-dbase less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062331" comment="php5-dom less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062332" comment="php5-exif less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062333" comment="php5-fastcgi less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062334" comment="php5-ftp less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062335" comment="php5-gd less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062336" comment="php5-gettext less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062337" comment="php5-gmp less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062338" comment="php5-hash less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062339" comment="php5-iconv less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062340" comment="php5-json less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062341" comment="php5-ldap less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062342" comment="php5-mbstring less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062343" comment="php5-mcrypt less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062344" comment="php5-mysql less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062345" comment="php5-odbc less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062346" comment="php5-openssl less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062347" comment="php5-pcntl less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062348" comment="php5-pdo less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062349" comment="php5-pear less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062350" comment="php5-pgsql less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062351" comment="php5-pspell less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062352" comment="php5-shmop less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062353" comment="php5-snmp less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062354" comment="php5-soap less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062355" comment="php5-suhosin less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062356" comment="php5-sysvmsg less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062357" comment="php5-sysvsem less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062358" comment="php5-sysvshm less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062359" comment="php5-tokenizer less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062360" comment="php5-wddx less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062361" comment="php5-xmlreader less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062362" comment="php5-xmlrpc less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062363" comment="php5-xmlwriter less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062364" comment="php5-xsl less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062365" comment="php5-zip less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062366" comment="php5-zlib less than 5.2.14-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102221" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2221</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2221" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2221" source="CVE"/>
	<description>
	Multiple buffer overflows in the iSNS implementation in isns.c in (1) Linux SCSI target framework (aka tgt or scsi-target-utils) before 1.0.6, (2) iSCSI Enterprise Target (aka iscsitarget or IET) 1.4.20.1 and earlier, and (3) Generic SCSI Target Subsystem for Linux (aka SCST or iscsi-scst) 1.0.1.1 and earlier allow remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via (a) a long iSCSI Name string in an SCN message or (b) an invalid PDU.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1d0f181fabeecec7ee58bfd9c3780c48 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062375" comment="tgt less than 0.9.0-1.27.1"/>
	</criteria>
	<!-- 204272c38ed26d94a6c1cfc810001299 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062376" comment="tgt less than 0.9.10-0.6.1"/>
	</criteria>
	<!-- 4e58ced289f629acb8d772b382ef45d5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062377" comment="iscsitarget-kmp-default less than 0.4.15_2.6.27.48_0.6-94.14.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062378" comment="iscsitarget-kmp-pae less than 0.4.15_2.6.27.48_0.6-94.14.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062379" comment="iscsitarget-kmp-ppc64 less than 0.4.15_2.6.27.48_0.6-94.14.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062380" comment="iscsitarget-kmp-vmi less than 0.4.15_2.6.27.48_0.6-94.14.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062381" comment="iscsitarget-kmp-xen less than 0.4.15_2.6.27.48_0.6-94.14.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062382" comment="iscsitarget less than 0.4.15-94.14.1"/>
		</criteria>
	</criteria>
	<!-- b2720d1cb13b664616006efc437aaeb0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062383" comment="iscsitarget-kmp-default less than 1.4.19_2.6.32.13_0.5-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062384" comment="iscsitarget-kmp-pae less than 1.4.19_2.6.32.13_0.5-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062385" comment="iscsitarget-kmp-ppc64 less than 1.4.19_2.6.32.13_0.5-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062386" comment="iscsitarget-kmp-xen less than 1.4.19_2.6.32.13_0.5-0.7.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062387" comment="iscsitarget less than 1.4.19-0.7.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102225" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2225</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2225" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2225" source="CVE"/>
	<description>
	Use-after-free vulnerability in the SplObjectStorage unserializer in PHP 5.2.x and 5.3.x through 5.3.2 allows remote attackers to execute arbitrary code or obtain sensitive information via serialized data, related to the PHP unserialize function.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 192c274ce8afb5e5f6a207e8c4e39e5d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062323" comment="apache2-mod_php5 less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062324" comment="php5-bcmath less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062325" comment="php5-bz2 less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062326" comment="php5-calendar less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062327" comment="php5-ctype less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062328" comment="php5-curl less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062329" comment="php5-dba less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062330" comment="php5-dbase less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062331" comment="php5-dom less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062332" comment="php5-exif less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062333" comment="php5-fastcgi less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062334" comment="php5-ftp less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062335" comment="php5-gd less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062336" comment="php5-gettext less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062337" comment="php5-gmp less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062338" comment="php5-hash less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062339" comment="php5-iconv less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062340" comment="php5-json less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062341" comment="php5-ldap less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062342" comment="php5-mbstring less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062343" comment="php5-mcrypt less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062344" comment="php5-mysql less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062345" comment="php5-odbc less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062346" comment="php5-openssl less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062347" comment="php5-pcntl less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062348" comment="php5-pdo less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062349" comment="php5-pear less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062350" comment="php5-pgsql less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062351" comment="php5-pspell less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062352" comment="php5-shmop less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062353" comment="php5-snmp less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062354" comment="php5-soap less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062355" comment="php5-suhosin less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062356" comment="php5-sysvmsg less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062357" comment="php5-sysvsem less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062358" comment="php5-sysvshm less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062359" comment="php5-tokenizer less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062360" comment="php5-wddx less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062361" comment="php5-xmlreader less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062362" comment="php5-xmlrpc less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062363" comment="php5-xmlwriter less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062364" comment="php5-xsl less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062365" comment="php5-zip less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062366" comment="php5-zlib less than 5.2.14-0.1.1"/>
		</criteria>
	</criteria>
	<!-- d9f07e551f70d0ed3756c02a021f2fec -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062323" comment="apache2-mod_php5 less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062324" comment="php5-bcmath less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062325" comment="php5-bz2 less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062326" comment="php5-calendar less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062327" comment="php5-ctype less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062328" comment="php5-curl less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062329" comment="php5-dba less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062330" comment="php5-dbase less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062331" comment="php5-dom less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062332" comment="php5-exif less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062333" comment="php5-fastcgi less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062334" comment="php5-ftp less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062335" comment="php5-gd less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062336" comment="php5-gettext less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062337" comment="php5-gmp less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062338" comment="php5-hash less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062339" comment="php5-iconv less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062340" comment="php5-json less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062341" comment="php5-ldap less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062342" comment="php5-mbstring less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062343" comment="php5-mcrypt less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062344" comment="php5-mysql less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062345" comment="php5-odbc less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062346" comment="php5-openssl less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062347" comment="php5-pcntl less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062348" comment="php5-pdo less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062349" comment="php5-pear less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062350" comment="php5-pgsql less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062351" comment="php5-pspell less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062352" comment="php5-shmop less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062353" comment="php5-snmp less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062354" comment="php5-soap less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062355" comment="php5-suhosin less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062356" comment="php5-sysvmsg less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062357" comment="php5-sysvsem less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062358" comment="php5-sysvshm less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062359" comment="php5-tokenizer less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062360" comment="php5-wddx less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062361" comment="php5-xmlreader less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062362" comment="php5-xmlrpc less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062363" comment="php5-xmlwriter less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062364" comment="php5-xsl less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062365" comment="php5-zip less than 5.2.14-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062366" comment="php5-zlib less than 5.2.14-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102237" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2237</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2237" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2237" source="CVE"/>
	<description>
	Red Hat libvirt, possibly 0.6.1 through 0.8.2, looks up disk backing stores without referring to the user-defined main disk format, which might allow guest OS users to read arbitrary files on the host OS, and possibly have unspecified other impact, via unknown vectors.
	</description>
 </metadata>
<!-- a8fd679955cb064e6e90b799c4557591 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009062636" comment="libvirt-doc less than 0.7.6-1.12.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062637" comment="libvirt-python less than 0.7.6-1.12.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062638" comment="libvirt less than 0.7.6-1.12.2"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102238" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2238</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2238" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2238" source="CVE"/>
	<description>
	Red Hat libvirt, possibly 0.7.2 through 0.8.2, recurses into disk-image backing stores without extracting the defined disk backing-store format, which might allow guest OS users to read arbitrary files on the host OS, and possibly have unspecified other impact, via unknown vectors.
	</description>
 </metadata>
<!-- a8fd679955cb064e6e90b799c4557591 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009062636" comment="libvirt-doc less than 0.7.6-1.12.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062637" comment="libvirt-python less than 0.7.6-1.12.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062638" comment="libvirt less than 0.7.6-1.12.2"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102239" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2239</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2239" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2239" source="CVE"/>
	<description>
	Red Hat libvirt, possibly 0.6.0 through 0.8.2, creates new images without setting the user-defined backing-store format, which allows guest OS users to read arbitrary files on the host OS via unspecified vectors.
	</description>
 </metadata>
<!-- a8fd679955cb064e6e90b799c4557591 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009062636" comment="libvirt-doc less than 0.7.6-1.12.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062637" comment="libvirt-python less than 0.7.6-1.12.2"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009062638" comment="libvirt less than 0.7.6-1.12.2"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102240" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2240</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2240" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2240" source="CVE"/>
	<description>
	The do_anonymous_page function in mm/memory.c in the Linux kernel before 2.6.27.52, 2.6.32.x before 2.6.32.19, 2.6.34.x before 2.6.34.4, and 2.6.35.x before 2.6.35.2 does not properly separate the stack and the heap, which allows context-dependent attackers to execute arbitrary code by writing to the bottom page of a shared memory segment, as demonstrated by a memory-exhaustion attack against the X.Org X server.
	</description>
 </metadata>
<!-- 0174468eca4a0d10570a92e001f081dd -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009063235" comment="xorg-x11-Xvnc less than 7.4-27.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009063236" comment="xorg-x11-server-extra less than 7.4-27.24.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009063237" comment="xorg-x11-server less than 7.4-27.24.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102242" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2242</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2242" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2242" source="CVE"/>
	<description>
	Red Hat libvirt 0.2.0 through 0.8.2 creates iptables rules with improper mappings of privileged source ports, which allows guest OS users to bypass intended access restrictions by leveraging IP address and source-port values, as demonstrated by copying and deleting an NFS directory tree.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 4e3e6cd81221a6afd2bfbca8567ebb2c -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062639" comment="libvirt-doc less than 0.4.6-14.63.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062640" comment="libvirt-python less than 0.4.6-14.63.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062641" comment="libvirt less than 0.4.6-14.63.1"/>
		</criteria>
	</criteria>
	<!-- a8fd679955cb064e6e90b799c4557591 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062636" comment="libvirt-doc less than 0.7.6-1.12.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062637" comment="libvirt-python less than 0.7.6-1.12.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062638" comment="libvirt less than 0.7.6-1.12.2"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102249" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2249</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2249" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2249" source="CVE"/>
	<description>
	Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunks.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 05599e35a510ca089ac92c0708d24d96 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062258" comment="libpng12-0-32bit less than 1.2.31-5.18.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062259" comment="libpng12-0-x86 less than 1.2.31-5.18.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062260" comment="libpng12-0 less than 1.2.31-5.18.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062258" comment="libpng12-0-32bit less than 1.2.31-5.18.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062260" comment="libpng12-0 less than 1.2.31-5.18.1"/>
			</criteria>
		</criteria></criteria>
	<!-- 1827d5255702922bfdc18e59d59e6a20 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062258" comment="libpng12-0-32bit less than 1.2.31-5.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062259" comment="libpng12-0-x86 less than 1.2.31-5.18.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062260" comment="libpng12-0 less than 1.2.31-5.18.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102283" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2283</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2283" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2283" source="CVE"/>
	<description>
	The SMB dissector in Wireshark 0.99.6 through 1.0.13, and 1.2.0 through 1.2.8 allows remote attackers to cause a denial of service (NULL pointer dereference) via unknown vectors.
	</description>
 </metadata>
<!-- 6e5fc6e202651e8b93c830786b3ea82f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066948" comment="wireshark less than 1.4.4-0.2.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102284" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2284</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2284" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2284" source="CVE"/>
	<description>
	Buffer overflow in the ASN.1 BER dissector in Wireshark 0.10.13 through 1.0.13 and 1.2.0 through 1.2.8 has unknown impact and remote attack vectors.
	</description>
 </metadata>
<!-- 6e5fc6e202651e8b93c830786b3ea82f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066948" comment="wireshark less than 1.4.4-0.2.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102285" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2285</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2285" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2285" source="CVE"/>
	<description>
	The SMB PIPE dissector in Wireshark 0.8.20 through 1.0.13 and 1.2.0 through 1.2.8 allows remote attackers to cause a denial of service (NULL pointer dereference) via unknown vectors.
	</description>
 </metadata>
<!-- 6e5fc6e202651e8b93c830786b3ea82f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066948" comment="wireshark less than 1.4.4-0.2.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102286" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2286</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2286" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2286" source="CVE"/>
	<description>
	The SigComp Universal Decompressor Virtual Machine dissector in Wireshark 0.10.7 through 1.0.13 and 1.2.0 through 1.2.8 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.
	</description>
 </metadata>
<!-- 6e5fc6e202651e8b93c830786b3ea82f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066948" comment="wireshark less than 1.4.4-0.2.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102287" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2287</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2287" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2287" source="CVE"/>
	<description>
	Buffer overflow in the SigComp Universal Decompressor Virtual Machine dissector in Wireshark 0.10.8 through 1.0.13 and 1.2.0 through 1.2.8 has unknown impact and remote attack vectors.
	</description>
 </metadata>
<!-- 6e5fc6e202651e8b93c830786b3ea82f -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009066948" comment="wireshark less than 1.4.4-0.2.1"/>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102431" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2431</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for Teradata</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2431" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2431" source="CVE"/>
	<description>
	The cupsFileOpen function in CUPS before 1.4.4 allows local users, with lp group membership, to overwrite arbitrary files via a symlink attack on the (1) /var/cache/cups/remote.cache or (2) /var/cache/cups/job.cache file.
	</description>
 </metadata>
<!-- e50c58ccd03dea996e547017df4bffff -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009070956" comment="cups-client less than 1.3.9-8.44.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070957" comment="cups-libs-32bit less than 1.3.9-8.44.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070958" comment="cups-libs-x86 less than 1.3.9-8.44.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070959" comment="cups-libs less than 1.3.9-8.44.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070960" comment="cups less than 1.3.9-8.44.1"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009070956" comment="cups-client less than 1.3.9-8.44.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070957" comment="cups-libs-32bit less than 1.3.9-8.44.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070959" comment="cups-libs less than 1.3.9-8.44.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070960" comment="cups less than 1.3.9-8.44.1"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102432" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2432</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for Teradata</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2432" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2432" source="CVE"/>
	<description>
	The cupsDoAuthentication function in auth.c in the client in CUPS before 1.4.4, when HAVE_GSSAPI is omitted, does not properly handle a demand for authorization, which allows remote CUPS servers to cause a denial of service (infinite loop) via HTTP_UNAUTHORIZED responses.
	</description>
 </metadata>
<!-- e50c58ccd03dea996e547017df4bffff -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009070956" comment="cups-client less than 1.3.9-8.44.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070957" comment="cups-libs-32bit less than 1.3.9-8.44.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070958" comment="cups-libs-x86 less than 1.3.9-8.44.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070959" comment="cups-libs less than 1.3.9-8.44.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070960" comment="cups less than 1.3.9-8.44.1"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009070956" comment="cups-client less than 1.3.9-8.44.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070957" comment="cups-libs-32bit less than 1.3.9-8.44.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070959" comment="cups-libs less than 1.3.9-8.44.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070960" comment="cups less than 1.3.9-8.44.1"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102478" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2478</title>
	<affected family="unix">
		<platform>SLE 11 SERVER Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2478" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2478" source="CVE"/>
	<description>
	Integer overflow in the ethtool_get_rxnfc function in net/core/ethtool.c in the Linux kernel before 2.6.33.7 on 32-bit platforms allows local users to cause a denial of service or possibly have unspecified other impact via an ETHTOOL_GRXCLSRLALL ethtool command with a large info.rule_cnt value that triggers a buffer overflow, a different vulnerability than CVE-2010-3084.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 70608756570f270952a30400f0f97a67 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062391" comment="ext4dev-kmp-xen less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
			</criteria>
		</criteria></criteria>
	<!-- 9343885edda5fa87713dfe0432ee1dde -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062404" comment="ext4dev-kmp-ppc64 less than 0_2.6.32.19_0.2-7.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062405" comment="kernel-ppc64-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062406" comment="kernel-ppc64-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062407" comment="kernel-ppc64 less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
	<!-- a28f8d8e1ce77f22744f2d703cc04134 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
	<!-- e2f6c6cc02f7dc05554cab87c9f88650 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062408" comment="btrfs-kmp-pae less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062409" comment="ext4dev-kmp-pae less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062391" comment="ext4dev-kmp-xen less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062410" comment="hyper-v-kmp-pae less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062411" comment="kernel-pae-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062412" comment="kernel-pae-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062413" comment="kernel-pae less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062408" comment="btrfs-kmp-pae less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062409" comment="ext4dev-kmp-pae less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062410" comment="hyper-v-kmp-pae less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062411" comment="kernel-pae-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062412" comment="kernel-pae-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062413" comment="kernel-pae less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
			</criteria>
		</criteria></criteria>
	<!-- ff70db7653be66560fa26573ef04bc05 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062414" comment="kernel-default-man less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102495" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2495</title>
	<affected family="unix">
		<platform>SLE 11 SERVER Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2495" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2495" source="CVE"/>
	<description>
	The pppol2tp_xmit function in drivers/net/pppol2tp.c in the L2TP implementation in the Linux kernel before 2.6.34 does not properly validate certain values associated with an interface, which allows attackers to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via vectors related to a routing change.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 01f44594f9d8615a4c725ad4472abb2b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061868" comment="btrfs-kmp-default less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061869" comment="btrfs-kmp-xen less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061870" comment="ext4dev-kmp-default less than 0_2.6.32.13_0.5-7.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061871" comment="ext4dev-kmp-xen less than 0_2.6.32.13_0.5-7.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061872" comment="hyper-v-kmp-default less than 0_2.6.32.13_0.5-0.7.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061873" comment="kernel-default-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061874" comment="kernel-default-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061875" comment="kernel-default less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061876" comment="kernel-source less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061877" comment="kernel-syms less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061878" comment="kernel-trace-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061879" comment="kernel-trace-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061880" comment="kernel-trace less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061881" comment="kernel-xen-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061882" comment="kernel-xen-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061883" comment="kernel-xen less than 2.6.32.13-0.5.1"/>
		</criteria>
	</criteria>
	<!-- 06ee9fa41e8722a56ab4c7b8f6a7be72 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061868" comment="btrfs-kmp-default less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061870" comment="ext4dev-kmp-default less than 0_2.6.32.13_0.5-7.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061873" comment="kernel-default-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061874" comment="kernel-default-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061884" comment="kernel-default-man less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061875" comment="kernel-default less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061876" comment="kernel-source less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061877" comment="kernel-syms less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061878" comment="kernel-trace-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061879" comment="kernel-trace-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061880" comment="kernel-trace less than 2.6.32.13-0.5.1"/>
		</criteria>
	</criteria>
	<!-- 18bb8606d302505049983784dc2eae07 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061868" comment="btrfs-kmp-default less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061870" comment="ext4dev-kmp-default less than 0_2.6.32.13_0.5-7.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061873" comment="kernel-default-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061874" comment="kernel-default-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061875" comment="kernel-default less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061876" comment="kernel-source less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061877" comment="kernel-syms less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061878" comment="kernel-trace-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061879" comment="kernel-trace-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061880" comment="kernel-trace less than 2.6.32.13-0.5.1"/>
		</criteria>
	</criteria>
	<!-- 2c10f83a368b9104456f6181c617a477 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061868" comment="btrfs-kmp-default less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061870" comment="ext4dev-kmp-default less than 0_2.6.32.13_0.5-7.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061885" comment="ext4dev-kmp-ppc64 less than 0_2.6.32.13_0.5-7.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061873" comment="kernel-default-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061874" comment="kernel-default-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061875" comment="kernel-default less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061886" comment="kernel-ppc64-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061887" comment="kernel-ppc64-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061888" comment="kernel-ppc64 less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061876" comment="kernel-source less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061877" comment="kernel-syms less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061878" comment="kernel-trace-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061879" comment="kernel-trace-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061880" comment="kernel-trace less than 2.6.32.13-0.5.1"/>
		</criteria>
	</criteria>
	<!-- caf966715fc66f993dd8892aa75742ad -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061868" comment="btrfs-kmp-default less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061889" comment="btrfs-kmp-pae less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061869" comment="btrfs-kmp-xen less than 0_2.6.32.13_0.5-0.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061870" comment="ext4dev-kmp-default less than 0_2.6.32.13_0.5-7.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061890" comment="ext4dev-kmp-pae less than 0_2.6.32.13_0.5-7.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061871" comment="ext4dev-kmp-xen less than 0_2.6.32.13_0.5-7.3.9"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061872" comment="hyper-v-kmp-default less than 0_2.6.32.13_0.5-0.7.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061891" comment="hyper-v-kmp-pae less than 0_2.6.32.13_0.5-0.7.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061873" comment="kernel-default-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061874" comment="kernel-default-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061875" comment="kernel-default less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061892" comment="kernel-pae-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061893" comment="kernel-pae-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061894" comment="kernel-pae less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061876" comment="kernel-source less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061877" comment="kernel-syms less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061878" comment="kernel-trace-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061879" comment="kernel-trace-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061880" comment="kernel-trace less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061881" comment="kernel-xen-base less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061882" comment="kernel-xen-devel less than 2.6.32.13-0.5.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061883" comment="kernel-xen less than 2.6.32.13-0.5.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102497" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2497</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2497" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2497" source="CVE"/>
	<description>
	Integer underflow in glyph handling in FreeType before 2.4.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 7bcc9a1fade88c7620df728424de42c5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062064" comment="freetype2-x86 less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
	<!-- f28613bd3eb0b0f8e83bbf97c432760b -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062064" comment="freetype2-x86 less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102498" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2498</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2498" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2498" source="CVE"/>
	<description>
	The psh_glyph_find_strong_points function in pshinter/pshalgo.c in FreeType before 2.4.0 does not properly implement hinting masks, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a crafted font file that triggers an invalid free operation.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 7bcc9a1fade88c7620df728424de42c5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062064" comment="freetype2-x86 less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
	<!-- f28613bd3eb0b0f8e83bbf97c432760b -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062064" comment="freetype2-x86 less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102499" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2499</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2499" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2499" source="CVE"/>
	<description>
	Buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted LaserWriter PS font file with an embedded PFB fragment.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 7bcc9a1fade88c7620df728424de42c5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062064" comment="freetype2-x86 less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
	<!-- f28613bd3eb0b0f8e83bbf97c432760b -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062064" comment="freetype2-x86 less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102500" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2500</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2500" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2500" source="CVE"/>
	<description>
	Integer overflow in the gray_render_span function in smooth/ftgrays.c in FreeType before 2.4.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 7bcc9a1fade88c7620df728424de42c5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062064" comment="freetype2-x86 less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
	<!-- f28613bd3eb0b0f8e83bbf97c432760b -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062064" comment="freetype2-x86 less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102519" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2519</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2519" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2519" source="CVE"/>
	<description>
	Heap-based buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted length value in a POST fragment header in a font file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 7bcc9a1fade88c7620df728424de42c5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062064" comment="freetype2-x86 less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
	<!-- f28613bd3eb0b0f8e83bbf97c432760b -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062064" comment="freetype2-x86 less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102520" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2520</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2520" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2520" source="CVE"/>
	<description>
	Heap-based buffer overflow in the Ins_IUP function in truetype/ttinterp.c in FreeType before 2.4.0, when TrueType bytecode support is enabled, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 7bcc9a1fade88c7620df728424de42c5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062064" comment="freetype2-x86 less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
	<!-- f28613bd3eb0b0f8e83bbf97c432760b -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062064" comment="freetype2-x86 less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102521" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2521</title>
	<affected family="unix">
		<platform>SLE 11 SERVER Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2521" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2521" source="CVE"/>
	<description>
	Multiple buffer overflows in fs/nfsd/nfs4xdr.c in the XDR implementation in the NFS server in the Linux kernel before 2.6.34-rc6 allow remote attackers to cause a denial of service (panic) or possibly execute arbitrary code via a crafted NFSv4 compound WRITE request, related to the read_buf and nfsd4_decode_compound functions.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 1a1e84bdf877ca5c38ecac3616374922 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061675" comment="kernel-default-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061680" comment="kernel-pae-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061693" comment="kernel-xen-extra less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 2959a2080579b86be5f71889c23098f9 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061702" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061678" comment="kernel-kdump less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061682" comment="kernel-ppc64-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061684" comment="kernel-ppc64 less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 34efb3de15e5405c1817c287028a50e3 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061675" comment="kernel-default-extra less than 2.6.27.48-0.1.1"/>
	</criteria>
	<!-- 3c314aa8e3d1c4878e06108d767c18da -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061675" comment="kernel-default-extra less than 2.6.27.48-0.1.1"/>
	</criteria>
	<!-- 66504af0afe753b5175112b44bc8827d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061703" comment="ext4dev-kmp-pae less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061704" comment="ext4dev-kmp-vmi less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061705" comment="ext4dev-kmp-xen less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061679" comment="kernel-pae-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061681" comment="kernel-pae less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061706" comment="kernel-vmi-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061707" comment="kernel-vmi less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 6a5b519e1125164aefd647adb31ccec8 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061675" comment="kernel-default-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061683" comment="kernel-ppc64-extra less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 70608756570f270952a30400f0f97a67 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062391" comment="ext4dev-kmp-xen less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
			</criteria>
		</criteria></criteria>
	<!-- 7c255bf89525f242ab9deddcf14e6517 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061675" comment="kernel-default-extra less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061693" comment="kernel-xen-extra less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 9343885edda5fa87713dfe0432ee1dde -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062404" comment="ext4dev-kmp-ppc64 less than 0_2.6.32.19_0.2-7.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062405" comment="kernel-ppc64-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062406" comment="kernel-ppc64-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062407" comment="kernel-ppc64 less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
	<!-- 99ed0d9e003dfe8866db7105d4850a09 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- a28f8d8e1ce77f22744f2d703cc04134 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
	<!-- c8a29eec659b0b2b3e85c610b67beacd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061705" comment="ext4dev-kmp-xen less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061692" comment="kernel-xen-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061694" comment="kernel-xen less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- e2f6c6cc02f7dc05554cab87c9f88650 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062408" comment="btrfs-kmp-pae less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062409" comment="ext4dev-kmp-pae less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062391" comment="ext4dev-kmp-xen less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062410" comment="hyper-v-kmp-pae less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062411" comment="kernel-pae-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062412" comment="kernel-pae-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062413" comment="kernel-pae less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062408" comment="btrfs-kmp-pae less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062409" comment="ext4dev-kmp-pae less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062410" comment="hyper-v-kmp-pae less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062411" comment="kernel-pae-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062412" comment="kernel-pae-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062413" comment="kernel-pae less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
			</criteria>
		</criteria></criteria>
	<!-- f73f22d4b713e9a7674cc8c4eebf91dd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061701" comment="ext4dev-kmp-default less than 0_2.6.27.48_0.1-7.1.33"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061674" comment="kernel-default-base less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061708" comment="kernel-default-man less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061676" comment="kernel-default less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061686" comment="kernel-source less than 2.6.27.48-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061687" comment="kernel-syms less than 2.6.27.48-0.1.1"/>
		</criteria>
	</criteria>
	<!-- ff70db7653be66560fa26573ef04bc05 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062414" comment="kernel-default-man less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102522" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2522</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2522" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2522" source="CVE"/>
	<description>
	The mipv6 daemon in UMIP 0.4 does not verify that netlink messages originated in the kernel, which allows local users to spoof netlink socket communication via a crafted unicast message.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 448eb6fbdb13a064282bf6f2a91d1a9f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063774" comment="mipv6d less than 2.0.2-2.15.1"/>
	</criteria>
	<!-- d682c26a46cd978068d8c8bc5311a1cd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063774" comment="mipv6d less than 2.0.2-2.15.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102523" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2523</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2523" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2523" source="CVE"/>
	<description>
	Multiple buffer overflows in ha.c in the mipv6 daemon in UMIP 0.4 allow remote attackers to have an unspecified impact via a crafted (1) ND_OPT_PREFIX_INFORMATION or (2) ND_OPT_HOME_AGENT_INFO packet.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 448eb6fbdb13a064282bf6f2a91d1a9f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063774" comment="mipv6d less than 2.0.2-2.15.1"/>
	</criteria>
	<!-- d682c26a46cd978068d8c8bc5311a1cd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063774" comment="mipv6d less than 2.0.2-2.15.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102524" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2524</title>
	<affected family="unix">
		<platform>SLE 11 SERVER Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2524" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2524" source="CVE"/>
	<description>
	The DNS resolution functionality in the CIFS implementation in the Linux kernel before 2.6.35, when CONFIG_CIFS_DFS_UPCALL is enabled, relies on a user's keyring for the dns_resolver upcall in the cifs.upcall userspace helper, which allows local users to spoof the results of DNS queries and perform arbitrary CIFS mounts via vectors involving an add_key call, related to a "cache stuffing" issue and MS-DFS referrals.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 70608756570f270952a30400f0f97a67 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062391" comment="ext4dev-kmp-xen less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
			</criteria>
		</criteria></criteria>
	<!-- 9343885edda5fa87713dfe0432ee1dde -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062404" comment="ext4dev-kmp-ppc64 less than 0_2.6.32.19_0.2-7.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062405" comment="kernel-ppc64-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062406" comment="kernel-ppc64-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062407" comment="kernel-ppc64 less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
	<!-- a28f8d8e1ce77f22744f2d703cc04134 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
	<!-- e2f6c6cc02f7dc05554cab87c9f88650 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062408" comment="btrfs-kmp-pae less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062409" comment="ext4dev-kmp-pae less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062391" comment="ext4dev-kmp-xen less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062410" comment="hyper-v-kmp-pae less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062411" comment="kernel-pae-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062412" comment="kernel-pae-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062413" comment="kernel-pae less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062408" comment="btrfs-kmp-pae less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062409" comment="ext4dev-kmp-pae less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062410" comment="hyper-v-kmp-pae less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062411" comment="kernel-pae-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062412" comment="kernel-pae-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062413" comment="kernel-pae less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
			</criteria>
		</criteria></criteria>
	<!-- ff70db7653be66560fa26573ef04bc05 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062414" comment="kernel-default-man less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102526" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2526</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2526" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2526" source="CVE"/>
	<description>
	The cluster logical volume manager daemon (clvmd) in lvm2-cluster in LVM2 before 2.02.72, as used in Red Hat Global File System (GFS) and other products, does not verify client credentials upon a socket connection, which allows local users to cause a denial of service (daemon exit or logical-volume change) or possibly have unspecified other impact via crafted control commands.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5d5a4e6a66842e208571ff8227921547 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062642" comment="lvm2 less than 2.02.39-18.26.3"/>
	</criteria>
	<!-- 8a73ebc90cadef3ab692d6db3b81626d -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062643" comment="lvm2 less than 2.02.39-18.31.2"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102527" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2527</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2527" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2527" source="CVE"/>
	<description>
	Multiple buffer overflows in demo programs in FreeType before 2.4.0 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 7bcc9a1fade88c7620df728424de42c5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062064" comment="freetype2-x86 less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
	<!-- f28613bd3eb0b0f8e83bbf97c432760b -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062064" comment="freetype2-x86 less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102537" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2537</title>
	<affected family="unix">
		<platform>SLE 11 SERVER Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2537" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2537" source="CVE"/>
	<description>
	The btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a (1) BTRFS_IOC_CLONE or (2) BTRFS_IOC_CLONE_RANGE ioctl call that specifies this file as a donor.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 70608756570f270952a30400f0f97a67 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062391" comment="ext4dev-kmp-xen less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
			</criteria>
		</criteria></criteria>
	<!-- 9343885edda5fa87713dfe0432ee1dde -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062404" comment="ext4dev-kmp-ppc64 less than 0_2.6.32.19_0.2-7.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062405" comment="kernel-ppc64-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062406" comment="kernel-ppc64-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062407" comment="kernel-ppc64 less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
	<!-- a28f8d8e1ce77f22744f2d703cc04134 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
	<!-- e2f6c6cc02f7dc05554cab87c9f88650 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062408" comment="btrfs-kmp-pae less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062409" comment="ext4dev-kmp-pae less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062391" comment="ext4dev-kmp-xen less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062410" comment="hyper-v-kmp-pae less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062411" comment="kernel-pae-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062412" comment="kernel-pae-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062413" comment="kernel-pae less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062408" comment="btrfs-kmp-pae less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062409" comment="ext4dev-kmp-pae less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062410" comment="hyper-v-kmp-pae less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062411" comment="kernel-pae-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062412" comment="kernel-pae-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062413" comment="kernel-pae less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
			</criteria>
		</criteria></criteria>
	<!-- ff70db7653be66560fa26573ef04bc05 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062414" comment="kernel-default-man less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102538" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2538</title>
	<affected family="unix">
		<platform>SLE 11 SERVER Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2538" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2538" source="CVE"/>
	<description>
	Integer overflow in the btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2.6.35 might allow local users to obtain sensitive information via a BTRFS_IOC_CLONE_RANGE ioctl call.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 70608756570f270952a30400f0f97a67 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062391" comment="ext4dev-kmp-xen less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
			</criteria>
		</criteria></criteria>
	<!-- 9343885edda5fa87713dfe0432ee1dde -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062404" comment="ext4dev-kmp-ppc64 less than 0_2.6.32.19_0.2-7.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062405" comment="kernel-ppc64-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062406" comment="kernel-ppc64-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062407" comment="kernel-ppc64 less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
	<!-- a28f8d8e1ce77f22744f2d703cc04134 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
	<!-- e2f6c6cc02f7dc05554cab87c9f88650 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062408" comment="btrfs-kmp-pae less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062409" comment="ext4dev-kmp-pae less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062391" comment="ext4dev-kmp-xen less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062410" comment="hyper-v-kmp-pae less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062411" comment="kernel-pae-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062412" comment="kernel-pae-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062413" comment="kernel-pae less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062408" comment="btrfs-kmp-pae less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062409" comment="ext4dev-kmp-pae less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062410" comment="hyper-v-kmp-pae less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062411" comment="kernel-pae-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062412" comment="kernel-pae-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062413" comment="kernel-pae less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
			</criteria>
		</criteria></criteria>
	<!-- ff70db7653be66560fa26573ef04bc05 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062414" comment="kernel-default-man less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102541" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2541</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2541" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2541" source="CVE"/>
	<description>
	Buffer overflow in ftmulti.c in the ftmulti demo program in FreeType before 2.4.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 7bcc9a1fade88c7620df728424de42c5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062064" comment="freetype2-x86 less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
	<!-- f28613bd3eb0b0f8e83bbf97c432760b -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062064" comment="freetype2-x86 less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102547" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2547</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2547" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2547" source="CVE"/>
	<description>
	Use-after-free vulnerability in kbx/keybox-blob.c in GPGSM in GnuPG 2.x through 2.0.16 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a certificate with a large number of Subject Alternate Names, which is not properly handled in a realloc operation when importing the certificate or verifying its signature.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- ab5fff9f4b3475bf58d306cbb6b25aef -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061951" comment="gpg2-lang less than 2.0.9-25.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061952" comment="gpg2 less than 2.0.9-25.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061953" comment="libgcrypt11-32bit less than 1.4.1-6.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061954" comment="libgcrypt11-x86 less than 1.4.1-6.7"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061955" comment="libgcrypt11 less than 1.4.1-6.7"/>
		</criteria>
	</criteria>
	<!-- d0a463a21a2a3eaac40630a601b657a3 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061951" comment="gpg2-lang less than 2.0.9-25.26.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061952" comment="gpg2 less than 2.0.9-25.26.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102575" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2575</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2575" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2575" source="CVE"/>
	<description>
	Heap-based buffer overflow in the RLE decompression functionality in the TranscribePalmImageToJPEG function in generators/plucker/inplug/image.cpp in Okular in KDE SC 4.3.0 through 4.5.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted image in a PDB file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 5f5356890325fbbde04920c42296ed96 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063238" comment="kde4-gwenview less than 4.1.3-7.17.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063239" comment="kde4-kcolorchooser less than 4.1.3-7.17.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063240" comment="kde4-kruler less than 4.1.3-7.17.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063241" comment="kde4-ksnapshot less than 4.1.3-7.17.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063242" comment="kde4-okular less than 4.1.3-7.17.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063243" comment="libkipi5 less than 4.1.3-7.17.1"/>
		</criteria>
	</criteria>
	<!-- ab2f556bf2a34c6440fc935aabb8b6df -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063244" comment="gwenview less than 4.3.5-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063245" comment="kcolorchooser less than 4.3.5-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063246" comment="kruler less than 4.3.5-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063247" comment="ksnapshot less than 4.3.5-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063248" comment="libkexiv2-7 less than 4.3.5-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063249" comment="libkipi6 less than 4.3.5-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063250" comment="okular less than 4.3.5-0.2.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102621" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2621</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for Teradata</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2621" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2621" source="CVE"/>
	<description>
	The QSslSocketBackendPrivate::transmit function in src_network_ssl_qsslsocket_openssl.cpp in Qt 4.6.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a malformed request.
	</description>
 </metadata>
<!-- 34afda31849d3183ccf4b0c1ae44eb26 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009070875" comment="libQtWebKit4-32bit less than 4.6.3-5.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070876" comment="libQtWebKit4-x86 less than 4.6.3-5.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070877" comment="libQtWebKit4 less than 4.6.3-5.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070878" comment="libqt4-32bit less than 4.6.3-5.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070879" comment="libqt4-qt3support-32bit less than 4.6.3-5.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070880" comment="libqt4-qt3support-x86 less than 4.6.3-5.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070881" comment="libqt4-qt3support less than 4.6.3-5.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070882" comment="libqt4-sql-32bit less than 4.6.3-5.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070883" comment="libqt4-sql-mysql less than 4.6.3-5.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070884" comment="libqt4-sql-sqlite less than 4.6.3-5.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070885" comment="libqt4-sql-x86 less than 4.6.3-5.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070886" comment="libqt4-sql less than 4.6.3-5.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070887" comment="libqt4-x11-32bit less than 4.6.3-5.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070888" comment="libqt4-x11-x86 less than 4.6.3-5.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070889" comment="libqt4-x11 less than 4.6.3-5.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070890" comment="libqt4-x86 less than 4.6.3-5.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070891" comment="libqt4 less than 4.6.3-5.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070892" comment="qt4-x11-tools less than 4.6.3-5.10.1"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009070875" comment="libQtWebKit4-32bit less than 4.6.3-5.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070877" comment="libQtWebKit4 less than 4.6.3-5.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070878" comment="libqt4-32bit less than 4.6.3-5.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070879" comment="libqt4-qt3support-32bit less than 4.6.3-5.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070881" comment="libqt4-qt3support less than 4.6.3-5.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070882" comment="libqt4-sql-32bit less than 4.6.3-5.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070883" comment="libqt4-sql-mysql less than 4.6.3-5.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070884" comment="libqt4-sql-sqlite less than 4.6.3-5.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070886" comment="libqt4-sql less than 4.6.3-5.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070887" comment="libqt4-x11-32bit less than 4.6.3-5.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070889" comment="libqt4-x11 less than 4.6.3-5.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070891" comment="libqt4 less than 4.6.3-5.10.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009070892" comment="qt4-x11-tools less than 4.6.3-5.10.1"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102628" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2628</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2628" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2628" source="CVE"/>
	<description>
	The IKE daemon in strongSwan 4.3.x before 4.3.7 and 4.4.x before 4.4.1 does not properly check the return values of snprintf calls, which allows remote attackers to execute arbitrary code via crafted (1) certificate or (2) identity data that triggers buffer overflows.
	</description>
 </metadata>
<!-- 0fcdb75b2f24c2cf4d05018279a4e2b9 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009061963" comment="strongswan-doc less than 4.3.4-3.4.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061964" comment="strongswan less than 4.3.4-3.4.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102640" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2640</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2640" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2640" source="CVE"/>
	<description>
	Array index error in the PK font parser in the dvi-backend component in Evince 2.32 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer.
	</description>
 </metadata>
<!-- 625b56e690b7e91964f2b45637eb0b04 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009065541" comment="evince-doc less than 2.28.2-0.3.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009065542" comment="evince-lang less than 2.28.2-0.3.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009065543" comment="evince less than 2.28.2-0.3.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102641" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2641</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2641" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2641" source="CVE"/>
	<description>
	Array index error in the VF font parser in the dvi-backend component in Evince 2.32 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer.
	</description>
 </metadata>
<!-- 625b56e690b7e91964f2b45637eb0b04 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009065541" comment="evince-doc less than 2.28.2-0.3.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009065542" comment="evince-lang less than 2.28.2-0.3.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009065543" comment="evince less than 2.28.2-0.3.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102642" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2642</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2642" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2642" source="CVE"/>
	<description>
	Heap-based buffer overflow in the AFM font parser in the dvi-backend component in Evince 2.32 and earlier, teTeX 3.0, t1lib 5.1.2, and possibly other products allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 625b56e690b7e91964f2b45637eb0b04 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009065541" comment="evince-doc less than 2.28.2-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065542" comment="evince-lang less than 2.28.2-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065543" comment="evince less than 2.28.2-0.3.1"/>
		</criteria>
	</criteria>
	<!-- 9d8611fed55623b964f5455e5c86abd4 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065858" comment="t1lib less than 5.1.1-100.19.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102643" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2643</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2643" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2643" source="CVE"/>
	<description>
	Integer overflow in the TFM font parser in the dvi-backend component in Evince 2.32 and earlier allows remote attackers to execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer.
	</description>
 </metadata>
<!-- 625b56e690b7e91964f2b45637eb0b04 -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009065541" comment="evince-doc less than 2.28.2-0.3.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009065542" comment="evince-lang less than 2.28.2-0.3.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009065543" comment="evince less than 2.28.2-0.3.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102713" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2713</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2713" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2713" source="CVE"/>
	<description>
	The vte_sequence_handler_window_manipulation function in vteseq.c in libvte (aka libvte9) in VTE 0.25.1 and earlier, as used in gnome-terminal, does not properly handle escape sequences, which allows remote attackers to execute arbitrary commands or obtain potentially sensitive information via a (1) window title or (2) icon title sequence.  NOTE: this issue exists because of a CVE-2003-0070 regression.
	</description>
 </metadata>
<!-- 6a3beb3117af5d396e2b650b8babbc2e -->
<criteria operator="AND">
	<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
	<criteria operator="OR">
		<criterion test_ref="oval:org.opensuse.security:tst:2009061709" comment="vte-doc less than 0.22.5-0.2.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061710" comment="vte-lang less than 0.22.5-0.2.1"/>
		<criterion test_ref="oval:org.opensuse.security:tst:2009061711" comment="vte less than 0.22.5-0.2.1"/>
	</criteria>
</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102751" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2751</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2751" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2751" source="CVE"/>
	<description>
	The nsDocShell::OnRedirectStateChange function in docshell/base/nsDocShell.cpp in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to spoof the SSL security status of a document via vectors involving multiple requests, a redirect, and the history.back and history.forward JavaScript functions.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0d0d8706df2d64128121ceea3338a129 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061813" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
	<!-- f23d3ef3410fecb23cf62a058d285514 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061813" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102752" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2752</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2752" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2752" source="CVE"/>
	<description>
	Integer overflow in an array class in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code by placing many Cascading Style Sheets (CSS) values in an array, related to references to external font resources and an inconsistency between 16-bit and 32-bit integers.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0d0d8706df2d64128121ceea3338a129 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061813" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
	<!-- f23d3ef3410fecb23cf62a058d285514 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061813" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102753" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2753</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2753" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2753" source="CVE"/>
	<description>
	Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code via a large selection attribute in a XUL tree element, which triggers a use-after-free.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 090848ec46b4dd478bc9cd3ba9442531 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063391" comment="mozilla-xulrunner192-x86 less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 0c29d728f4fd029a2fbf4ea1e669fc81 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064213" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
			</criteria>
		</criteria></criteria>
	<!-- 0d0d8706df2d64128121ceea3338a129 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061813" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
	<!-- 50a3e55a414b85ba53fc6385752379a7 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063391" comment="mozilla-xulrunner192-x86 less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
			</criteria>
		</criteria></criteria>
	<!-- 8f1a8feab628d727a6016f2016a02361 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064213" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
	<!-- f23d3ef3410fecb23cf62a058d285514 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061813" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102754" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2754</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
	</affected>
	<reference ref_id="CVE-2010-2754" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2754" source="CVE"/>
	<description>
	dom/base/nsJSEnvironment.cpp in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 does not properly suppress a script's URL in certain circumstances involving a redirect and an error message, which allows remote attackers to obtain sensitive information about script parameters via a crafted HTML document, related to the window.onerror handler.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 0d0d8706df2d64128121ceea3338a129 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061813" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
	<!-- f23d3ef3410fecb23cf62a058d285514 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009061808" comment="MozillaFirefox-translations less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061809" comment="MozillaFirefox less than 3.5.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061810" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061811" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061812" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061813" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009061814" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102760" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2760</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2760" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2760" source="CVE"/>
	<description>
	Use-after-free vulnerability in the nsTreeSelection function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 might allow remote attackers to execute arbitrary code via vectors involving a XUL tree selection, related to a "dangling pointer vulnerability." NOTE: this issue exists because of an incomplete fix for CVE-2010-2753.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 090848ec46b4dd478bc9cd3ba9442531 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063391" comment="mozilla-xulrunner192-x86 less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 0c29d728f4fd029a2fbf4ea1e669fc81 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064213" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
			</criteria>
		</criteria></criteria>
	<!-- 50a3e55a414b85ba53fc6385752379a7 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063391" comment="mozilla-xulrunner192-x86 less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
			</criteria>
		</criteria></criteria>
	<!-- 8f1a8feab628d727a6016f2016a02361 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064213" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102761" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2761</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2761" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2761" source="CVE"/>
	<description>
	The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier uses a hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, which allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input that contains this value, a different vulnerability than CVE-2010-3172.
	</description>
 </metadata>
<!-- 31907ff5cbd65bb3539b83632a7125a2 -->
<criteria operator="OR">
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009065589" comment="perl-32bit less than 5.10.0-64.53.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065590" comment="perl-base less than 5.10.0-64.53.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065591" comment="perl-doc less than 5.10.0-64.53.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065592" comment="perl-x86 less than 5.10.0-64.53.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065593" comment="perl less than 5.10.0-64.53.1"/>
		</criteria>
	</criteria>
		<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009065589" comment="perl-32bit less than 5.10.0-64.53.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065590" comment="perl-base less than 5.10.0-64.53.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065591" comment="perl-doc less than 5.10.0-64.53.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065593" comment="perl less than 5.10.0-64.53.1"/>
		</criteria>
	</criteria></criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102762" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2762</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2762" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2762" source="CVE"/>
	<description>
	The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Firefox 3.6.x before 3.6.9 and Thunderbird 3.1.x before 3.1.3 does not properly restrict objects at the end of scope chains, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via vectors related to a chrome privileged object and a chain ending in an outer object.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 090848ec46b4dd478bc9cd3ba9442531 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063391" comment="mozilla-xulrunner192-x86 less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 0c29d728f4fd029a2fbf4ea1e669fc81 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064213" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
			</criteria>
		</criteria></criteria>
	<!-- 50a3e55a414b85ba53fc6385752379a7 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063391" comment="mozilla-xulrunner192-x86 less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
			</criteria>
		</criteria></criteria>
	<!-- 8f1a8feab628d727a6016f2016a02361 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064213" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102763" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2763</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2763" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2763" source="CVE"/>
	<description>
	The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Firefox before 3.5.12, Thunderbird before 3.0.7, and SeaMonkey before 2.0.7 does not properly restrict scripted functions, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted function.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 090848ec46b4dd478bc9cd3ba9442531 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063391" comment="mozilla-xulrunner192-x86 less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 0c29d728f4fd029a2fbf4ea1e669fc81 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064213" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
			</criteria>
		</criteria></criteria>
	<!-- 50a3e55a414b85ba53fc6385752379a7 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063391" comment="mozilla-xulrunner192-x86 less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
			</criteria>
		</criteria></criteria>
	<!-- 8f1a8feab628d727a6016f2016a02361 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064213" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102764" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2764</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2764" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2764" source="CVE"/>
	<description>
	Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 do not properly restrict read access to the statusText property of XMLHttpRequest objects, which allows remote attackers to discover the existence of intranet web servers via cross-origin requests.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 090848ec46b4dd478bc9cd3ba9442531 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063391" comment="mozilla-xulrunner192-x86 less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 0c29d728f4fd029a2fbf4ea1e669fc81 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064213" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
			</criteria>
		</criteria></criteria>
	<!-- 50a3e55a414b85ba53fc6385752379a7 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063391" comment="mozilla-xulrunner192-x86 less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
			</criteria>
		</criteria></criteria>
	<!-- 8f1a8feab628d727a6016f2016a02361 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064213" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102765" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2765</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2765" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2765" source="CVE"/>
	<description>
	Integer overflow in the FRAMESET element implementation in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 might allow remote attackers to execute arbitrary code via a large number of values in the cols (aka columns) attribute, leading to a heap-based buffer overflow.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 090848ec46b4dd478bc9cd3ba9442531 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063391" comment="mozilla-xulrunner192-x86 less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 0c29d728f4fd029a2fbf4ea1e669fc81 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064213" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
			</criteria>
		</criteria></criteria>
	<!-- 50a3e55a414b85ba53fc6385752379a7 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063391" comment="mozilla-xulrunner192-x86 less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
			</criteria>
		</criteria></criteria>
	<!-- 8f1a8feab628d727a6016f2016a02361 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064213" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102766" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2766</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2766" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2766" source="CVE"/>
	<description>
	The normalizeDocument function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle the removal of DOM nodes during normalization, which might allow remote attackers to execute arbitrary code via vectors involving access to a deleted object.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 090848ec46b4dd478bc9cd3ba9442531 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063391" comment="mozilla-xulrunner192-x86 less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 0c29d728f4fd029a2fbf4ea1e669fc81 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064213" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
			</criteria>
		</criteria></criteria>
	<!-- 50a3e55a414b85ba53fc6385752379a7 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063391" comment="mozilla-xulrunner192-x86 less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
			</criteria>
		</criteria></criteria>
	<!-- 8f1a8feab628d727a6016f2016a02361 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064213" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102767" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2767</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2767" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2767" source="CVE"/>
	<description>
	The navigator.plugins implementation in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle destruction of the DOM plugin array, which might allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via crafted access to the navigator object, related to a "dangling pointer vulnerability."
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 090848ec46b4dd478bc9cd3ba9442531 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063391" comment="mozilla-xulrunner192-x86 less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 0c29d728f4fd029a2fbf4ea1e669fc81 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064213" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
			</criteria>
		</criteria></criteria>
	<!-- 50a3e55a414b85ba53fc6385752379a7 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063391" comment="mozilla-xulrunner192-x86 less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
			</criteria>
		</criteria></criteria>
	<!-- 8f1a8feab628d727a6016f2016a02361 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064213" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102768" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2768</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2768" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2768" source="CVE"/>
	<description>
	Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 do not properly restrict use of the type attribute of an OBJECT element to set a document's charset, which allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms via UTF-7 encoding.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 090848ec46b4dd478bc9cd3ba9442531 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063391" comment="mozilla-xulrunner192-x86 less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 0c29d728f4fd029a2fbf4ea1e669fc81 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064213" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
			</criteria>
		</criteria></criteria>
	<!-- 50a3e55a414b85ba53fc6385752379a7 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063391" comment="mozilla-xulrunner192-x86 less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
			</criteria>
		</criteria></criteria>
	<!-- 8f1a8feab628d727a6016f2016a02361 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064213" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102769" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2769</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2769" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2769" source="CVE"/>
	<description>
	Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 allows user-assisted remote attackers to inject arbitrary web script or HTML via a selection that is added to a document in which the designMode property is enabled.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 090848ec46b4dd478bc9cd3ba9442531 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063391" comment="mozilla-xulrunner192-x86 less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 0c29d728f4fd029a2fbf4ea1e669fc81 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064213" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
			</criteria>
		</criteria></criteria>
	<!-- 50a3e55a414b85ba53fc6385752379a7 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063391" comment="mozilla-xulrunner192-x86 less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
			</criteria>
		</criteria></criteria>
	<!-- 8f1a8feab628d727a6016f2016a02361 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064213" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102770" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2770</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2770" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2770" source="CVE"/>
	<description>
	Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 on Mac OS X allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted font in a data: URL.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 090848ec46b4dd478bc9cd3ba9442531 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063391" comment="mozilla-xulrunner192-x86 less than 1.9.2.10-1.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
		</criteria>
	</criteria>
	<!-- 0c29d728f4fd029a2fbf4ea1e669fc81 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064213" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
			</criteria>
		</criteria></criteria>
	<!-- 50a3e55a414b85ba53fc6385752379a7 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063391" comment="mozilla-xulrunner192-x86 less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063386" comment="MozillaFirefox-translations less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063387" comment="MozillaFirefox less than 3.6.10-1.6.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063388" comment="mozilla-xulrunner192-32bit less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063389" comment="mozilla-xulrunner192-gnome less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063390" comment="mozilla-xulrunner192-translations less than 1.9.2.10-1.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063392" comment="mozilla-xulrunner192 less than 1.9.2.10-1.1.1"/>
			</criteria>
		</criteria></criteria>
	<!-- 8f1a8feab628d727a6016f2016a02361 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064210" comment="mozilla-xulrunner191-32bit less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064211" comment="mozilla-xulrunner191-gnomevfs less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064212" comment="mozilla-xulrunner191-translations less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064213" comment="mozilla-xulrunner191-x86 less than 1.9.1.11-0.1.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064214" comment="mozilla-xulrunner191 less than 1.9.1.11-0.1.15"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102798" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2798</title>
	<affected family="unix">
		<platform>SLE 11 SERVER Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2798" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2798" source="CVE"/>
	<description>
	The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, which allows local users to cause a denial of service (NULL pointer dereference and panic) and possibly have unspecified other impact by renaming a file in a GFS2 filesystem, related to the gfs2_rename function in fs/gfs2/ops_inode.c.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 397f45e4eb102e91e10ebd86d7e1eb7b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063839" comment="ext4dev-kmp-default less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063840" comment="ext4dev-kmp-pae less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063841" comment="ext4dev-kmp-vmi less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063842" comment="ext4dev-kmp-xen less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063845" comment="kernel-pae-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063846" comment="kernel-pae less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063849" comment="kernel-vmi-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063850" comment="kernel-vmi less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063851" comment="kernel-xen-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063852" comment="kernel-xen less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- 4bacf8b00c9bc222e0a14ed705d0b9ad -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063854" comment="kernel-ppc64-extra less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- 70608756570f270952a30400f0f97a67 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062391" comment="ext4dev-kmp-xen less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
			</criteria>
		</criteria></criteria>
	<!-- 72ae5c3ed53caa1ba58b4f047b0e9c3b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
	</criteria>
	<!-- 83796b8aba495c97aa0d63167a692970 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063855" comment="kernel-pae-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063856" comment="kernel-xen-extra less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- 9343885edda5fa87713dfe0432ee1dde -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062404" comment="ext4dev-kmp-ppc64 less than 0_2.6.32.19_0.2-7.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062405" comment="kernel-ppc64-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062406" comment="kernel-ppc64-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062407" comment="kernel-ppc64 less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
	<!-- a26754073e422d7b7d2bdf784e6e85c7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
	</criteria>
	<!-- a28f8d8e1ce77f22744f2d703cc04134 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
	<!-- adf6f45f6f57d4321fb47c3a8b0daacd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063839" comment="ext4dev-kmp-default less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063857" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063858" comment="kernel-kdump less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063859" comment="kernel-ppc64-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063860" comment="kernel-ppc64 less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- bd9ae64a765977a7721644cb644a9d43 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063856" comment="kernel-xen-extra less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- d3c38f03bc070bd67fc914231f086f3e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063839" comment="ext4dev-kmp-default less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- d69f430f61b72448377e859dd89a3663 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063839" comment="ext4dev-kmp-default less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063842" comment="ext4dev-kmp-xen less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063851" comment="kernel-xen-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063852" comment="kernel-xen less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- e2f6c6cc02f7dc05554cab87c9f88650 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062408" comment="btrfs-kmp-pae less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062409" comment="ext4dev-kmp-pae less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062391" comment="ext4dev-kmp-xen less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062410" comment="hyper-v-kmp-pae less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062411" comment="kernel-pae-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062412" comment="kernel-pae-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062413" comment="kernel-pae less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062408" comment="btrfs-kmp-pae less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062409" comment="ext4dev-kmp-pae less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062410" comment="hyper-v-kmp-pae less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062411" comment="kernel-pae-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062412" comment="kernel-pae-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062413" comment="kernel-pae less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
			</criteria>
		</criteria></criteria>
	<!-- f3a833ad82c2fedcac92886c8ef582ff -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063839" comment="ext4dev-kmp-default less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063861" comment="iscsitarget-kmp-default less than 0.4.15_2.6.27.54_0.2-94.14.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063862" comment="kernel-default-man less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063863" comment="oracleasm-kmp-default less than 2.0.5_2.6.27.54_0.2-7.9.1"/>
		</criteria>
	</criteria>
	<!-- ff70db7653be66560fa26573ef04bc05 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062414" comment="kernel-default-man less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102803" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2803</title>
	<affected family="unix">
		<platform>SLE 11 SERVER Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2803" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2803" source="CVE"/>
	<description>
	The drm_ioctl function in drivers/gpu/drm/drm_drv.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.27.53, 2.6.32.x before 2.6.32.21, 2.6.34.x before 2.6.34.6, and 2.6.35.x before 2.6.35.4 allows local users to obtain potentially sensitive information from kernel memory by requesting a large memory-allocation amount.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 397f45e4eb102e91e10ebd86d7e1eb7b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063839" comment="ext4dev-kmp-default less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063840" comment="ext4dev-kmp-pae less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063841" comment="ext4dev-kmp-vmi less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063842" comment="ext4dev-kmp-xen less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063845" comment="kernel-pae-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063846" comment="kernel-pae less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063849" comment="kernel-vmi-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063850" comment="kernel-vmi less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063851" comment="kernel-xen-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063852" comment="kernel-xen less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- 4bacf8b00c9bc222e0a14ed705d0b9ad -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063854" comment="kernel-ppc64-extra less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- 70608756570f270952a30400f0f97a67 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062391" comment="ext4dev-kmp-xen less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
			</criteria>
		</criteria></criteria>
	<!-- 72ae5c3ed53caa1ba58b4f047b0e9c3b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
	</criteria>
	<!-- 83796b8aba495c97aa0d63167a692970 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063855" comment="kernel-pae-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063856" comment="kernel-xen-extra less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- 9343885edda5fa87713dfe0432ee1dde -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062404" comment="ext4dev-kmp-ppc64 less than 0_2.6.32.19_0.2-7.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062405" comment="kernel-ppc64-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062406" comment="kernel-ppc64-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062407" comment="kernel-ppc64 less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
	<!-- a26754073e422d7b7d2bdf784e6e85c7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
	</criteria>
	<!-- a28f8d8e1ce77f22744f2d703cc04134 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
	<!-- adf6f45f6f57d4321fb47c3a8b0daacd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063839" comment="ext4dev-kmp-default less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063857" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063858" comment="kernel-kdump less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063859" comment="kernel-ppc64-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063860" comment="kernel-ppc64 less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- bd9ae64a765977a7721644cb644a9d43 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063856" comment="kernel-xen-extra less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- d3c38f03bc070bd67fc914231f086f3e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063839" comment="ext4dev-kmp-default less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- d69f430f61b72448377e859dd89a3663 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063839" comment="ext4dev-kmp-default less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063842" comment="ext4dev-kmp-xen less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063851" comment="kernel-xen-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063852" comment="kernel-xen less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- e2f6c6cc02f7dc05554cab87c9f88650 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062408" comment="btrfs-kmp-pae less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062409" comment="ext4dev-kmp-pae less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062391" comment="ext4dev-kmp-xen less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062410" comment="hyper-v-kmp-pae less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062411" comment="kernel-pae-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062412" comment="kernel-pae-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062413" comment="kernel-pae less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062408" comment="btrfs-kmp-pae less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062409" comment="ext4dev-kmp-pae less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062410" comment="hyper-v-kmp-pae less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062411" comment="kernel-pae-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062412" comment="kernel-pae-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062413" comment="kernel-pae less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
			</criteria>
		</criteria></criteria>
	<!-- f3a833ad82c2fedcac92886c8ef582ff -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063839" comment="ext4dev-kmp-default less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063861" comment="iscsitarget-kmp-default less than 0.4.15_2.6.27.54_0.2-94.14.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063862" comment="kernel-default-man less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063863" comment="oracleasm-kmp-default less than 2.0.5_2.6.27.54_0.2-7.9.1"/>
		</criteria>
	</criteria>
	<!-- ff70db7653be66560fa26573ef04bc05 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062414" comment="kernel-default-man less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102805" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2805</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2805" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2805" source="CVE"/>
	<description>
	The FT_Stream_EnterFrame function in base/ftstream.c in FreeType before 2.4.2 does not properly validate certain position values, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 7bcc9a1fade88c7620df728424de42c5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062064" comment="freetype2-x86 less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
	<!-- f28613bd3eb0b0f8e83bbf97c432760b -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062064" comment="freetype2-x86 less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102806" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2806</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2806" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2806" source="CVE"/>
	<description>
	Array index error in the t42_parse_sfnts function in type42/t42parse.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via negative size values for certain strings in FontType42 font files, leading to a heap-based buffer overflow.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 7bcc9a1fade88c7620df728424de42c5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062064" comment="freetype2-x86 less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
	<!-- f28613bd3eb0b0f8e83bbf97c432760b -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062064" comment="freetype2-x86 less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102807" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2807</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2807" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2807" source="CVE"/>
	<description>
	FreeType before 2.4.2 uses incorrect integer data types during bounds checking, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 7bcc9a1fade88c7620df728424de42c5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062064" comment="freetype2-x86 less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
	<!-- f28613bd3eb0b0f8e83bbf97c432760b -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062064" comment="freetype2-x86 less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102808" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2808</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2808" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2808" source="CVE"/>
	<description>
	Buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Adobe Type 1 Mac Font File (aka LWFN) font.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 7bcc9a1fade88c7620df728424de42c5 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062064" comment="freetype2-x86 less than 2.3.7-25.11.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
		</criteria>
	</criteria>
	<!-- f28613bd3eb0b0f8e83bbf97c432760b -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062064" comment="freetype2-x86 less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062063" comment="freetype2-32bit less than 2.3.7-25.11.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062065" comment="freetype2 less than 2.3.7-25.11.1"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102939" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2939</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2939" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2939" source="CVE"/>
	<description>
	Double free vulnerability in the ssl3_get_key_exchange function in the OpenSSL client (ssl/s3_clnt.c) in OpenSSL 1.0.0a, 0.9.8, 0.9.7, and possibly other versions, when using ECDH, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted private key with an invalid prime.  NOTE: some sources refer to this as a use-after-free issue.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- b2240bd1cc1b86d466bf4511cb5287fd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064298" comment="libopenssl0_9_8-32bit less than 0.9.8h-30.22.22.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064299" comment="libopenssl0_9_8-x86 less than 0.9.8h-30.22.22.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064300" comment="libopenssl0_9_8 less than 0.9.8h-30.22.22.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064301" comment="openssl-doc less than 0.9.8h-30.22.22.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064302" comment="openssl less than 0.9.8h-30.22.22.1"/>
		</criteria>
	</criteria>
	<!-- d4275070c6d35e2cd6ce91e877bc91e7 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064303" comment="libopenssl0_9_8-32bit less than 0.9.8h-30.28.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064304" comment="libopenssl0_9_8-x86 less than 0.9.8h-30.28.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064305" comment="libopenssl0_9_8 less than 0.9.8h-30.28.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064306" comment="openssl-doc less than 0.9.8h-30.28.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064307" comment="openssl less than 0.9.8h-30.28.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064303" comment="libopenssl0_9_8-32bit less than 0.9.8h-30.28.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064305" comment="libopenssl0_9_8 less than 0.9.8h-30.28.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064306" comment="openssl-doc less than 0.9.8h-30.28.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064307" comment="openssl less than 0.9.8h-30.28.1"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102941" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2941</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2941" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2941" source="CVE"/>
	<description>
	ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted IPP request.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- d603aeff8a309d9d04651d4469e31973 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009064776" comment="cups-client less than 1.3.9-8.37.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064777" comment="cups-libs-32bit less than 1.3.9-8.37.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064778" comment="cups-libs-x86 less than 1.3.9-8.37.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064779" comment="cups-libs less than 1.3.9-8.37.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064780" comment="cups less than 1.3.9-8.37.1"/>
		</criteria>
	</criteria>
	<!-- e290f3059978b800480c09727b4b714a -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064776" comment="cups-client less than 1.3.9-8.37.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064777" comment="cups-libs-32bit less than 1.3.9-8.37.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064778" comment="cups-libs-x86 less than 1.3.9-8.37.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064779" comment="cups-libs less than 1.3.9-8.37.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064780" comment="cups less than 1.3.9-8.37.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009064776" comment="cups-client less than 1.3.9-8.37.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064777" comment="cups-libs-32bit less than 1.3.9-8.37.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064779" comment="cups-libs less than 1.3.9-8.37.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009064780" comment="cups less than 1.3.9-8.37.1"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102942" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2942</title>
	<affected family="unix">
		<platform>SLE 11 SERVER Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2942" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2942" source="CVE"/>
	<description>
	The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump operations, which allows local users to obtain potentially sensitive information from kernel memory via vectors related to (1) the tcf_gact_dump function in net/sched/act_gact.c, (2) the tcf_mirred_dump function in net/sched/act_mirred.c, (3) the tcf_nat_dump function in net/sched/act_nat.c, (4) the tcf_simp_dump function in net/sched/act_simple.c, and (5) the tcf_skbedit_dump function in net/sched/act_skbedit.c.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 397f45e4eb102e91e10ebd86d7e1eb7b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063839" comment="ext4dev-kmp-default less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063840" comment="ext4dev-kmp-pae less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063841" comment="ext4dev-kmp-vmi less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063842" comment="ext4dev-kmp-xen less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063845" comment="kernel-pae-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063846" comment="kernel-pae less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063849" comment="kernel-vmi-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063850" comment="kernel-vmi less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063851" comment="kernel-xen-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063852" comment="kernel-xen less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- 4bacf8b00c9bc222e0a14ed705d0b9ad -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063854" comment="kernel-ppc64-extra less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- 70608756570f270952a30400f0f97a67 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062391" comment="ext4dev-kmp-xen less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
			</criteria>
		</criteria></criteria>
	<!-- 72ae5c3ed53caa1ba58b4f047b0e9c3b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
	</criteria>
	<!-- 83796b8aba495c97aa0d63167a692970 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063855" comment="kernel-pae-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063856" comment="kernel-xen-extra less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- 9343885edda5fa87713dfe0432ee1dde -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062404" comment="ext4dev-kmp-ppc64 less than 0_2.6.32.19_0.2-7.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062405" comment="kernel-ppc64-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062406" comment="kernel-ppc64-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062407" comment="kernel-ppc64 less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
	<!-- a26754073e422d7b7d2bdf784e6e85c7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
	</criteria>
	<!-- a28f8d8e1ce77f22744f2d703cc04134 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
	<!-- adf6f45f6f57d4321fb47c3a8b0daacd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063839" comment="ext4dev-kmp-default less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063857" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063858" comment="kernel-kdump less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063859" comment="kernel-ppc64-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063860" comment="kernel-ppc64 less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- bd9ae64a765977a7721644cb644a9d43 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063856" comment="kernel-xen-extra less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- d3c38f03bc070bd67fc914231f086f3e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063839" comment="ext4dev-kmp-default less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- d69f430f61b72448377e859dd89a3663 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063839" comment="ext4dev-kmp-default less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063842" comment="ext4dev-kmp-xen less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063851" comment="kernel-xen-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063852" comment="kernel-xen less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- e2f6c6cc02f7dc05554cab87c9f88650 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062408" comment="btrfs-kmp-pae less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062409" comment="ext4dev-kmp-pae less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062391" comment="ext4dev-kmp-xen less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062410" comment="hyper-v-kmp-pae less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062411" comment="kernel-pae-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062412" comment="kernel-pae-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062413" comment="kernel-pae less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062408" comment="btrfs-kmp-pae less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062409" comment="ext4dev-kmp-pae less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062410" comment="hyper-v-kmp-pae less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062411" comment="kernel-pae-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062412" comment="kernel-pae-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062413" comment="kernel-pae less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
			</criteria>
		</criteria></criteria>
	<!-- f3a833ad82c2fedcac92886c8ef582ff -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063839" comment="ext4dev-kmp-default less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063861" comment="iscsitarget-kmp-default less than 0.4.15_2.6.27.54_0.2-94.14.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063862" comment="kernel-default-man less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063863" comment="oracleasm-kmp-default less than 2.0.5_2.6.27.54_0.2-7.9.1"/>
		</criteria>
	</criteria>
	<!-- ff70db7653be66560fa26573ef04bc05 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062414" comment="kernel-default-man less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102943" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2943</title>
	<affected family="unix">
		<platform>SLE 11 SERVER Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2943" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2943" source="CVE"/>
	<description>
	The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read or overwrite disk blocks that are currently assigned to an active file but were previously assigned to an unlinked file, by accessing a stale NFS filehandle.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 37a20332a3477c6790648da1bb44afd0 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009065986" comment="btrfs-kmp-default less than 0_2.6.32.29_0.3-0.3.34"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065987" comment="ext4dev-kmp-default less than 0_2.6.32.29_0.3-7.9.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065988" comment="kernel-default-base less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065989" comment="kernel-default-devel less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065990" comment="kernel-default-man less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065991" comment="kernel-default less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065992" comment="kernel-source less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065993" comment="kernel-syms less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065994" comment="kernel-trace-base less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065995" comment="kernel-trace-devel less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065996" comment="kernel-trace less than 2.6.32.29-0.3.1"/>
		</criteria>
	</criteria>
	<!-- 40fa968a3fed1c5ae479db978466dc9b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009065986" comment="btrfs-kmp-default less than 0_2.6.32.29_0.3-0.3.34"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065987" comment="ext4dev-kmp-default less than 0_2.6.32.29_0.3-7.9.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065997" comment="ext4dev-kmp-ppc64 less than 0_2.6.32.29_0.3-7.9.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065988" comment="kernel-default-base less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065989" comment="kernel-default-devel less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065991" comment="kernel-default less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065998" comment="kernel-ppc64-base less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065999" comment="kernel-ppc64-devel less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009066000" comment="kernel-ppc64 less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065992" comment="kernel-source less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065993" comment="kernel-syms less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065994" comment="kernel-trace-base less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065995" comment="kernel-trace-devel less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065996" comment="kernel-trace less than 2.6.32.29-0.3.1"/>
		</criteria>
	</criteria>
	<!-- a980dec7ad0f6081c9c24832e0e59c6f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009065986" comment="btrfs-kmp-default less than 0_2.6.32.29_0.3-0.3.34"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065987" comment="ext4dev-kmp-default less than 0_2.6.32.29_0.3-7.9.2"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065988" comment="kernel-default-base less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065989" comment="kernel-default-devel less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065991" comment="kernel-default less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065992" comment="kernel-source less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065993" comment="kernel-syms less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065994" comment="kernel-trace-base less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065995" comment="kernel-trace-devel less than 2.6.32.29-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009065996" comment="kernel-trace less than 2.6.32.29-0.3.1"/>
		</criteria>
	</criteria>
	<!-- abeba8d6c807360502c7dfc6ca6f2b4d -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009065986" comment="btrfs-kmp-default less than 0_2.6.32.29_0.3-0.3.34"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066001" comment="btrfs-kmp-pae less than 0_2.6.32.29_0.3-0.3.34"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066002" comment="btrfs-kmp-xen less than 0_2.6.32.29_0.3-0.3.34"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065987" comment="ext4dev-kmp-default less than 0_2.6.32.29_0.3-7.9.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066003" comment="ext4dev-kmp-pae less than 0_2.6.32.29_0.3-7.9.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066004" comment="ext4dev-kmp-xen less than 0_2.6.32.29_0.3-7.9.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066005" comment="hyper-v-kmp-default less than 0_2.6.32.29_0.3-0.10.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066006" comment="hyper-v-kmp-pae less than 0_2.6.32.29_0.3-0.10.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065988" comment="kernel-default-base less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065989" comment="kernel-default-devel less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065991" comment="kernel-default less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066007" comment="kernel-ec2-base less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066008" comment="kernel-ec2 less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066009" comment="kernel-pae-base less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066010" comment="kernel-pae-devel less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066011" comment="kernel-pae less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065992" comment="kernel-source less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065993" comment="kernel-syms less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065994" comment="kernel-trace-base less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065995" comment="kernel-trace-devel less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065996" comment="kernel-trace less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066012" comment="kernel-xen-base less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066013" comment="kernel-xen-devel less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066014" comment="kernel-xen less than 2.6.32.29-0.3.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009065986" comment="btrfs-kmp-default less than 0_2.6.32.29_0.3-0.3.34"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066001" comment="btrfs-kmp-pae less than 0_2.6.32.29_0.3-0.3.34"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065987" comment="ext4dev-kmp-default less than 0_2.6.32.29_0.3-7.9.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066003" comment="ext4dev-kmp-pae less than 0_2.6.32.29_0.3-7.9.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066005" comment="hyper-v-kmp-default less than 0_2.6.32.29_0.3-0.10.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066006" comment="hyper-v-kmp-pae less than 0_2.6.32.29_0.3-0.10.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065988" comment="kernel-default-base less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065989" comment="kernel-default-devel less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065991" comment="kernel-default less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066009" comment="kernel-pae-base less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066010" comment="kernel-pae-devel less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066011" comment="kernel-pae less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065992" comment="kernel-source less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065993" comment="kernel-syms less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065994" comment="kernel-trace-base less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065995" comment="kernel-trace-devel less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065996" comment="kernel-trace less than 2.6.32.29-0.3.1"/>
			</criteria>
		</criteria></criteria>
	<!-- b296065a76246d5eb3b84a54249a6ab9 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009065986" comment="btrfs-kmp-default less than 0_2.6.32.29_0.3-0.3.34"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066002" comment="btrfs-kmp-xen less than 0_2.6.32.29_0.3-0.3.34"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065987" comment="ext4dev-kmp-default less than 0_2.6.32.29_0.3-7.9.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066004" comment="ext4dev-kmp-xen less than 0_2.6.32.29_0.3-7.9.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066005" comment="hyper-v-kmp-default less than 0_2.6.32.29_0.3-0.10.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065988" comment="kernel-default-base less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065989" comment="kernel-default-devel less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065991" comment="kernel-default less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066007" comment="kernel-ec2-base less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066008" comment="kernel-ec2 less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065992" comment="kernel-source less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065993" comment="kernel-syms less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065994" comment="kernel-trace-base less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065995" comment="kernel-trace-devel less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065996" comment="kernel-trace less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066012" comment="kernel-xen-base less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066013" comment="kernel-xen-devel less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066014" comment="kernel-xen less than 2.6.32.29-0.3.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009065986" comment="btrfs-kmp-default less than 0_2.6.32.29_0.3-0.3.34"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065987" comment="ext4dev-kmp-default less than 0_2.6.32.29_0.3-7.9.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009066005" comment="hyper-v-kmp-default less than 0_2.6.32.29_0.3-0.10.2"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065988" comment="kernel-default-base less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065989" comment="kernel-default-devel less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065991" comment="kernel-default less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065992" comment="kernel-source less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065993" comment="kernel-syms less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065994" comment="kernel-trace-base less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065995" comment="kernel-trace-devel less than 2.6.32.29-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009065996" comment="kernel-trace less than 2.6.32.29-0.3.1"/>
			</criteria>
		</criteria></criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102946" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2946</title>
	<affected family="unix">
		<platform>SLE 11 SERVER Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2946" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2946" source="CVE"/>
	<description>
	fs/jfs/xattr.c in the Linux kernel before 2.6.35.2 does not properly handle a certain legacy format for storage of extended attributes, which might allow local users by bypass intended xattr namespace restrictions via an "os2." substring at the beginning of a name.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 397f45e4eb102e91e10ebd86d7e1eb7b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063839" comment="ext4dev-kmp-default less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063840" comment="ext4dev-kmp-pae less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063841" comment="ext4dev-kmp-vmi less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063842" comment="ext4dev-kmp-xen less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063845" comment="kernel-pae-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063846" comment="kernel-pae less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063849" comment="kernel-vmi-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063850" comment="kernel-vmi less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063851" comment="kernel-xen-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063852" comment="kernel-xen less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- 4bacf8b00c9bc222e0a14ed705d0b9ad -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063854" comment="kernel-ppc64-extra less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- 70608756570f270952a30400f0f97a67 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062391" comment="ext4dev-kmp-xen less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
			</criteria>
		</criteria></criteria>
	<!-- 72ae5c3ed53caa1ba58b4f047b0e9c3b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
	</criteria>
	<!-- 83796b8aba495c97aa0d63167a692970 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063855" comment="kernel-pae-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063856" comment="kernel-xen-extra less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- 9343885edda5fa87713dfe0432ee1dde -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062404" comment="ext4dev-kmp-ppc64 less than 0_2.6.32.19_0.2-7.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062405" comment="kernel-ppc64-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062406" comment="kernel-ppc64-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062407" comment="kernel-ppc64 less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
	<!-- a26754073e422d7b7d2bdf784e6e85c7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
	</criteria>
	<!-- a28f8d8e1ce77f22744f2d703cc04134 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
	<!-- adf6f45f6f57d4321fb47c3a8b0daacd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063839" comment="ext4dev-kmp-default less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063857" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063858" comment="kernel-kdump less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063859" comment="kernel-ppc64-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063860" comment="kernel-ppc64 less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- bd9ae64a765977a7721644cb644a9d43 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063856" comment="kernel-xen-extra less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- d3c38f03bc070bd67fc914231f086f3e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063839" comment="ext4dev-kmp-default less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- d69f430f61b72448377e859dd89a3663 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063839" comment="ext4dev-kmp-default less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063842" comment="ext4dev-kmp-xen less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063851" comment="kernel-xen-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063852" comment="kernel-xen less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- e2f6c6cc02f7dc05554cab87c9f88650 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062408" comment="btrfs-kmp-pae less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062389" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062409" comment="ext4dev-kmp-pae less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062391" comment="ext4dev-kmp-xen less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062410" comment="hyper-v-kmp-pae less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062411" comment="kernel-pae-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062412" comment="kernel-pae-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062413" comment="kernel-pae less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062401" comment="kernel-xen-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062402" comment="kernel-xen-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062403" comment="kernel-xen less than 2.6.32.19-0.2.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062408" comment="btrfs-kmp-pae less than 0_2.6.32.19_0.2-0.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062409" comment="ext4dev-kmp-pae less than 0_2.6.32.19_0.2-7.3.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062392" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062410" comment="hyper-v-kmp-pae less than 0_2.6.32.19_0.2-0.7.11"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062411" comment="kernel-pae-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062412" comment="kernel-pae-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062413" comment="kernel-pae less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
			</criteria>
		</criteria></criteria>
	<!-- f3a833ad82c2fedcac92886c8ef582ff -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063839" comment="ext4dev-kmp-default less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063861" comment="iscsitarget-kmp-default less than 0.4.15_2.6.27.54_0.2-94.14.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063862" comment="kernel-default-man less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063863" comment="oracleasm-kmp-default less than 2.0.5_2.6.27.54_0.2-7.9.1"/>
		</criteria>
	</criteria>
	<!-- ff70db7653be66560fa26573ef04bc05 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062388" comment="btrfs-kmp-default less than 0_2.6.32.19_0.2-0.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062390" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.2-7.3.15"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062393" comment="kernel-default-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062394" comment="kernel-default-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062414" comment="kernel-default-man less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062395" comment="kernel-default less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062396" comment="kernel-source less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062397" comment="kernel-syms less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062398" comment="kernel-trace-base less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062399" comment="kernel-trace-devel less than 2.6.32.19-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062400" comment="kernel-trace less than 2.6.32.19-0.2.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102947" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2947</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2947" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2947" source="CVE"/>
	<description>
	Heap-based buffer overflow in the HX_split function in string.c in libHX before 3.6 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a string that is inconsistent with the expected number of fields.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 4e77557a3a7b0f2f19676adf628cafc7 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063455" comment="libHX13-32bit less than 1.23-4.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063456" comment="libHX13-x86 less than 1.23-4.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063457" comment="libHX13 less than 1.23-4.1.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063455" comment="libHX13-32bit less than 1.23-4.1.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063457" comment="libHX13 less than 1.23-4.1.1"/>
			</criteria>
		</criteria></criteria>
	<!-- cbb98a2d5ddca9caae96d5d63dee035f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063455" comment="libHX13-32bit less than 1.23-4.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063456" comment="libHX13-x86 less than 1.23-4.1.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063457" comment="libHX13 less than 1.23-4.1.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102948" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2948</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2948" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2948" source="CVE"/>
	<description>
	Stack-based buffer overflow in the bgp_route_refresh_receive function in bgp_packet.c in bgpd in Quagga before 0.99.17 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a malformed Outbound Route Filtering (ORF) record in a BGP ROUTE-REFRESH (RR) message.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 344cc2cc5934e6e983a0a577e99d387f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064507" comment="quagga less than 0.99.15-0.2.1"/>
	</criteria>
	<!-- 7dc27bc7ebc4925ed4cfc0179671386b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064508" comment="quagga less than 0.99.10-17.18.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102949" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2949</title>
	<affected family="unix">
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2949" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2949" source="CVE"/>
	<description>
	bgpd in Quagga before 0.99.17 does not properly parse AS paths, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an unknown AS type in an AS path attribute in a BGP UPDATE message.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 344cc2cc5934e6e983a0a577e99d387f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064507" comment="quagga less than 0.99.15-0.2.1"/>
	</criteria>
	<!-- 7dc27bc7ebc4925ed4cfc0179671386b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009064508" comment="quagga less than 0.99.10-17.18.1"/>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102954" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2954</title>
	<affected family="unix">
		<platform>SLE 11 SERVER Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2954" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2954" source="CVE"/>
	<description>
	The irda_bind function in net/irda/af_irda.c in the Linux kernel before 2.6.36-rc3-next-20100901 does not properly handle failure of the irda_open_tsap function, which allows local users to cause a denial of service (NULL pointer dereference and panic) and possibly have unspecified other impact via multiple unsuccessful calls to bind on an AF_IRDA (aka PF_IRDA) socket.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 039ba32580d28580329514de944be593 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063425" comment="btrfs-kmp-default less than 0_2.6.32.23_0.3-0.3.20"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063426" comment="btrfs-kmp-xen less than 0_2.6.32.23_0.3-0.3.20"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063427" comment="ext4dev-kmp-default less than 0_2.6.32.23_0.3-7.3.20"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063428" comment="ext4dev-kmp-xen less than 0_2.6.32.23_0.3-7.3.20"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063429" comment="hyper-v-kmp-default less than 0_2.6.32.23_0.3-0.7.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063430" comment="kernel-default-base less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063431" comment="kernel-default-devel less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063432" comment="kernel-default less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063433" comment="kernel-ec2-base less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063434" comment="kernel-ec2-devel less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063435" comment="kernel-ec2 less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063436" comment="kernel-source less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063437" comment="kernel-syms less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063438" comment="kernel-trace-base less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063439" comment="kernel-trace-devel less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063440" comment="kernel-trace less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063441" comment="kernel-xen-base less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063442" comment="kernel-xen-devel less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063443" comment="kernel-xen less than 2.6.32.23-0.3.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063425" comment="btrfs-kmp-default less than 0_2.6.32.23_0.3-0.3.20"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063427" comment="ext4dev-kmp-default less than 0_2.6.32.23_0.3-7.3.20"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063429" comment="hyper-v-kmp-default less than 0_2.6.32.23_0.3-0.7.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063430" comment="kernel-default-base less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063431" comment="kernel-default-devel less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063432" comment="kernel-default less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063436" comment="kernel-source less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063437" comment="kernel-syms less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063438" comment="kernel-trace-base less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063439" comment="kernel-trace-devel less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063440" comment="kernel-trace less than 2.6.32.23-0.3.1"/>
			</criteria>
		</criteria></criteria>
	<!-- 0b6dfabf37b6d2b5cada53458079e702 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063425" comment="btrfs-kmp-default less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063427" comment="ext4dev-kmp-default less than 0_2.6.32.23_0.3-7.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063430" comment="kernel-default-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063431" comment="kernel-default-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063444" comment="kernel-default-man less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063432" comment="kernel-default less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063436" comment="kernel-source less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063437" comment="kernel-syms less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063438" comment="kernel-trace-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063439" comment="kernel-trace-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063440" comment="kernel-trace less than 2.6.32.23-0.3.1"/>
		</criteria>
	</criteria>
	<!-- 397f45e4eb102e91e10ebd86d7e1eb7b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063839" comment="ext4dev-kmp-default less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063840" comment="ext4dev-kmp-pae less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063841" comment="ext4dev-kmp-vmi less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063842" comment="ext4dev-kmp-xen less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063845" comment="kernel-pae-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063846" comment="kernel-pae less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063849" comment="kernel-vmi-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063850" comment="kernel-vmi less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063851" comment="kernel-xen-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063852" comment="kernel-xen less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- 4bacf8b00c9bc222e0a14ed705d0b9ad -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063854" comment="kernel-ppc64-extra less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- 5d21a11418f02516ef6ae58f362c1f98 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063425" comment="btrfs-kmp-default less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063427" comment="ext4dev-kmp-default less than 0_2.6.32.23_0.3-7.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063465" comment="ext4dev-kmp-ppc64 less than 0_2.6.32.23_0.3-7.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063430" comment="kernel-default-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063431" comment="kernel-default-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063432" comment="kernel-default less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063466" comment="kernel-ppc64-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063467" comment="kernel-ppc64-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063468" comment="kernel-ppc64 less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063436" comment="kernel-source less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063437" comment="kernel-syms less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063438" comment="kernel-trace-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063439" comment="kernel-trace-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063440" comment="kernel-trace less than 2.6.32.23-0.3.1"/>
		</criteria>
	</criteria>
	<!-- 72ae5c3ed53caa1ba58b4f047b0e9c3b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
	</criteria>
	<!-- 83796b8aba495c97aa0d63167a692970 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063855" comment="kernel-pae-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063856" comment="kernel-xen-extra less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- a26754073e422d7b7d2bdf784e6e85c7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
	</criteria>
	<!-- a412f327abfdfb030c31be1c37133055 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063425" comment="btrfs-kmp-default less than 0_2.6.32.23_0.3-0.3.20"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063445" comment="btrfs-kmp-pae less than 0_2.6.32.23_0.3-0.3.20"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063426" comment="btrfs-kmp-xen less than 0_2.6.32.23_0.3-0.3.20"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063427" comment="ext4dev-kmp-default less than 0_2.6.32.23_0.3-7.3.20"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063446" comment="ext4dev-kmp-pae less than 0_2.6.32.23_0.3-7.3.20"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063428" comment="ext4dev-kmp-xen less than 0_2.6.32.23_0.3-7.3.20"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063429" comment="hyper-v-kmp-default less than 0_2.6.32.23_0.3-0.7.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063447" comment="hyper-v-kmp-pae less than 0_2.6.32.23_0.3-0.7.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063430" comment="kernel-default-base less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063431" comment="kernel-default-devel less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063432" comment="kernel-default less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063433" comment="kernel-ec2-base less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063434" comment="kernel-ec2-devel less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063435" comment="kernel-ec2 less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063448" comment="kernel-pae-base less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063449" comment="kernel-pae-devel less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063450" comment="kernel-pae less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063436" comment="kernel-source less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063437" comment="kernel-syms less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063438" comment="kernel-trace-base less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063439" comment="kernel-trace-devel less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063440" comment="kernel-trace less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063441" comment="kernel-xen-base less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063442" comment="kernel-xen-devel less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063443" comment="kernel-xen less than 2.6.32.23-0.3.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009063425" comment="btrfs-kmp-default less than 0_2.6.32.23_0.3-0.3.20"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063445" comment="btrfs-kmp-pae less than 0_2.6.32.23_0.3-0.3.20"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063427" comment="ext4dev-kmp-default less than 0_2.6.32.23_0.3-7.3.20"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063446" comment="ext4dev-kmp-pae less than 0_2.6.32.23_0.3-7.3.20"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063429" comment="hyper-v-kmp-default less than 0_2.6.32.23_0.3-0.7.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063447" comment="hyper-v-kmp-pae less than 0_2.6.32.23_0.3-0.7.15"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063430" comment="kernel-default-base less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063431" comment="kernel-default-devel less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063432" comment="kernel-default less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063448" comment="kernel-pae-base less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063449" comment="kernel-pae-devel less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063450" comment="kernel-pae less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063436" comment="kernel-source less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063437" comment="kernel-syms less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063438" comment="kernel-trace-base less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063439" comment="kernel-trace-devel less than 2.6.32.23-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009063440" comment="kernel-trace less than 2.6.32.23-0.3.1"/>
			</criteria>
		</criteria></criteria>
	<!-- a7aa7671029d7a723db42187684cb976 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063425" comment="btrfs-kmp-default less than 0_2.6.32.23_0.3-0.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063427" comment="ext4dev-kmp-default less than 0_2.6.32.23_0.3-7.3.20"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063430" comment="kernel-default-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063431" comment="kernel-default-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063432" comment="kernel-default less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063436" comment="kernel-source less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063437" comment="kernel-syms less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063438" comment="kernel-trace-base less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063439" comment="kernel-trace-devel less than 2.6.32.23-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063440" comment="kernel-trace less than 2.6.32.23-0.3.1"/>
		</criteria>
	</criteria>
	<!-- adf6f45f6f57d4321fb47c3a8b0daacd -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063839" comment="ext4dev-kmp-default less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063857" comment="ext4dev-kmp-ppc64 less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063858" comment="kernel-kdump less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063859" comment="kernel-ppc64-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063860" comment="kernel-ppc64 less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- bd9ae64a765977a7721644cb644a9d43 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063856" comment="kernel-xen-extra less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- d3c38f03bc070bd67fc914231f086f3e -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063839" comment="ext4dev-kmp-default less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- d69f430f61b72448377e859dd89a3663 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063839" comment="ext4dev-kmp-default less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063842" comment="ext4dev-kmp-xen less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063851" comment="kernel-xen-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063852" comment="kernel-xen less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- f3a833ad82c2fedcac92886c8ef582ff -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063839" comment="ext4dev-kmp-default less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063861" comment="iscsitarget-kmp-default less than 0.4.15_2.6.27.54_0.2-94.14.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063862" comment="kernel-default-man less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063863" comment="oracleasm-kmp-default less than 2.0.5_2.6.27.54_0.2-7.9.1"/>
		</criteria>
	</criteria>
 </criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102955" version="0" class="vulnerability">
 <metadata>
 <title>CVE-2010-2955</title>
	<affected family="unix">
		<platform>SLE 11 SERVER Unsupported Extras</platform>
		<platform>SUSE Linux Enterprise Server 11 GA</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1</platform>
		<platform>SUSE Linux Enterprise Server 11 SP1 for VMware</platform>
	</affected>
	<reference ref_id="CVE-2010-2955" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2955" source="CVE"/>
	<description>
	The cfg80211_wext_giwessid function in net/wireless/wext-compat.c in the Linux kernel before 2.6.36-rc3-next-20100831 does not properly initialize certain structure members, which allows local users to leverage an off-by-one error in the ioctl_standard_iw_point function in net/wireless/wext-core.c, and obtain potentially sensitive information from kernel heap memory, via vectors involving an SIOCGIWESSID ioctl call that specifies a large buffer size.
	</description>
 </metadata>
 <criteria operator="OR">
	<!-- 397f45e4eb102e91e10ebd86d7e1eb7b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063839" comment="ext4dev-kmp-default less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063840" comment="ext4dev-kmp-pae less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063841" comment="ext4dev-kmp-vmi less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063842" comment="ext4dev-kmp-xen less than 0_2.6.27.54_0.2-7.1.43"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063843" comment="kernel-default-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063844" comment="kernel-default less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063845" comment="kernel-pae-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063846" comment="kernel-pae less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063847" comment="kernel-source less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063848" comment="kernel-syms less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063849" comment="kernel-vmi-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063850" comment="kernel-vmi less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063851" comment="kernel-xen-base less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063852" comment="kernel-xen less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- 421f9d6f4a3a600663a17b502da3b170 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062814" comment="btrfs-kmp-default less than 0_2.6.32.19_0.3-0.3.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062815" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.3-7.3.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062816" comment="kernel-default-base less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062817" comment="kernel-default-devel less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062818" comment="kernel-default less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062819" comment="kernel-source less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062820" comment="kernel-syms less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062821" comment="kernel-trace-base less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062822" comment="kernel-trace-devel less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062823" comment="kernel-trace less than 2.6.32.19-0.3.1"/>
		</criteria>
	</criteria>
	<!-- 43635d2ef5db017de2e87f6c750727d5 -->
	<criteria operator="OR">
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062814" comment="btrfs-kmp-default less than 0_2.6.32.19_0.3-0.3.16"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062824" comment="btrfs-kmp-pae less than 0_2.6.32.19_0.3-0.3.16"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062825" comment="btrfs-kmp-xen less than 0_2.6.32.19_0.3-0.3.16"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062815" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.3-7.3.16"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062826" comment="ext4dev-kmp-pae less than 0_2.6.32.19_0.3-7.3.16"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062827" comment="ext4dev-kmp-xen less than 0_2.6.32.19_0.3-7.3.16"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062828" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.3-0.7.12"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062829" comment="hyper-v-kmp-pae less than 0_2.6.32.19_0.3-0.7.12"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062816" comment="kernel-default-base less than 2.6.32.19-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062817" comment="kernel-default-devel less than 2.6.32.19-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062818" comment="kernel-default less than 2.6.32.19-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062830" comment="kernel-pae-base less than 2.6.32.19-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062831" comment="kernel-pae-devel less than 2.6.32.19-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062832" comment="kernel-pae less than 2.6.32.19-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062819" comment="kernel-source less than 2.6.32.19-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062820" comment="kernel-syms less than 2.6.32.19-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062821" comment="kernel-trace-base less than 2.6.32.19-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062822" comment="kernel-trace-devel less than 2.6.32.19-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062823" comment="kernel-trace less than 2.6.32.19-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062833" comment="kernel-xen-base less than 2.6.32.19-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062834" comment="kernel-xen-devel less than 2.6.32.19-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062835" comment="kernel-xen less than 2.6.32.19-0.3.1"/>
			</criteria>
		</criteria>
			<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062226" comment="sles11-sp1-vmware is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009062814" comment="btrfs-kmp-default less than 0_2.6.32.19_0.3-0.3.16"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062824" comment="btrfs-kmp-pae less than 0_2.6.32.19_0.3-0.3.16"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062815" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.3-7.3.16"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062826" comment="ext4dev-kmp-pae less than 0_2.6.32.19_0.3-7.3.16"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062828" comment="hyper-v-kmp-default less than 0_2.6.32.19_0.3-0.7.12"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062829" comment="hyper-v-kmp-pae less than 0_2.6.32.19_0.3-0.7.12"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062816" comment="kernel-default-base less than 2.6.32.19-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062817" comment="kernel-default-devel less than 2.6.32.19-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062818" comment="kernel-default less than 2.6.32.19-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062830" comment="kernel-pae-base less than 2.6.32.19-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062831" comment="kernel-pae-devel less than 2.6.32.19-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062832" comment="kernel-pae less than 2.6.32.19-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062819" comment="kernel-source less than 2.6.32.19-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062820" comment="kernel-syms less than 2.6.32.19-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062821" comment="kernel-trace-base less than 2.6.32.19-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062822" comment="kernel-trace-devel less than 2.6.32.19-0.3.1"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009062823" comment="kernel-trace less than 2.6.32.19-0.3.1"/>
			</criteria>
		</criteria></criteria>
	<!-- 4bacf8b00c9bc222e0a14ed705d0b9ad -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063854" comment="kernel-ppc64-extra less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- 72ae5c3ed53caa1ba58b4f047b0e9c3b -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
	</criteria>
	<!-- 83796b8aba495c97aa0d63167a692970 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063855" comment="kernel-pae-extra less than 2.6.27.54-0.2.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063856" comment="kernel-xen-extra less than 2.6.27.54-0.2.1"/>
		</criteria>
	</criteria>
	<!-- 98a3967afd5a9038f6414265e6788e61 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062814" comment="btrfs-kmp-default less than 0_2.6.32.19_0.3-0.3.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062815" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.3-7.3.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062836" comment="ext4dev-kmp-ppc64 less than 0_2.6.32.19_0.3-7.3.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062816" comment="kernel-default-base less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062817" comment="kernel-default-devel less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062818" comment="kernel-default less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062837" comment="kernel-ppc64-base less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062838" comment="kernel-ppc64-devel less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062839" comment="kernel-ppc64 less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062819" comment="kernel-source less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062820" comment="kernel-syms less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062821" comment="kernel-trace-base less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062822" comment="kernel-trace-devel less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062823" comment="kernel-trace less than 2.6.32.19-0.3.1"/>
		</criteria>
	</criteria>
	<!-- a26754073e422d7b7d2bdf784e6e85c7 -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009032105" comment="sles11-extra is installed"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009063853" comment="kernel-default-extra less than 2.6.27.54-0.2.1"/>
	</criteria>
	<!-- ac1a621e10ddcf3b61b268fe8c24c08f -->
	<criteria operator="AND">
		<criterion test_ref="oval:org.opensuse.security:tst:2009060800" comment="sles11-sp1 is installed"/>
		<criteria operator="OR">
			<criterion test_ref="oval:org.opensuse.security:tst:2009062814" comment="btrfs-kmp-default less than 0_2.6.32.19_0.3-0.3.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062815" comment="ext4dev-kmp-default less than 0_2.6.32.19_0.3-7.3.16"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062840" comment="iscsitarget-kmp-default less than 1.4.19_2.6.32.19_0.3-0.7.8"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062816" comment="kernel-default-base less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062817" comment="kernel-default-devel less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062841" comment="kernel-default-man less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062818" comment="kernel-default less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062819" comment="kernel-source less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062820" comment="kernel-syms less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval:org.opensuse.security:tst:2009062821" comment="kernel-trace-base less than 2.6.32.19-0.3.1"/>
			<criterion test_ref="oval
