<?xml version='1.0' encoding='UTF-8'?>
<oval_definitions xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5' xmlns:unix-def='http://oval.mitre.org/XMLSchema/oval-definitions-5#unix' xmlns:ind-def ='http://oval.mitre.org/XMLSchema/oval-definitions-5#independent' xmlns:oval='http://oval.mitre.org/XMLSchema/oval-common-5' xmlns:oval-def='http://oval.mitre.org/XMLSchema/oval-definitions-5' xmlns:xsi='http://www.w3.org/2001/XMLSchema-instance' xsi:schemaLocation='http://oval.mitre.org/XMLSchema/oval-definitions-5#independent independent-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd' xmlns:linux-def='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux'>
  <generator>
    <oval:product_name>Debian</oval:product_name>
    <oval:schema_version>5.3</oval:schema_version>
    <oval:timestamp>2008-11-19T19:32:38.188-04:00</oval:timestamp>
  </generator>
  <definitions>
    <definition version='1' id='oval:org.debian:def:96' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>mutt</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0001' ref_id='CVE-2002-0001'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-01-03</date>
          <moreinfo>
          </moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='mutt DPKG is earlier than 1.2.5-5' test_ref='oval:org.debian.oval:tst:2'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:97' class='vulnerability'>
      <metadata>
        <title>Uncontrolled program execution</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>exim</product>
        </affected>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-01-03</date>
          <moreinfo>
Patrice Fournier discovered a bug in all versions of Exim older than
Exim 3.34 and Exim 3.952.
The Exim maintainer, Philip Hazel,
&lt;a href="http://www.exim.org/pipermail/exim-announce/2001q4/000048.html">\
writes&lt;/a> about this issue: "The
problem exists only in the case of a run time configuration which
directs or routes an address to a pipe transport without checking the
local part of the address in any way.  This does not apply, for
example, to pipes run from alias or forward files, because the local
part is checked to ensure that it is the name of an alias or of a
local user.  The bug's effect is that, instead of obeying the correct
pipe command, a broken Exim runs the command encoded in the local part
of the address."
This problem has been fixed in Exim version 3.12-10.2 for the stable
distribution Debian GNU/Linux 2.2 and 3.33-1.1 for the testing and
unstable distribution.  We recommend that you upgrade your exim
package.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='eximon DPKG is earlier than 3.12-10.2' test_ref='oval:org.debian.oval:tst:3'/>
            <criterion comment='exim DPKG is earlier than 3.12-10.2' test_ref='oval:org.debian.oval:tst:4'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:98' class='vulnerability'>
      <metadata>
        <title>format string vulnerability and buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>libgtop</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0927' ref_id='CVE-2001-0927'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0928' ref_id='CVE-2001-0928'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-01-09</date>
          <moreinfo>
Two different problems where found in libgtop-daemon:
Since libgtop_daemon runs as user nobody both bugs could be used
to gain access as the nobody user to a system running libgtop_daemon.
Both problems have been fixed in version 1.0.6-1.1 and we recommend
you upgrade your libgtop-daemon package immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libgtop-dev DPKG is earlier than 1.0.6-1.1' test_ref='oval:org.debian.oval:tst:5'/>
            <criterion comment='libgtop1 DPKG is earlier than 1.0.6-1.1' test_ref='oval:org.debian.oval:tst:6'/>
            <criterion comment='libgtop-daemon DPKG is earlier than 1.0.6-1.1' test_ref='oval:org.debian.oval:tst:7'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:99' class='vulnerability'>
      <metadata>
        <title>IRC session hijacking</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>XChat</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0006' ref_id='CVE-2002-0006'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-01-12</date>
          <moreinfo>
zen-parse found a &lt;a href="http://online.securityfocus.com/archive/1/249113">\
vulnerability&lt;/a> in the XChat IRC client that allows an
attacker to take over the users IRC session.
It is possible to trick XChat IRC clients into sending arbitrary
commands to the IRC server they are on, potentially allowing social
engineering attacks, channel takeovers, and denial of service.  This
problem exists in versions 1.4.2 and 1.4.3.  Later versions of XChat
are vulnerable as well, but this behaviour is controlled by the
configuration variable ťpercasciiŤ, which defaults to 0.  If it is set
to 1 then the problem becomes apparent in 1.6/1.8 as well.
This problem has been fixed in upstream version 1.8.7 and in version
1.4.3-1 for the current stable Debian release (2.2) with a patch
provided from the upstream author Peter Zelezny.  We recommend that
you upgrade your XChat packages immediately, since this problem is
already actively being exploited.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='xchat-common DPKG is earlier than 1.4.3-1' test_ref='oval:org.debian.oval:tst:9'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='xchat-gnome DPKG is earlier than 1.4.3-1' test_ref='oval:org.debian.oval:tst:10'/>
            <criterion comment='xchat-text DPKG is earlier than 1.4.3-1' test_ref='oval:org.debian.oval:tst:11'/>
            <criterion comment='xchat DPKG is earlier than 1.4.3-1' test_ref='oval:org.debian.oval:tst:12'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:100' class='vulnerability'>
      <metadata>
        <title>Potential buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>gzip</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1228' ref_id='CVE-2001-1228'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-01-13</date>
          <moreinfo>
GOBBLES found a buffer overflow in gzip that occurs when compressing
files with really long filenames.  Even though GOBBLES claims to have
developed an exploit to take advantage of this bug, it has been said
by others that this &lt;a href="http://online.securityfocus.com/bid/3712">\
problem&lt;/a> is not likely to be exploitable as other
security incidents.
Additionally, the Debian version of gzip from the stable release does
not segfault, and hence does not directly inherit this problem.
However, better be safe than sorry, so we have prepared an update for
you.
Please make sure you are running an up-to-date version from
stable/unstable/testing with at least version 1.2.4-33.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='gzip DPKG is earlier than 1.2.4-33.1' test_ref='oval:org.debian.oval:tst:13'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:101' class='vulnerability'>
      <metadata>
        <title>Local root exploit</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>sudo</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0043' ref_id='CVE-2002-0043'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-01-14</date>
          <moreinfo>
Sebastian Krahmer from SuSE found a vulnerability in &lt;code>sudo&lt;/code> which could
easily lead into a local root exploit.
This problem has been fixed in upstream version 1.6.4 as well as in
version 1.6.2p2-2.1 for the stable release of Debian GNU/Linux.
We recommend that you upgrade your sudo packages immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='sudo DPKG is earlier than 1.6.2p2-2.1' test_ref='oval:org.debian.oval:tst:14'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:102' class='vulnerability'>
      <metadata>
        <title>daemon exploit</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>at</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0004' ref_id='CVE-2002-0004'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-01-16</date>
          <moreinfo>
zen-parse found a bug in the current implementation of at which leads
into a heap corruption vulnerability which in turn could potentially
lead into an exploit of the daemon user.
We recommend that you upgrade your at packages.
Unfortunately, the bugfix from DSA 102-1 wasn't propagated properly due
to a packaging bug.  While the file parsetime.y was fixed, and yy.tab.c
should be generated from it, yy.tab.c from the original source was still
used.  This has been fixed in DSA-102-2.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='at DPKG is earlier than 3.1.8-10.2' test_ref='oval:org.debian.oval:tst:15'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:103' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>glibc</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0886' ref_id='CVE-2001-0886'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-01-13</date>
          <moreinfo>
A buffer overflow has been found in the globbing code for glibc.
This is the code which is used to glob patterns for filenames and is
commonly used in applications like shells and FTP servers.
This has been fixed in version 2.1.3-20 and we recommend that
you upgrade your libc package immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='glibc-doc DPKG is earlier than 2.1.3-20' test_ref='oval:org.debian.oval:tst:16'/>
              <criterion comment='i18ndata DPKG is earlier than 2.1.3-20' test_ref='oval:org.debian.oval:tst:17'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:19'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:20'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:21'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:22'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='nscd DPKG is earlier than 2.1.3-20' test_ref='oval:org.debian.oval:tst:23'/>
              <criterion comment='libc6-dev DPKG is earlier than 2.1.3-20' test_ref='oval:org.debian.oval:tst:24'/>
              <criterion comment='libc6-pic DPKG is earlier than 2.1.3-20' test_ref='oval:org.debian.oval:tst:25'/>
              <criterion comment='libc6 DPKG is earlier than 2.1.3-20' test_ref='oval:org.debian.oval:tst:26'/>
              <criterion comment='libc6-prof DPKG is earlier than 2.1.3-20' test_ref='oval:org.debian.oval:tst:27'/>
              <criterion comment='libc6-dbg DPKG is earlier than 2.1.3-20' test_ref='oval:org.debian.oval:tst:28'/>
              <criterion comment='locales DPKG is earlier than 2.1.3-20' test_ref='oval:org.debian.oval:tst:29'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:30'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libc6.1-pic DPKG is earlier than 2.1.3-20' test_ref='oval:org.debian.oval:tst:31'/>
              <criterion comment='libc6.1-dev DPKG is earlier than 2.1.3-20' test_ref='oval:org.debian.oval:tst:32'/>
              <criterion comment='libc6.1-dbg DPKG is earlier than 2.1.3-20' test_ref='oval:org.debian.oval:tst:33'/>
              <criterion comment='libnss1-compat DPKG is earlier than 2.1.3-20' test_ref='oval:org.debian.oval:tst:34'/>
              <criterion comment='libc6.1-prof DPKG is earlier than 2.1.3-20' test_ref='oval:org.debian.oval:tst:35'/>
              <criterion comment='libc6.1 DPKG is earlier than 2.1.3-20' test_ref='oval:org.debian.oval:tst:36'/>
              <criterion comment='nscd DPKG is earlier than 2.1.3-20' test_ref='oval:org.debian.oval:tst:37'/>
              <criterion comment='locales DPKG is earlier than 2.1.3-20' test_ref='oval:org.debian.oval:tst:38'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported platform section' operator='AND'>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:19'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='libnss1-compat DPKG is earlier than 2.1.3-20' test_ref='oval:org.debian.oval:tst:40'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:104' class='vulnerability'>
      <metadata>
        <title>DoS attack</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>cipe</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0047' ref_id='CVE-2002-0047'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-01-14</date>
          <moreinfo>
Larry McVoy found a bug in the packet handling code for the CIPE
VPN package: it did not check if a received packet was too short 
and could crash.
This has been fixed in version 1.3.0-3, and we recommend that you
upgrade your CIPE packages immediately.
Please note that the package only contains the required kernel patch,
you will have to manually build the kernel modules for your kernel with the
updated source from the &lt;code>cipe-source&lt;/code> package.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='cipe-source DPKG is earlier than 1.3.0-3' test_ref='oval:org.debian.oval:tst:41'/>
              <criterion comment='cipe-common DPKG is earlier than 1.3.0-3' test_ref='oval:org.debian.oval:tst:42'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:105' class='vulnerability'>
      <metadata>
        <title>insecure temporary files</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>enscript</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0044' ref_id='CVE-2002-0044'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-01-21</date>
          <moreinfo>
The version of enscript (a tool to convert ASCII text to different
formats) in potato has been found to create temporary files insecurely.
This has been fixed in version 1.6.2-4.1.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='enscript DPKG is earlier than 1.6.2-4.1' test_ref='oval:org.debian.oval:tst:43'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:106' class='vulnerability'>
      <metadata>
        <title>remote exploit</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>rsync</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0048' ref_id='CVE-2002-0048'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-01-26</date>
          <moreinfo>
This has been fixed in version 2.3.2-1.3 and we recommend you upgrade
your rsync package immediately.
Unfortunately the patch used to fix that problem broke rsync.
This has been fixed in version 2.3.2-1.5 and we recommend you
upgrade to that version immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='rsync DPKG is earlier than 2.3.2-1.5' test_ref='oval:org.debian.oval:tst:44'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:107' class='vulnerability'>
      <metadata>
        <title>format print vulnerability</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>jgroff</product>
        </affected>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-01-30</date>
          <moreinfo>
          </moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='jgroff DPKG is earlier than 1.15+ja-3.4' test_ref='oval:org.debian.oval:tst:45'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:108' class='vulnerability'>
      <metadata>
        <title>symlink vulnerability</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>wmtv</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0247' ref_id='CVE-2002-0247'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0248' ref_id='CVE-2002-0248'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-02-07</date>
          <moreinfo>
Nicolas Boullis found some security problems in the wmtv package (a
dockable video4linux TV player for windowmaker) which is distributed
in Debian GNU/Linux 2.2.  With the current version of wmtv, the
configuration file is written back as the superuser, and without any
further checks.  A malicious user might use that to damage important
files.
This problem has been fixed in version 0.6.5-2potato2 for the stable
distribution by dropping privileges as soon as possible and only
regaining them where required.  In the current testing/unstable
distribution this problem has been fixed in version 0.6.5-9 and above
by not requiring privileges anymore.  Both contain fixes for two
potential buffer overflows as well.
We recommend that you upgrade your wmtv packages immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='wmtv DPKG is earlier than 0.6.5-2potato2' test_ref='oval:org.debian.oval:tst:46'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:109' class='vulnerability'>
      <metadata>
        <title>cross-site scripting vulnerability</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>faqomatic</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0230' ref_id='CVE-2002-0230'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-02-13</date>
          <moreinfo>
Due to unescaped HTML code Faq-O-Matic returned unverified scripting
code to the browser.  With some tweaking this enables an attacker to
steal cookies from one of the Faq-O-Matic moderators or the admin.
Cross-Site Scripting is a type of problem that allows a malicious
person to make another person run some JavaScript in their browser.
The JavaScript is executed on the victims machine and is in the
context of the website running the Faq-O-Matic Frequently Asked
Question manager.
This problem has been fixed in version 2.603-1.2 for the stable Debian
distribution and version 2.712-2 for the current testing/unstable
distribution.
We recommend that you upgrade your faqomatic package if you have it
installed.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='faqomatic DPKG is earlier than 2.603-1.2' test_ref='oval:org.debian.oval:tst:47'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:110' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>cupsys</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0063' ref_id='CVE-2002-0063'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-02-13</date>
          <moreinfo>
The authors of CUPS, the Common UNIX Printing System, have found a
potential buffer overflow bug in the code of the CUPS daemon where it
reads the names of attributes.  This affects all versions of CUPS.
This problem has been fixed in version 1.0.4-10 for the stable Debian
distribution and version 1.1.13-2 for the current testing/unstable
distribution.
We recommend that you upgrade your CUPS packages immediately if you
have them installed.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libcupsys1 DPKG is earlier than 1.0.4-10' test_ref='oval:org.debian.oval:tst:48'/>
            <criterion comment='libcupsys1-dev DPKG is earlier than 1.0.4-10' test_ref='oval:org.debian.oval:tst:49'/>
            <criterion comment='cupsys DPKG is earlier than 1.0.4-10' test_ref='oval:org.debian.oval:tst:50'/>
            <criterion comment='cupsys-bsd DPKG is earlier than 1.0.4-10' test_ref='oval:org.debian.oval:tst:51'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:111' class='vulnerability'>
      <metadata>
        <title>remote exploit</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>ucd-snmp</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-012' ref_id='CVE-2002-012'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-013' ref_id='CVE-2002-013'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-02-14</date>
          <moreinfo>
The Secure Programming Group of the Oulu University did a study on
SNMP implementations and uncovered multiple problems which can
cause problems ranging from Denial of Service attacks to remote
exploits.
New UCD-SNMP packages have been prepared to fix these problems
as well as a few others. The complete list of fixed problems is:
(thanks to Caldera for most of the work on those patches)
The new version is 4.1.1-2.1 and we recommend you upgrade your
snmp packages immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:30'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:21'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:22'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:19'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='snmp DPKG is earlier than 4.1.1-2.2' test_ref='oval:org.debian.oval:tst:52'/>
              <criterion comment='libsnmp4.1 DPKG is earlier than 4.1.1-2.2' test_ref='oval:org.debian.oval:tst:53'/>
              <criterion comment='libsnmp4.1-dev DPKG is earlier than 4.1.1-2.2' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='snmpd DPKG is earlier than 4.1.1-2.2' test_ref='oval:org.debian.oval:tst:55'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:112' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>hanterm</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0239' ref_id='CVE-2002-0239'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-02-16</date>
          <moreinfo>
A set of buffer overflow problems have been found in hanterm, a Hangul
terminal for X11 derived from xterm, that will read and display Korean
characters in its terminal window.  The font handling code in hanterm
uses hard limited string variables but didn't check for boundaries.
This problem can be exploited by a malicious user to gain access to
the utmp group which is able to write the wtmp and utmp files.  These
files record login and logout activities.
This problem has been fixed in version 3.3.1p17-5.2 for the stable
Debian distribution.  A fixed package for the current testing/unstable
distribution is not yet available but will have a version number
higher than 3.3.1p18-6.1.
We recommend that you upgrade your hanterm packages immediately if you
have them installed.  Known exploits are already available.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='hanterm DPKG is earlier than 3.3.1p17-5.2' test_ref='oval:org.debian.oval:tst:56'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:113' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>ncurses</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0062' ref_id='CVE-2002-0062'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-02-18</date>
          <moreinfo>
Several buffer overflows were fixed in the "ncurses" library in November
2000.  Unfortunately, one was missed.  This can lead to crashes when using
ncurses applications in large windows.
The &lt;a href="http://cve.mitre.org/">Common Vulnerabilities and
Exposures project&lt;/a> has assigned the name
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0062">\
CAN-2002-0062&lt;/a> to this issue.
This problem has been fixed for the stable release of Debian in version
5.0-6.0potato2.  The testing and unstable releases contain ncurses 5.2,
which is not affected by this problem.
There are no known exploits for this problem, but we recommend that all
users upgrade ncurses immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='ncurses-term DPKG is earlier than 5.0-6.0potato2' test_ref='oval:org.debian.oval:tst:57'/>
              <criterion comment='ncurses-base DPKG is earlier than 5.0-6.0potato2' test_ref='oval:org.debian.oval:tst:58'/>
            </criteria>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libncurses5-dev DPKG is earlier than 5.0-6.0potato2' test_ref='oval:org.debian.oval:tst:59'/>
            <criterion comment='ncurses-bin DPKG is earlier than 5.0-6.0potato2' test_ref='oval:org.debian.oval:tst:60'/>
            <criterion comment='libncurses5-dbg DPKG is earlier than 5.0-6.0potato2' test_ref='oval:org.debian.oval:tst:61'/>
            <criterion comment='libncurses5 DPKG is earlier than 5.0-6.0potato2' test_ref='oval:org.debian.oval:tst:62'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:114' class='vulnerability'>
      <metadata>
        <title>unauthorized file access</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>gnujsp</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0300' ref_id='CVE-2002-0300'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-02-21</date>
          <moreinfo>
Thomas Springer found a vulnerability in GNUJSP, a Java servlet that
allows you to insert Java source code into HTML files.  The problem
can be used to bypass access restrictions in the web server.  An
attacker can view the contents of directories and download files
directly rather then receiving their HTML output.  This means that the
source code of scripts could also be revealed.
The problem was fixed by Stefan Gybas, who maintains the Debian
package of GNUJSP.  It is fixed in version 1.0.0-5 for the stable
release of Debian GNU/Linux.
The versions in testing and unstable are the same as the one in stable
so they are vulnerable, too.  You can install the fixed version this
advisory refers to on these systems to solve the problem as this
package is architecture independent.
We recommend that you upgrade your gnujsp package immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='gnujsp DPKG is earlier than 1.0.0-5' test_ref='oval:org.debian.oval:tst:63'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:115' class='vulnerability'>
      <metadata>
        <title>broken boundary check and more</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>php3, php4</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0081' ref_id='CVE-2002-0081'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-03-02</date>
          <moreinfo>
Stefan Esser, who is also a member of the PHP team, found several
&lt;a href="http://security.e-matters.de/advisories/012002.html">flaws&lt;/a>
in the way PHP handles multipart/form-data POST requests (as
described in RFC1867) known as POST fileuploads.  Each of the flaws
could allow an attacker to execute arbitrary code on the victim's
system.
For PHP3 flaws contain a broken boundary check and an arbitrary heap
overflow.  For PHP4 they consist of a broken boundary check and a heap
off by one error.
For the stable release of Debian these problems are fixed in version
3.0.18-0potato1.1 of PHP3 and version 4.0.3pl1-0potato3 of PHP4.
For the unstable and testing release of Debian these problems are
fixed in version 3.0.18-22 of PHP3 and version 4.1.2-1 of PHP4.
There is no PHP4 in the stable and unstable distribution for the arm
architecture due to a compiler error.
We recommend that you upgrade your PHP packages immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='php4-dev DPKG is earlier than 4.0.3pl1-0potato3' test_ref='oval:org.debian.oval:tst:64'/>
              <criterion comment='php3-doc DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:65'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:19'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:20'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:21'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:30'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='php4-cgi-mhash DPKG is earlier than 4.0.3pl1-0potato3' test_ref='oval:org.debian.oval:tst:66'/>
              <criterion comment='php3-cgi-snmp DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:67'/>
              <criterion comment='php4-cgi-pgsql DPKG is earlier than 4.0.3pl1-0potato3' test_ref='oval:org.debian.oval:tst:68'/>
              <criterion comment='php3-snmp DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:69'/>
              <criterion comment='php3-magick DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:70'/>
              <criterion comment='php4-cgi-ldap DPKG is earlier than 4.0.3pl1-0potato3' test_ref='oval:org.debian.oval:tst:71'/>
              <criterion comment='php4-mhash DPKG is earlier than 4.0.3pl1-0potato3' test_ref='oval:org.debian.oval:tst:72'/>
              <criterion comment='php3-cgi-pgsql DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:73'/>
              <criterion comment='php3-cgi-ldap DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:74'/>
              <criterion comment='php4-cgi-imap DPKG is earlier than 4.0.3pl1-0potato3' test_ref='oval:org.debian.oval:tst:75'/>
              <criterion comment='php3-dev DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:76'/>
              <criterion comment='php3-cgi DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:77'/>
              <criterion comment='php4-mysql DPKG is earlier than 4.0.3pl1-0potato3' test_ref='oval:org.debian.oval:tst:78'/>
              <criterion comment='php3-cgi-imap DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:79'/>
              <criterion comment='php4 DPKG is earlier than 4.0.3pl1-0potato3' test_ref='oval:org.debian.oval:tst:80'/>
              <criterion comment='php4-imap DPKG is earlier than 4.0.3pl1-0potato3' test_ref='oval:org.debian.oval:tst:81'/>
              <criterion comment='php4-cgi DPKG is earlier than 4.0.3pl1-0potato3' test_ref='oval:org.debian.oval:tst:82'/>
              <criterion comment='php3 DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:83'/>
              <criterion comment='php4-pgsql DPKG is earlier than 4.0.3pl1-0potato3' test_ref='oval:org.debian.oval:tst:84'/>
              <criterion comment='php3-mhash DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:85'/>
              <criterion comment='php4-snmp DPKG is earlier than 4.0.3pl1-0potato3' test_ref='oval:org.debian.oval:tst:86'/>
              <criterion comment='php3-pgsql DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:87'/>
              <criterion comment='php4-ldap DPKG is earlier than 4.0.3pl1-0potato3' test_ref='oval:org.debian.oval:tst:88'/>
              <criterion comment='php4-xml DPKG is earlier than 4.0.3pl1-0potato3' test_ref='oval:org.debian.oval:tst:89'/>
              <criterion comment='php3-cgi-xml DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:90'/>
              <criterion comment='php3-mysql DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:91'/>
              <criterion comment='php3-gd DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:92'/>
              <criterion comment='php3-xml DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:93'/>
              <criterion comment='php3-cgi-mhash DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:94'/>
              <criterion comment='php4-cgi-xml DPKG is earlier than 4.0.3pl1-0potato3' test_ref='oval:org.debian.oval:tst:95'/>
              <criterion comment='php3-cgi-magick DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:96'/>
              <criterion comment='php4-cgi-snmp DPKG is earlier than 4.0.3pl1-0potato3' test_ref='oval:org.debian.oval:tst:97'/>
              <criterion comment='php4-gd DPKG is earlier than 4.0.3pl1-0potato3' test_ref='oval:org.debian.oval:tst:98'/>
              <criterion comment='php4-cgi-gd DPKG is earlier than 4.0.3pl1-0potato3' test_ref='oval:org.debian.oval:tst:99'/>
              <criterion comment='php3-imap DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:100'/>
              <criterion comment='php3-ldap DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:101'/>
              <criterion comment='php3-cgi-gd DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:102'/>
              <criterion comment='php3-cgi-mysql DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:103'/>
              <criterion comment='php4-cgi-mysql DPKG is earlier than 4.0.3pl1-0potato3' test_ref='oval:org.debian.oval:tst:104'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:22'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='php3-dev DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:105'/>
              <criterion comment='php3-cgi-mhash DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:106'/>
              <criterion comment='php3-pgsql DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:107'/>
              <criterion comment='php3-cgi-snmp DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:108'/>
              <criterion comment='php3-cgi-magick DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:109'/>
              <criterion comment='php3-magick DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:110'/>
              <criterion comment='php3-mysql DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:111'/>
              <criterion comment='php3-cgi DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:112'/>
              <criterion comment='php3-snmp DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:113'/>
              <criterion comment='php3-cgi-xml DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:114'/>
              <criterion comment='php3-mhash DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:115'/>
              <criterion comment='php3-cgi-imap DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:116'/>
              <criterion comment='php3 DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:117'/>
              <criterion comment='php3-ldap DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:118'/>
              <criterion comment='php3-imap DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:119'/>
              <criterion comment='php3-cgi-gd DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:120'/>
              <criterion comment='php3-cgi-pgsql DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:121'/>
              <criterion comment='php3-cgi-mysql DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:122'/>
              <criterion comment='php3-gd DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:123'/>
              <criterion comment='php3-cgi-ldap DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:124'/>
              <criterion comment='php3-xml DPKG is earlier than 3.0.18-0potato1.1' test_ref='oval:org.debian.oval:tst:125'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:116' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>cfs</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0351' ref_id='CVE-2002-0351'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-03-02</date>
          <moreinfo>
Zorgon found several buffer overflows in cfsd, a daemon that pushes
encryption services into the Unix(tm) file system.  We are not yet
sure if these overflows can successfully be exploited to gain root
access to the machine running the CFS daemon.  However, since cfsd can
easily be forced to die, a malicious user can easily perform a denial
of service attack to it.
This problem has been fixed in version 1.3.3-8.1 for the stable Debian
distribution and in version 1.4.1-5 for the testing and unstable
distribution of Debian.
We recommend that you upgrade your cfs package immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='cfs DPKG is earlier than 1.3.3-8.1' test_ref='oval:org.debian.oval:tst:126'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:117' class='vulnerability'>
      <metadata>
        <title>improper variable initialization</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>cvs</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0092' ref_id='CVE-2002-0092'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-03-05</date>
          <moreinfo>
Kim Nielsen recently found an internal problem with the CVS server and
reported it to the vuln-dev mailing list.  The problem is triggered by
an improperly initialized global variable.  A user exploiting this can
crash the CVS server, which may be accessed through the pserver
service and running under a remote user id.  It is not yet clear if
the remote account can be exposed, though.
This problem has been fixed in version 1.10.7-9 for the stable Debian
distribution with help of Niels Heinen and in versions newer
than 1.11.1p1debian-3 for the
testing and unstable distribution of Debian (not yet uploaded,
though).
We recommend that you upgrade your CVS package.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='cvs-doc DPKG is earlier than 1.10.7-9' test_ref='oval:org.debian.oval:tst:127'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='cvs DPKG is earlier than 1.10.7-9' test_ref='oval:org.debian.oval:tst:128'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:118' class='vulnerability'>
      <metadata>
        <title>insecure temporary files</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>xsane</product>
        </affected>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-03-05</date>
          <moreinfo>
Tim Waugh found several insecure uses of temporary files in the xsane
program, which is used for scanning.  This was fixed for Debian/stable
by moving those files into a securely created directory within the
/tmp directory.
This problem has been fixed in version 0.50-5.1 for the stable Debian
distribution and in version 0.84-0.1 for the testing and unstable
distribution of Debian.
We recommend that you upgrade your xsane package.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='xsane DPKG is earlier than 0.50-5.1' test_ref='oval:org.debian.oval:tst:129'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:120' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>libapache-mod-ssl, apache-ssl</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0082' ref_id='CVE-2002-0082'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-03-10</date>
          <moreinfo>
Ed Moyle recently
&lt;a href="http://archives.neohapsis.com/archives/bugtraq/2002-02/0313.html">\
found&lt;/a> a buffer overflow in Apache-SSL and mod_ssl.
With session caching enabled, mod_ssl will serialize SSL session
variables to store them for later use.  These variables were stored in
a buffer of a fixed size without proper boundary checks.
To exploit the overflow, the server must be configured to require client
certificates, and an attacker must obtain a carefully crafted client
certificate that has been signed by a Certificate Authority which is
trusted by the server. If these conditions are met, it would be possible
for an attacker to execute arbitrary code on the server.
This problem has been fixed in version 1.3.9.13-4 of Apache-SSL and
version 2.4.10-1.3.9-1potato1 of libapache-mod-ssl for the stable
Debian distribution as well as in version 1.3.23.1+1.47-1 of
Apache-SSL and version 2.8.7-1 of libapache-mod-ssl for the testing
and unstable distribution of Debian.
We recommend that you upgrade your Apache-SSL and mod_ssl packages.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='libapache-mod-ssl-doc DPKG is earlier than 2.4.10-1.3.9-1potato1' test_ref='oval:org.debian.oval:tst:130'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libapache-mod-ssl DPKG is earlier than 2.4.10-1.3.9-1potato1' test_ref='oval:org.debian.oval:tst:131'/>
            <criterion comment='apache-ssl DPKG is earlier than 1.3.9.13-4' test_ref='oval:org.debian.oval:tst:132'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:121' class='vulnerability'>
      <metadata>
        <title>buffer overflow, symlink problem, ".." directory traversal</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>xtell</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0332' ref_id='CVE-2002-0332'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0333' ref_id='CVE-2002-0333'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0334' ref_id='CVE-2002-0334'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-03-11</date>
          <moreinfo>
Several security related problems have been found in the xtell
package, a simple messaging client and server.  In detail, these
problems contain several buffer overflows, a problem in connection
with symbolic links, unauthorized directory traversal when the path
contains "..".  These problems could lead into an attacker being able
to execute arbitrary code on the server machine.  The server runs with
nobody privileges by default, so this would be the account to be
exploited.
They have been corrected by backporting changes from a newer upstream
version by the Debian maintainer for xtell.  These problems are fixed
in version 1.91.1 in the stable distribution of Debian and in version
2.7 for the testing and unstable distribution of Debian.
We recommend that you upgrade your xtell packages immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='xtell DPKG is earlier than 1.91.1' test_ref='oval:org.debian.oval:tst:133'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:122' class='vulnerability'>
      <metadata>
        <title>malloc error (double free)</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>zlib</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0059' ref_id='CVE-2002-0059'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-03-11</date>
          <moreinfo>
The compression library zlib has a flaw in which it attempts to free
memory more than once under certain conditions. This can possibly be
exploited to run arbitrary code in a program that includes zlib. If a
network application running as root is linked to zlib, this could
potentially lead to a remote root compromise. No exploits are known at
this time. This vulnerability is assigned the CVE candidate name of
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0059">CAN-2002-0059&lt;/a>.
The zlib vulnerability is fixed in the Debian zlib package version
1.1.3-5.1. A number of programs either link statically to zlib or include
a private copy of zlib code. These programs must also be upgraded
to eliminate the zlib vulnerability. The affected packages and fixed
versions follow:
Those using the pre-release (testing) version of Debian should upgrade
to zlib 1.1.3-19.1 or a later version. Note that since this version of
Debian has not yet been released it may not be available immediately for
all architectures. Debian 2.2 (potato) is the latest supported release.
We recommend that you upgrade your packages immediately. Note that you
should restart all programs that use the shared zlib library in order
for the fix to take effect. This is most easily done by rebooting the
system.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='erlang-java DPKG is earlier than 49.1-10.1' test_ref='oval:org.debian.oval:tst:134'/>
              <criterion comment='erlang-base DPKG is earlier than 49.1-10.1' test_ref='oval:org.debian.oval:tst:135'/>
              <criterion comment='freeamp-doc DPKG is earlier than 2.0.6-2.1' test_ref='oval:org.debian.oval:tst:136'/>
              <criterion comment='erlang-erl DPKG is earlier than 49.1-10.1' test_ref='oval:org.debian.oval:tst:137'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:20'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:21'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:30'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:22'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='rsync DPKG is earlier than 2.3.2-1.6' test_ref='oval:org.debian.oval:tst:138'/>
              <criterion comment='zlib-bin DPKG is earlier than 1.1.3-5.1' test_ref='oval:org.debian.oval:tst:139'/>
              <criterion comment='amaya DPKG is earlier than 2.4-1potato1' test_ref='oval:org.debian.oval:tst:140'/>
              <criterion comment='dictd DPKG is earlier than 1.4.9-9potato1' test_ref='oval:org.debian.oval:tst:141'/>
              <criterion comment='ppp DPKG is earlier than 2.3.11-1.5' test_ref='oval:org.debian.oval:tst:142'/>
              <criterion comment='dict DPKG is earlier than 1.4.9-9potato1' test_ref='oval:org.debian.oval:tst:143'/>
              <criterion comment='zlib1g DPKG is earlier than 1.1.3-5.1' test_ref='oval:org.debian.oval:tst:144'/>
              <criterion comment='vrweb DPKG is earlier than 1.5-5.1' test_ref='oval:org.debian.oval:tst:145'/>
              <criterion comment='zlib1g-dev DPKG is earlier than 1.1.3-5.1' test_ref='oval:org.debian.oval:tst:146'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:21'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='freeamp DPKG is earlier than 2.0.6-2.1' test_ref='oval:org.debian.oval:tst:147'/>
              <criterion comment='libfreeamp-esound DPKG is earlier than 2.0.6-2.1' test_ref='oval:org.debian.oval:tst:148'/>
              <criterion comment='libfreeamp-alsa DPKG is earlier than 2.0.6-2.1' test_ref='oval:org.debian.oval:tst:149'/>
              <criterion comment='zlib1-altdev DPKG is earlier than 1.1.3-5.1' test_ref='oval:org.debian.oval:tst:150'/>
              <criterion comment='zlib1 DPKG is earlier than 1.1.3-5.1' test_ref='oval:org.debian.oval:tst:151'/>
              <criterion comment='erlang DPKG is earlier than 49.1-10.1' test_ref='oval:org.debian.oval:tst:152'/>
              <criterion comment='mirrordir DPKG is earlier than 0.10.48-2.1' test_ref='oval:org.debian.oval:tst:153'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported platform section' operator='AND'>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:20'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='libfreeamp-alsa DPKG is earlier than 2.0.6-2.1' test_ref='oval:org.debian.oval:tst:170'/>
                <criterion comment='erlang DPKG is earlier than 49.1-10.1' test_ref='oval:org.debian.oval:tst:171'/>
                <criterion comment='libfreeamp-esound DPKG is earlier than 2.0.6-2.1' test_ref='oval:org.debian.oval:tst:172'/>
                <criterion comment='freeamp DPKG is earlier than 2.0.6-2.1' test_ref='oval:org.debian.oval:tst:173'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:123' class='vulnerability'>
      <metadata>
        <title>remote exploit</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>listar</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0467' ref_id='CVE-2002-0467'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-03-19</date>
          <moreinfo>
Janusz Niewiadomski and Wojciech Purczynski reported a buffer overflow
in the address_match of listar (a listserv style mailing-list manager).
This has been fixed in version 0.129a-2.potato1.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='listar-cgi DPKG is earlier than 0.129a-2.potato1' test_ref='oval:org.debian.oval:tst:174'/>
            <criterion comment='listar DPKG is earlier than 0.129a-2.potato1' test_ref='oval:org.debian.oval:tst:175'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:124' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>mtr</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0497' ref_id='CVE-2002-0497'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-03-26</date>
          <moreinfo>
The authors of mtr released a new upstream version, noting a
non-exploitable buffer overflow in their ChangeLog.  Przemyslaw
Frasunek, however, found an &lt;a href="http://bugs.debian.org/137102">\
easy way&lt;/a> to exploit this bug, which allows
an attacker to gain access to the raw socket, which makes IP spoofing
and other malicious network activity possible.
The problem has been fixed by the Debian maintainer in version 0.41-6
for the stable distribution of Debian by backporting the upstream fix
and in version 0.48-1 for the testing/unstable distribution.
We recommend that you upgrade your mtr package immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='mtr DPKG is earlier than 0.41-6' test_ref='oval:org.debian.oval:tst:176'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:125' class='vulnerability'>
      <metadata>
        <title>cross-site scripting </title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>analog</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0166' ref_id='CVE-2002-0166'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-03-28</date>
          <moreinfo>
Yuji Takahashi discovered a bug in analog which allows a cross-site
scripting type attack.  It is easy for an attacker to insert arbitrary
strings into any web server logfile.  If these strings are then
analysed by analog, they can appear in the report.  By this means an
attacker can introduce arbitrary Javascript code, for example, into an
analog report produced by someone else and read by a third person.
Analog already attempted to encode unsafe characters to avoid this
type of attack, but the conversion was incomplete.
This problem has been fixed in the upstream version 5.22 of analog.
Unfortunately patching the old version of analog in the stable
distribution of Debian instead is a very large job that defeats us.
We recommend that you upgrade your analog package immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='analog DPKG is earlier than 5.22-0potato1' test_ref='oval:org.debian.oval:tst:177'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:126' class='vulnerability'>
      <metadata>
        <title>cross-site scripting</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>imp</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0181' ref_id='CVE-2002-0181'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-04-16</date>
          <moreinfo>
A cross-site scripting (CSS) problem was discovered in Horde and IMP (a web
based IMAP mail package). This was fixed upstream in Horde version 1.2.8
and IMP version 2.2.8. The relevant patches have been back-ported to 
version 1.2.6-0.potato.5 of the horde package and version 2.2.6-0.potato.5
of the imp package.
This release also fixes a bug introduced by the PHP security fix from 
&lt;a href="dsa-115">DSA-115-1&lt;/a>: Postgres support for PHP was changed
in a subtle way which broke the Postgres support from IMP.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='imp DPKG is earlier than 2.2.6-0.potato.5' test_ref='oval:org.debian.oval:tst:178'/>
              <criterion comment='horde DPKG is earlier than 1.2.6-0.potato.5' test_ref='oval:org.debian.oval:tst:179'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:127' class='vulnerability'>
      <metadata>
        <title>remote buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>xpilot</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0179' ref_id='CVE-2002-0179'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-04-17</date>
          <moreinfo>
An internal audit by the xpilot (a multi-player tactical manoeuvring
game for X) maintainers revealed a buffer overflow in xpilot server.
This overflow can be abused by remote attackers to gain access to
the server under which the xpilot server is running.
This has been fixed in upstream version 4.5.1 and version
4.1.0-4.U.4alpha2.4.potato1 of the Debian package.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='xpilot DPKG is earlier than 4.1.0-4.U.4alpha2.4.potato1' test_ref='oval:org.debian.oval:tst:180'/>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:21'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:19'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:20'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:30'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='xpilot-client-nas DPKG is earlier than 4.1.0-4.U.4alpha2.4.potato1' test_ref='oval:org.debian.oval:tst:181'/>
              <criterion comment='xpilot-client-rplay DPKG is earlier than 4.1.0-4.U.4alpha2.4.potato1' test_ref='oval:org.debian.oval:tst:182'/>
              <criterion comment='xpilot-client-nosound DPKG is earlier than 4.1.0-4.U.4alpha2.4.potato1' test_ref='oval:org.debian.oval:tst:183'/>
              <criterion comment='xpilot-server DPKG is earlier than 4.1.0-4.U.4alpha2.4.potato1' test_ref='oval:org.debian.oval:tst:184'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:128' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>sudo</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0184' ref_id='CVE-2002-0184'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-04-26</date>
          <moreinfo>
fc found a buffer overflow in the variable expansion code
used by sudo for its prompt. Since sudo is necessarily installed suid
root a local user can use this to gain root access.
This has been fixed in version 1.6.2-2.2 for the stable distribution
of Debian and version 1.6.6-1 for the testing/unstable distribution.
We recommend that you upgrade your sudo package immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='sudo DPKG is earlier than 1.6.2p2-2.2' test_ref='oval:org.debian.oval:tst:185'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:129' class='vulnerability'>
      <metadata>
        <title>remote denial of service</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>uucp</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0912' ref_id='CVE-2002-0912'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-05-27</date>
          <moreinfo>
We have received reports that in.uucpd, an authentication agent in the
uucp package, does not properly terminate certain long input strings.
This has been corrected in uucp package version 1.06.1-11potato3 for
Debian 2.2 (potato) and in version 1.06.1-18 for the upcoming (woody)
release.
We recommend you upgrade your uucp package immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='uucp DPKG is earlier than 1.06.1-11potato3' test_ref='oval:org.debian.oval:tst:186'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:130' class='vulnerability'>
      <metadata>
        <title>remotely triggered memory allocation error</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>ethereal</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0353' ref_id='CVE-2002-0353'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0401' ref_id='CVE-2002-0401'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0402' ref_id='CVE-2002-0402'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0403' ref_id='CVE-2002-0403'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0404' ref_id='CVE-2002-0404'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-06-01</date>
          <moreinfo>
Ethereal versions prior to 0.9.3 were vulnerable to an allocation error
in the ASN.1 parser. This can be triggered when analyzing traffic using
the SNMP, LDAP, COPS, or Kerberos protocols in ethereal. This
vulnerability was announced in the ethereal security advisory
&lt;a href="http://www.ethereal.com/appnotes/enpa-sa-00003.html">enpa-sa-00003&lt;/a>.
This issue has been corrected in ethereal version 0.8.0-3potato for
Debian 2.2 (potato).
Additionally, a number of vulnerabilities were discussed in ethereal
security advisory
&lt;a href="http://www.ethereal.com/appnotes/enpa-sa-00004.html">enpa-sa-00004&lt;/a>;
the version of ethereal in Debian 2.2
(potato) is not vulnerable to the issues raised in this later advisory.
Users of the not-yet-released woody distribution should ensure that they
are running ethereal 0.9.4-1 or a later version.
We recommend you upgrade your ethereal package immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='ethereal DPKG is earlier than 0.8.0-3potato' test_ref='oval:org.debian.oval:tst:187'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:131' class='vulnerability'>
      <metadata>
        <title>remote DoS / exploit</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>apache</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0392' ref_id='CVE-2002-0392'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-06-19</date>
          <moreinfo>
Mark Litchfield found a denial of service attack in the Apache
web-server. While investigating the problem the Apache Software
Foundation discovered that the code for handling invalid requests which
use chunked encoding also might allow arbitrary code execution on 64
bit architectures.
This has been fixed in version 1.3.9-14.1 of the Debian apache package,
as well as upstream versions 1.3.26 and 2.0.37. We strongly recommend
that you upgrade your apache package immediately.
The package upgrade does not restart the apache server automatically,
this will have to be done manually. Please make sure your
configuration is correct ("&lt;kbd>apachectl configtest&lt;/kbd>" will verify that for
you) and restart it using "&lt;kbd>/etc/init.d/apache restart&lt;/kbd>"</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='apache-doc DPKG is earlier than 1.3.9-14.1' test_ref='oval:org.debian.oval:tst:188'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='apache DPKG is earlier than 1.3.9-14.1' test_ref='oval:org.debian.oval:tst:189'/>
            <criterion comment='apache-common DPKG is earlier than 1.3.9-14.1' test_ref='oval:org.debian.oval:tst:190'/>
            <criterion comment='apache-dev DPKG is earlier than 1.3.9-14.1' test_ref='oval:org.debian.oval:tst:191'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:132' class='vulnerability'>
      <metadata>
        <title>remote DoS / exploit</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>apache-ssl</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0392' ref_id='CVE-2002-0392'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-06-19</date>
          <moreinfo>
Mark Litchfield found a denial of service attack in the Apache
web-server. While investigating the problem the Apache Software
Foundation discovered that the code for handling invalid requests which
use chunked encoding also might allow arbitrary code execution on 64 bit
architectures.
This has been fixed in version 1.3.9.13-4.1 of the Debian apache-ssl
package and we recommend that you upgrade your apache-ssl package
immediately.
An update for the soon to be released Debian GNU/Linux 3.0/woody
distribution is not available at the moment.
More Information:
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0392">CVE-2002-0392&lt;/a>,
&lt;a href="http://www.cert.org/advisories/CA-2002-17.html">VU#944335&lt;/a>.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='apache-ssl DPKG is earlier than 1.3.9.13-4.1' test_ref='oval:org.debian.oval:tst:192'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:133' class='vulnerability'>
      <metadata>
        <title>remote DoS / exploit</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>apache-perl</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0392' ref_id='CVE-2002-0392'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-06-20</date>
          <moreinfo>
Mark Litchfield found a denial of service attack in the Apache
web-server. While investigating the problem the Apache Software
Foundation discovered that the code for handling invalid requests which
use chunked encoding also might allow arbitrary code execution.
This has been fixed in version 1.3.9-14.1-1.21.20000309-1 of the Debian
apache-perl package and we recommend that you upgrade your apache-perl
package immediately.
An update for the soon to be released Debian GNU/Linux 3.0/woody
distribution will be available soon.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='apache-perl DPKG is earlier than 1.3.9-14.1-1.21.20000309-1' test_ref='oval:org.debian.oval:tst:193'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:134' class='vulnerability'>
      <metadata>
        <title>remote exploit</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>ssh</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0640' ref_id='CVE-2002-0640'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0639' ref_id='CVE-2002-0639'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-06-24</date>
          <moreinfo>
ISS X-Force released an advisory about an OpenSSH "Remote Challenge
Vulnerability". Unfortunately, the advisory was incorrect on some
points, leading to widespread confusion about the impact of this
vulnerability. No version of OpenSSH in Debian is affected by the
SKEY and BSD_AUTH authentication methods described in the ISS
advisory. However, Debian does include OpenSSH servers with the PAM
feature described as vulnerable in the later advisory by the OpenSSH
team. (This vulnerable feature is authentication using PAM via the
keyboard-interactive mechanism [kbdint].) This vulnerability affects
OpenSSH versions 2.3.1 through 3.3. No exploit is currently known for
the PAM/kbdint vulnerability, but the details are publicly known. All
of these vulnerabilities were corrected in OpenSSH 3.4.
In addition to the vulnerabilities fixes outlined above, our OpenSSH
packages version 3.3 and higher support the new privilege separation
feature from Niels Provos, which changes ssh to use a separate
non-privileged process to handle most of the work. Vulnerabilities in
the unprivileged parts of OpenSSH will lead to compromise of an
unprivileged account restricted to an empty chroot, rather than a
direct root compromise. Privilege separation should help to mitigate
the risks of any future OpenSSH compromise.
Debian 2.2 (potato) shipped with an ssh package based on OpenSSH
1.2.3, and is not vulnerable to the vulnerabilities covered by this
advisory. Users still running a version 1.2.3 ssh package do not have
an immediate need to upgrade to OpenSSH 3.4. Users who upgraded to the
OpenSSH version 3.3 packages released in previous iterations of
DSA-134 should upgrade to the new version 3.4 OpenSSH packages, as the
version 3.3 packages are vulnerable. We suggest that users running
OpenSSH 1.2.3 consider a move to OpenSSH 3.4 to take advantage of the
privilege separation feature. (Though, again, we have no specific
knowledge of any vulnerability in OpenSSH 1.2.3. Please carefully read
the caveats listed below before upgrading from OpenSSH 1.2.3.) We
recommend that any users running a back-ported version of OpenSSH
version 2.0 or higher on potato move to OpenSSH 3.4.
The current pre-release version of Debian (woody) includes an OpenSSH
version 3.0.2p1 package (ssh), which is vulnerable to the PAM/kbdint
problem described above. We recommend that users upgrade to OpenSSH
3.4 and enable privilege separation. Please carefully read the release
notes below before upgrading. Updated packages for ssh-krb5 (an
OpenSSH package supporting kerberos authentication) are currently
being developed. Users who cannot currently upgrade their OpenSSH
packages may work around the known vulnerabilities by disabling the
vulnerable features: make sure the following lines are uncommented and
present in /etc/ssh/sshd_config and restart ssh
There should be no other PAMAuthenticationViaKbdInt or
ChallengeResponseAuthentication entries in sshd_config.
That concludes the vulnerability section of this advisory. What
follows are release notes related to the OpenSSH 3.4 package and the
privilege separation feature. URLs for the OpenSSH 3.4 packages are at
the bottom.
Some notes on possible issues associated with this upgrade:
Some issues from previous OpenSSH 3.3p1 packages corrected in this
advisory (not a complete changelog):
Again, we regret having to release packages with larger changes and
less testing than is our usual practice; given the potential severity
and non-specific nature of the original threat we decided that our users were
best served by having packages available for evaluation as quickly as
possible. We will send additional information as it comes to us, and
will continue to work on the outstanding issues.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criterion comment='ssleay DPKG is earlier than 0.9.6c-0.potato.1' test_ref='oval:org.debian.oval:tst:194'/>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:21'/>
                <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:20'/>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:18'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:30'/>
                <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:22'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='libssl-dev DPKG is earlier than 0.9.6c-0.potato.1' test_ref='oval:org.debian.oval:tst:195'/>
                <criterion comment='libssl0.9.6 DPKG is earlier than 0.9.6c-0.potato.1' test_ref='oval:org.debian.oval:tst:196'/>
                <criterion comment='openssl DPKG is earlier than 0.9.6c-0.potato.1' test_ref='oval:org.debian.oval:tst:197'/>
                <criterion comment='ssh DPKG is earlier than 3.4p1-0.0potato1' test_ref='oval:org.debian.oval:tst:198'/>
                <criterion comment='ssh-askpass-gnome DPKG is earlier than 3.4p1-0.0potato1' test_ref='oval:org.debian.oval:tst:199'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='ssh DPKG is earlier than 3.4p1-0.0woody1' test_ref='oval:org.debian.oval:tst:201'/>
              <criterion comment='ssh-askpass-gnome DPKG is earlier than 3.4p1-0.0woody1' test_ref='oval:org.debian.oval:tst:202'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:135' class='vulnerability'>
      <metadata>
        <title>buffer overflow / DoS</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>libapache-mod-ssl</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0653' ref_id='CVE-2002-0653'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-07-02</date>
          <moreinfo>
The libapache-mod-ssl package provides SSL capability to the apache
webserver.
Recently, a problem has been found in the handling of .htaccess files,
allowing arbitrary code execution as the web server user (regardless of
ExecCGI / suexec settings), DoS attacks (killing off apache children), and
allowing someone to take control of apache child processes - all through
specially crafted .htaccess files.
This has been fixed in the libapache-mod-ssl_2.4.10-1.3.9-1potato2 package
(for potato), and the libapache-mod-ssl_2.8.9-2 package (for woody).
We recommend you upgrade as soon as possible.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criterion comment='libapache-mod-ssl-doc DPKG is earlier than 2.4.10-1.3.9-1potato2' test_ref='oval:org.debian.oval:tst:203'/>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:21'/>
                <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:20'/>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:18'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:30'/>
                <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:22'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='libapache-mod-ssl DPKG is earlier than 2.4.10-1.3.9-1potato2' test_ref='oval:org.debian.oval:tst:204'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criterion comment='libapache-mod-ssl-doc DPKG is earlier than 2.8.9-2' test_ref='oval:org.debian.oval:tst:205'/>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:206'/>
                <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:19'/>
                <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:20'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:21'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:30'/>
                <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:207'/>
                <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:208'/>
                <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:22'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='libapache-mod-ssl DPKG is earlier than 2.8.9-2' test_ref='oval:org.debian.oval:tst:209'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:136' class='vulnerability'>
      <metadata>
        <title>multiple remote exploits</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>openssl</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0655' ref_id='CVE-2002-0655'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0656' ref_id='CVE-2002-0656'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0657' ref_id='CVE-2002-0657'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0659' ref_id='CVE-2002-0659'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-07-30</date>
          <moreinfo>
The OpenSSL development team has announced that a security audit by A.L.
Digital Ltd and The Bunker, under the DARPA CHATS program, has revealed
remotely exploitable buffer overflow conditions in the OpenSSL code.
Additionally, the ASN1 parser in OpenSSL has a potential DoS attack
independently discovered by Adi Stav and James Yonan.
CAN-2002-0655 references overflows in buffers used to hold ASCII
representations of integers on 64 bit platforms. CAN-2002-0656
references buffer overflows in the SSL2 server implementation (by
sending an invalid key to the server) and the SSL3 client implementation
(by sending a large session id to the client). The SSL2 issue was also
noticed by Neohapsis, who have privately demonstrated exploit code for
this issue. CAN-2002-0659 references the ASN1 parser DoS issue.
These vulnerabilities have been addressed for Debian 3.0 (woody) in
openssl094_0.9.4-6.woody.2, openssl095_0.9.5a-6.woody.1 and
openssl_0.9.6c-2.woody.1.
These vulnerabilities are also present in Debian 2.2 (potato). Fixed
packages are available in openssl094_0.9.4-6.potato.2 and
openssl_0.9.6c-0.potato.4.
A worm is actively exploiting this issue on internet-attached hosts;
we recommend you upgrade your OpenSSL as soon as possible. Note that you
must restart any daemons using SSL. (E.g., ssh or ssl-enabled apache.)
If you are uncertain which programs are using SSL you may choose to
reboot to ensure that all running daemons are using the new libraries.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criterion comment='ssleay DPKG is earlier than 0.9.6c-0.potato.3' test_ref='oval:org.debian.oval:tst:210'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libssl-dev DPKG is earlier than 0.9.6c-0.potato.4' test_ref='oval:org.debian.oval:tst:211'/>
              <criterion comment='libssl0.9.6 DPKG is earlier than 0.9.6c-0.potato.4' test_ref='oval:org.debian.oval:tst:212'/>
              <criterion comment='openssl DPKG is earlier than 0.9.6c-0.potato.4' test_ref='oval:org.debian.oval:tst:213'/>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:21'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='libssl09 DPKG is earlier than 0.9.4-6.potato.2' test_ref='oval:org.debian.oval:tst:214'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:206'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='libssl-dev DPKG is earlier than 0.9.6c-2.woody.0' test_ref='oval:org.debian.oval:tst:215'/>
                <criterion comment='libssl0.9.6 DPKG is earlier than 0.9.6c-2.woody.0' test_ref='oval:org.debian.oval:tst:216'/>
                <criterion comment='openssl DPKG is earlier than 0.9.6c-2.woody.0' test_ref='oval:org.debian.oval:tst:217'/>
              </criteria>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:21'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='libssl09 DPKG is earlier than 0.9.4-6.woody.1' test_ref='oval:org.debian.oval:tst:218'/>
                <criterion comment='libssl-dev DPKG is earlier than 0.9.6c-2.woody.1' test_ref='oval:org.debian.oval:tst:219'/>
                <criterion comment='libssl0.9.6 DPKG is earlier than 0.9.6c-2.woody.1' test_ref='oval:org.debian.oval:tst:220'/>
                <criterion comment='libssl095a DPKG is earlier than 0.9.5a-6.woody.1' test_ref='oval:org.debian.oval:tst:221'/>
                <criterion comment='openssl DPKG is earlier than 0.9.6c-2.woody.1' test_ref='oval:org.debian.oval:tst:222'/>
              </criteria>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported platform section' operator='AND'>
                <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:245'/>
                <criteria comment='Packages section' operator='OR'>
                  <criterion comment='libssl-dev DPKG is earlier than 0.9.6c-2.woody.1' test_ref='oval:org.debian.oval:tst:246'/>
                  <criterion comment='libssl0.9.6 DPKG is earlier than 0.9.6c-2.woody.1' test_ref='oval:org.debian.oval:tst:247'/>
                  <criterion comment='openssl DPKG is earlier than 0.9.6c-2.woody.1' test_ref='oval:org.debian.oval:tst:248'/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:137' class='vulnerability'>
      <metadata>
        <title>insecure temporary files</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>mm</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0658' ref_id='CVE-2002-0658'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-07-30</date>
          <moreinfo>
Marcus Meissner and Sebastian Krahmer discovered and fixed a temporary
file vulnerability in the mm shared memory library.  This problem can
be exploited to gain root access to a machine running Apache which is
linked against this library, if shell access to the user &amp;ldquo;www-data&amp;rdquo;
is already available (which could easily be triggered through PHP).
This problem has been fixed in the upstream version 1.2.0 of mm, which
will be uploaded to the unstable Debian distribution while this
advisory is released.  Fixed packages for potato (Debian 2.2) and
woody (Debian 3.0) are linked below.
We recommend that you upgrade your libmm packages immediately and
restart your Apache server.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libmm10-dev DPKG is earlier than 1.0.11-1.2' test_ref='oval:org.debian.oval:tst:249'/>
              <criterion comment='libmm10 DPKG is earlier than 1.0.11-1.2' test_ref='oval:org.debian.oval:tst:250'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libmm11-dev DPKG is earlier than 1.1.3-6.1' test_ref='oval:org.debian.oval:tst:251'/>
              <criterion comment='libmm11 DPKG is earlier than 1.1.3-6.1' test_ref='oval:org.debian.oval:tst:252'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:138' class='vulnerability'>
      <metadata>
        <title>remote exploit</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>gallery</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1412' ref_id='CVE-2002-1412'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-08-01</date>
          <moreinfo>
A problem was found in gallery (a web-based photo album toolkit): it
was possible to pass in the GALLERY_BASEDIR variable remotely. This
made it possible to execute commands under the uid of web-server.
This has been fixed in version 1.2.5-7 of the Debian package and upstream
version 1.3.1.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='gallery DPKG is earlier than 1.2.5-7.woody.0' test_ref='oval:org.debian.oval:tst:253'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:139' class='vulnerability'>
      <metadata>
        <title>format string vulnerability</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>super</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0817' ref_id='CVE-2002-0817'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-08-01</date>
          <moreinfo>
GOBBLES found an insecure use of format strings in the super package.
The included program super is intended to provide access to certain
system users for particular users and programs, similar to the program
sudo.  Exploiting this format string vulnerability a local user can
gain unauthorized root access.
This problem has been fixed in version 3.12.2-2.1 for the old stable
distribution (potato), in version 3.16.1-1.1 for the current stable
distribution (woody) and in version 3.18.0-3 for the unstable
distribution (sid).
We recommend that you upgrade your super package immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='super DPKG is earlier than 3.12.2-2.1' test_ref='oval:org.debian.oval:tst:254'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:206'/>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:18'/>
                <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:19'/>
                <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:20'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:21'/>
                <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:207'/>
                <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:235'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:30'/>
                <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:208'/>
                <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:245'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='super DPKG is earlier than 3.16.1-1.1' test_ref='oval:org.debian.oval:tst:255'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:140' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>libpng, libpng3</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0660' ref_id='CVE-2002-0660'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0728' ref_id='CVE-2002-0728'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-08-05</date>
          <moreinfo>
Developers of the PNG library have fixed a buffer overflow in the
progressive reader when the PNG datastream contains more IDAT data
than indicated by the IHDR chunk.  Such deliberately malformed
datastreams would crash applications which could potentially allow an
attacker to execute malicious code.  Programs such as Galeon,
Konqueror and various others make use of these libraries.
In addition to that, the packages below fix another
potential buffer overflow.  The PNG libraries implement a safety
margin which is also included in a newer upstream release.  Thanks to
Glenn Randers-Pehrson for informing us.
To find out which packages depend on this library, you may want to
execute the following commands:
This problem has been fixed in version 1.0.12-3.woody.2 of libpng and
version 1.2.1-1.1.woody.2 of libpng3 for the current stable
distribution (woody) and in version 1.0.12-4 of libpng and version
1.2.1-2 of libpng3 for the unstable distribution (sid).
The potato release of Debian does not seem to be vulnerable.
We recommend that you upgrade your libpng packages immediately and
restart programs and daemons that link to these libraries and read
external data, such as web browsers.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libpng2-dev DPKG is earlier than 1.0.12-3.woody.2' test_ref='oval:org.debian.oval:tst:256'/>
            <criterion comment='libpng3 DPKG is earlier than 1.2.1-1.1.woody.2' test_ref='oval:org.debian.oval:tst:257'/>
            <criterion comment='libpng-dev DPKG is earlier than 1.2.1-1.1.woody.2' test_ref='oval:org.debian.oval:tst:258'/>
            <criterion comment='libpng2 DPKG is earlier than 1.0.12-3.woody.2' test_ref='oval:org.debian.oval:tst:259'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:141' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>mpack</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1425' ref_id='CVE-2002-1425'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-08-01</date>
          <moreinfo>
Eckehard Berns discovered a buffer overflow in the munpack program
which is used for decoding (respectively) binary files in MIME
(Multipurpose Internet Mail Extensions) format mail messages.  If
munpack is run on an appropriately malformed email (or news article)
then it will crash, and perhaps can be made to run arbitrary code.
Herbert Xu reported a second vulnerability which affected malformed
filenames that refer to files in upper directories like "../a".  The
security impact is limited, though, because only a single leading
"../" was accepted and only new files can be created (i.e. no files
will be overwritten).
Both problems have been fixed in version 1.5-5potato2 for the old
stable distribution (potato), in version 1.5-7woody2 for the current
stable distribution (woody) and in version 1.5-9 for the unstable
distribution (sid).
We recommend that you upgrade your mpack package immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='mpack DPKG is earlier than 1.5-5potato2' test_ref='oval:org.debian.oval:tst:260'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='mpack DPKG is earlier than 1.5-7woody2' test_ref='oval:org.debian.oval:tst:261'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:142' class='vulnerability'>
      <metadata>
        <title>integer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>openafs</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0391' ref_id='CVE-2002-0391'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-08-05</date>
          <moreinfo>
An integer overflow bug has been discovered in the RPC library used by
the OpenAFS database server, which is derived from the SunRPC library.
This bug could be exploited to crash certain OpenAFS servers
(volserver, vlserver, ptserver, buserver) or to obtain unauthorized
root access to a host running one of these processes.  No exploits are
known to exist yet.
This problem has been fixed in version 1.2.3final2-6 for the current
stable distribution (woody) and in version 1.2.6-1 for the unstable
distribution (sid).  Debian 2.2 (potato) is not affected since it
doesn't contain OpenAFS packages.
OpenAFS is only available for the architectures alpha, i386, powerpc,
s390, sparc.  Hence, we only provide fixed packages for these
architectures.
We recommend that you upgrade your openafs packages.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='openafs-modules-source DPKG is earlier than 1.2.3final2-6' test_ref='oval:org.debian.oval:tst:262'/>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:206'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:21'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:20'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:30'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='openafs-kpasswd DPKG is earlier than 1.2.3final2-6' test_ref='oval:org.debian.oval:tst:263'/>
              <criterion comment='openafs-client DPKG is earlier than 1.2.3final2-6' test_ref='oval:org.debian.oval:tst:264'/>
              <criterion comment='openafs-fileserver DPKG is earlier than 1.2.3final2-6' test_ref='oval:org.debian.oval:tst:265'/>
              <criterion comment='openafs-dbserver DPKG is earlier than 1.2.3final2-6' test_ref='oval:org.debian.oval:tst:266'/>
              <criterion comment='libopenafs-dev DPKG is earlier than 1.2.3final2-6' test_ref='oval:org.debian.oval:tst:267'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:143' class='vulnerability'>
      <metadata>
        <title>integer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>krb5</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0391' ref_id='CVE-2002-0391'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-08-05</date>
          <moreinfo>
An integer overflow bug has been discovered in the RPC library used by
the Kerberos 5 administration system, which is derived from the SunRPC
library.  This bug could be exploited to gain unauthorized root access
to a KDC host.  It is believed that the attacker needs to be able to
authenticate to the kadmin daemon for this attack to be successful.
No exploits are known to exist yet.
This problem has been fixed in version 1.2.4-5woody1 for the current
stable distribution (woody) and in version 1.2.5-2 for the unstable
distribution (sid).  Debian 2.2 (potato) is not affected since it
doesn't contain krb5 packages.
We recommend that you upgrade your kerberos packages immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='krb5-doc DPKG is earlier than 1.2.4-5woody1' test_ref='oval:org.debian.oval:tst:268'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='krb5-rsh-server DPKG is earlier than 1.2.4-5woody1' test_ref='oval:org.debian.oval:tst:269'/>
            <criterion comment='krb5-telnetd DPKG is earlier than 1.2.4-5woody1' test_ref='oval:org.debian.oval:tst:270'/>
            <criterion comment='libkrb53 DPKG is earlier than 1.2.4-5woody1' test_ref='oval:org.debian.oval:tst:271'/>
            <criterion comment='libkrb5-dev DPKG is earlier than 1.2.4-5woody1' test_ref='oval:org.debian.oval:tst:272'/>
            <criterion comment='krb5-ftpd DPKG is earlier than 1.2.4-5woody1' test_ref='oval:org.debian.oval:tst:273'/>
            <criterion comment='krb5-admin-server DPKG is earlier than 1.2.4-5woody1' test_ref='oval:org.debian.oval:tst:274'/>
            <criterion comment='libkadm55 DPKG is earlier than 1.2.4-5woody1' test_ref='oval:org.debian.oval:tst:275'/>
            <criterion comment='krb5-user DPKG is earlier than 1.2.4-5woody1' test_ref='oval:org.debian.oval:tst:276'/>
            <criterion comment='krb5-clients DPKG is earlier than 1.2.4-5woody1' test_ref='oval:org.debian.oval:tst:277'/>
            <criterion comment='krb5-kdc DPKG is earlier than 1.2.4-5woody1' test_ref='oval:org.debian.oval:tst:278'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:144' class='vulnerability'>
      <metadata>
        <title>improper input handling</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>wwwoffle</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0818' ref_id='CVE-2002-0818'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-08-06</date>
          <moreinfo>
A problem with wwwoffle has been discovered.  The web proxy didn't
handle input data with negative Content-Length settings properly which
causes the processing child to crash.  It is at this time not obvious
how this can lead to an exploitable vulnerability; however, it's better
to be safe than sorry, so here's an update.
Additionally, in the woody version empty passwords will be treated as
wrong when trying to authenticate.  In the woody version we also
replaced CanonicaliseHost() with the latest routine from 2.7d, offered
by upstream.  This stops bad IPv6 format IP addresses in URLs from
causing problems (memory overwriting, potential exploits).
This problem has been fixed in version 2.5c-10.4 for the old stable
distribution (potato), in version 2.7a-1.2 for the current stable
distribution (woody) and in version 2.7d-1 for the unstable
distribution (sid).
We recommend that you upgrade your wwwoffle packages.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='wwwoffle DPKG is earlier than 2.5c-10.4' test_ref='oval:org.debian.oval:tst:279'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='wwwoffle DPKG is earlier than 2.7a-1.2' test_ref='oval:org.debian.oval:tst:280'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:145' class='vulnerability'>
      <metadata>
        <title>doubly freed memory</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>tinyproxy</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0847' ref_id='CVE-2002-0847'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-08-07</date>
          <moreinfo>
The authors of tinyproxy, a lightweight HTTP proxy, discovered a bug
in the handling of some invalid proxy requests.  Under some
circumstances, an invalid request may result in allocated memory
being freed twice.  This can potentially result in the execution of
arbitrary code.
This problem has been fixed in version 1.4.3-2woody2 for the current
stable distribution (woody) and in version 1.4.3-3 for the unstable
distribution (sid).  The old stable distribution (potato) is not
affected by this problem.
We recommend that you upgrade your tinyproxy package immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='tinyproxy DPKG is earlier than 1.4.3-2woody2' test_ref='oval:org.debian.oval:tst:281'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:146' class='vulnerability'>
      <metadata>
        <title>integer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>dietlibc</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0391' ref_id='CVE-2002-0391'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-08-08</date>
          <moreinfo>
An integer overflow bug has been discovered in the RPC library used by
dietlibc, a libc optimized for small size, which is derived from the
SunRPC library.  This bug could be exploited to gain unauthorized root
access to software linking to this code.  The packages below also fix
integer overflows in the calloc, fread and fwrite code.  They are also
more strict regarding hostile DNS packets that could lead to a
vulnerability otherwise.
These problems have been fixed in version 0.12-2.4 for the current
stable distribution (woody) and in version 0.20-0cvs20020808 for the
unstable distribution (sid).  Debian 2.2 (potato) is not affected
since it doesn't contain dietlibc packages.
We recommend that you upgrade your dietlibc packages immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='dietlibc-doc DPKG is earlier than 0.12-2.4' test_ref='oval:org.debian.oval:tst:282'/>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:20'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:21'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:30'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:207'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:208'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:22'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='dietlibc-dev DPKG is earlier than 0.12-2.4' test_ref='oval:org.debian.oval:tst:283'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:147' class='vulnerability'>
      <metadata>
        <title>cross-site scripting</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>mailman</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0388' ref_id='CVE-2002-0388'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0855' ref_id='CVE-2002-0855'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-08-08</date>
          <moreinfo>
A cross-site scripting vulnerability was discovered in mailman, a
software to manage electronic mailing lists.  When a properly crafted
URL is accessed with Internet Explorer (other browsers don't seem to
be affected), the resulting webpage is rendered similar to the real
one, but the javascript component is executed as well, which could be
used by an attacker to get access to sensitive information.  The new
version for Debian 2.2 also includes backports of security related
patches from mailman 2.0.11.
This problem has been fixed in version 2.0.11-1woody4 for the current
stable distribution (woody), in version 1.1-10.1 for the old stable
distribution (potato) and in version 2.0.12-1 for the unstable
distribution (sid).
We recommend that you upgrade your mailman package.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='mailman DPKG is earlier than 1.1-10.1' test_ref='oval:org.debian.oval:tst:284'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='mailman DPKG is earlier than 2.0.11-1woody4' test_ref='oval:org.debian.oval:tst:285'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:148' class='vulnerability'>
      <metadata>
        <title>buffer overflows and format string vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>hylafax</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1049' ref_id='CVE-2002-1049'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1050' ref_id='CVE-2002-1050'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1034' ref_id='CVE-2001-1034'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-08-12</date>
          <moreinfo>
A set of problems have been discovered in Hylafax, a flexible
client/server fax software distributed with many GNU/Linux
distributions.  Quoting SecurityFocus the problems are in detail:
These problems have been fixed in version 4.0.2-14.3 for the old
stable distribution (potato), in version 4.1.1-1.1 for the current
stable distribution (woody) and in version 4.1.2-2.1 for the unstable
distribution (sid).
We recommend that you upgrade your hylafax packages.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criterion comment='hylafax-doc DPKG is earlier than 4.0.2-14.3' test_ref='oval:org.debian.oval:tst:286'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='hylafax-client DPKG is earlier than 4.0.2-14.3' test_ref='oval:org.debian.oval:tst:287'/>
              <criterion comment='hylafax-server DPKG is earlier than 4.0.2-14.3' test_ref='oval:org.debian.oval:tst:288'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criterion comment='hylafax-doc DPKG is earlier than 4.1.1-1.1' test_ref='oval:org.debian.oval:tst:289'/>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:206'/>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:18'/>
                <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:19'/>
                <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:22'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:21'/>
                <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:235'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:30'/>
                <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:20'/>
                <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:245'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='hylafax-client DPKG is earlier than 4.1.1-1.1' test_ref='oval:org.debian.oval:tst:290'/>
                <criterion comment='hylafax-server DPKG is earlier than 4.1.1-1.1' test_ref='oval:org.debian.oval:tst:291'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:149' class='vulnerability'>
      <metadata>
        <title>integer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>glibc</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0391' ref_id='CVE-2002-0391'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-08-13</date>
          <moreinfo>
An integer overflow bug has been discovered in the RPC library used by
GNU libc, which is derived from the SunRPC library.  This bug could be
exploited to gain unauthorized root access to software linking to this
code.  The packages below also fix integer overflows in the malloc
code.  They also contain a fix from Andreas Schwab to reduce
linebuflen in parallel to bumping up the buffer pointer in the NSS DNS
code.
This problem has been fixed in version 2.1.3-23 for the old stable
distribution (potato), in version 2.2.5-11.1 for the current stable
distribution (woody) and in version 2.2.5-13 for the unstable
distribution (sid).
We recommend that you upgrade your libc6 packages immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='glibc-doc DPKG is earlier than 2.1.3-24' test_ref='oval:org.debian.oval:tst:292'/>
                <criterion comment='i18ndata DPKG is earlier than 2.1.3-24' test_ref='oval:org.debian.oval:tst:293'/>
              </criteria>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:18'/>
                <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:19'/>
                <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:20'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:21'/>
                <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:22'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='nscd DPKG is earlier than 2.1.3-24' test_ref='oval:org.debian.oval:tst:294'/>
                <criterion comment='libc6-dev DPKG is earlier than 2.1.3-24' test_ref='oval:org.debian.oval:tst:295'/>
                <criterion comment='libc6-pic DPKG is earlier than 2.1.3-24' test_ref='oval:org.debian.oval:tst:296'/>
                <criterion comment='libc6 DPKG is earlier than 2.1.3-24' test_ref='oval:org.debian.oval:tst:297'/>
                <criterion comment='libc6-prof DPKG is earlier than 2.1.3-24' test_ref='oval:org.debian.oval:tst:298'/>
                <criterion comment='libc6-dbg DPKG is earlier than 2.1.3-24' test_ref='oval:org.debian.oval:tst:299'/>
                <criterion comment='locales DPKG is earlier than 2.1.3-24' test_ref='oval:org.debian.oval:tst:300'/>
              </criteria>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:30'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='libc6.1-pic DPKG is earlier than 2.1.3-24' test_ref='oval:org.debian.oval:tst:301'/>
                <criterion comment='libc6.1-dev DPKG is earlier than 2.1.3-24' test_ref='oval:org.debian.oval:tst:302'/>
                <criterion comment='libc6.1-dbg DPKG is earlier than 2.1.3-24' test_ref='oval:org.debian.oval:tst:303'/>
                <criterion comment='libnss1-compat DPKG is earlier than 2.1.3-24' test_ref='oval:org.debian.oval:tst:304'/>
                <criterion comment='libc6.1-prof DPKG is earlier than 2.1.3-24' test_ref='oval:org.debian.oval:tst:305'/>
                <criterion comment='libc6.1 DPKG is earlier than 2.1.3-24' test_ref='oval:org.debian.oval:tst:306'/>
                <criterion comment='nscd DPKG is earlier than 2.1.3-24' test_ref='oval:org.debian.oval:tst:307'/>
                <criterion comment='locales DPKG is earlier than 2.1.3-24' test_ref='oval:org.debian.oval:tst:308'/>
              </criteria>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported platform section' operator='AND'>
                <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:19'/>
                <criteria comment='Packages section' operator='OR'>
                  <criterion comment='libnss1-compat DPKG is earlier than 2.1.3-24' test_ref='oval:org.debian.oval:tst:310'/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='glibc-doc DPKG is earlier than 2.2.5-11.2' test_ref='oval:org.debian.oval:tst:311'/>
                <criterion comment='locales DPKG is earlier than 2.2.5-11.2' test_ref='oval:org.debian.oval:tst:312'/>
              </criteria>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:206'/>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:18'/>
                <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:19'/>
                <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:22'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:21'/>
                <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:207'/>
                <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:20'/>
                <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:208'/>
                <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:245'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='nscd DPKG is earlier than 2.2.5-11.2' test_ref='oval:org.debian.oval:tst:313'/>
                <criterion comment='libc6-dev DPKG is earlier than 2.2.5-11.2' test_ref='oval:org.debian.oval:tst:314'/>
                <criterion comment='libc6-pic DPKG is earlier than 2.2.5-11.2' test_ref='oval:org.debian.oval:tst:315'/>
                <criterion comment='libc6 DPKG is earlier than 2.2.5-11.2' test_ref='oval:org.debian.oval:tst:316'/>
                <criterion comment='libc6-prof DPKG is earlier than 2.2.5-11.2' test_ref='oval:org.debian.oval:tst:317'/>
                <criterion comment='libc6-dbg DPKG is earlier than 2.2.5-11.2' test_ref='oval:org.debian.oval:tst:318'/>
              </criteria>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:235'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:30'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='libc6.1-pic DPKG is earlier than 2.2.5-11.2' test_ref='oval:org.debian.oval:tst:319'/>
                <criterion comment='libc6.1-dev DPKG is earlier than 2.2.5-11.2' test_ref='oval:org.debian.oval:tst:320'/>
                <criterion comment='libc6.1-dbg DPKG is earlier than 2.2.5-11.2' test_ref='oval:org.debian.oval:tst:321'/>
                <criterion comment='libc6.1-prof DPKG is earlier than 2.2.5-11.2' test_ref='oval:org.debian.oval:tst:322'/>
                <criterion comment='nscd DPKG is earlier than 2.2.5-11.2' test_ref='oval:org.debian.oval:tst:323'/>
                <criterion comment='libc6.1 DPKG is earlier than 2.2.5-11.2' test_ref='oval:org.debian.oval:tst:324'/>
              </criteria>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported platform section' operator='AND'>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:18'/>
                <criteria comment='Packages section' operator='OR'>
                  <criterion comment='libc6-sparc64 DPKG is earlier than 2.2.5-11.2' test_ref='oval:org.debian.oval:tst:325'/>
                  <criterion comment='libc6-dev-sparc64 DPKG is earlier than 2.2.5-11.2' test_ref='oval:org.debian.oval:tst:326'/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:150' class='vulnerability'>
      <metadata>
        <title>illegal file exposition</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>interchange</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0874' ref_id='CVE-2002-0874'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-08-13</date>
          <moreinfo>
A problem has been discovered in Interchange, an e-commerce and
general HTTP database display system, which can lead to an attacker
being able to read any file to which the user of the Interchange
daemon has sufficient permissions, when Interchange runs in "INET
mode" (internet domain socket).  This is not the default setting in
Debian packages, but configurable with Debconf and via configuration
file.  We also believe that this bug cannot exploited on a regular
Debian system.
This problem has been fixed by the package maintainer in version
4.8.3.20020306-1.woody.1 for the current stable distribution (woody)
and in version 4.8.6-1 for the unstable distribution (sid).  The old
stable distribution (potato) is not affected, since it doesn't ship
the Interchange system.
We recommend that you upgrade your interchange packages.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='interchange-ui DPKG is earlier than 4.8.3.20020306-1.woody.1' test_ref='oval:org.debian.oval:tst:327'/>
              <criterion comment='interchange-cat-foundation DPKG is earlier than 4.8.3.20020306-1.woody.1' test_ref='oval:org.debian.oval:tst:328'/>
            </criteria>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libapache-mod-interchange DPKG is earlier than 4.8.3.20020306-1.woody.1' test_ref='oval:org.debian.oval:tst:329'/>
            <criterion comment='interchange DPKG is earlier than 4.8.3.20020306-1.woody.1' test_ref='oval:org.debian.oval:tst:330'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:151' class='vulnerability'>
      <metadata>
        <title>pipe exposure</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>xinetd</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0871' ref_id='CVE-2002-0871'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-08-13</date>
          <moreinfo>
Solar Designer found a vulnerability in xinetd, a replacement for the
BSD derived inetd.  File descriptors for the signal pipe introduced in
version 2.3.4 are leaked into services started from xinetd.  The
descriptors could be used to talk to xinetd resulting in crashing it
entirely.  This is usually called a denial of service.
This problem has been fixed by the package maintainer in version
2.3.4-1.2 for the current stable distribution (woody) and in version
2.3.7-1 for the unstable distribution (sid).  The old stable
distribution (potato) is not affected, since it doesn't contain the
signal pipe.
We recommend that you upgrade your xinetd packages.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='xinetd DPKG is earlier than 2.3.4-1.2' test_ref='oval:org.debian.oval:tst:331'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:152' class='vulnerability'>
      <metadata>
        <title>missing random seed</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>l2tpd</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0872' ref_id='CVE-2002-0872'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0873' ref_id='CVE-2002-0873'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-08-13</date>
          <moreinfo>
Current versions of l2tpd, a layer 2 tunneling client/server program,
forgot to initialize the random generator which made it vulnerable
since all generated random number were 100% guessable.  When dealing
with the size of the value in an attribute value pair, too many bytes
were able to be copied, which could lead into the vendor field being
overwritten.
These problems have been fixed in version 0.67-1.1 for the current
stable distribution (woody) and in version 0.68-1 for the unstable
distribution (sid).  The old stable distribution (potato) is not
affected, since it doesn't contain the l2tpd package.
We recommend that you upgrade your l2tpd packages.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='l2tpd DPKG is earlier than 0.67-1.1' test_ref='oval:org.debian.oval:tst:332'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:153' class='vulnerability'>
      <metadata>
        <title>cross site code execution and privilege escalation</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>mantis</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1114' ref_id='CVE-2002-1114'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1113' ref_id='CVE-2002-1113'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1112' ref_id='CVE-2002-1112'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1111' ref_id='CVE-2002-1111'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1110' ref_id='CVE-2002-1110'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-08-14</date>
          <moreinfo>
Joao Gouveia discovered an uninitialized variable which was insecurely
used with file inclusions in the mantis package, a php based bug
tracking system.  The Debian Security Team found even more similar
problems.  When these occasions are exploited, a remote user is able
to execute arbitrary code under the webserver user id on the web
server hosting the mantis system.
Jeroen Latour discovered that Mantis did not check all user input,
especially if they do not come directly from form fields. This opens
up a wide variety of SQL poisoning vulnerabilities on systems without
magic_quotes_gpc enabled.  Most of these vulnerabilities are only
exploitable in a limited manner, since it is no longer possible to
execute multiple queries using one call to mysql_query().  There is
one query which can be tricked into changing an account's access
level.
Jeroen Latour also reported that it is possible to instruct Mantis to
show reporters only the bugs that they reported, by setting the
limit_reporters option to ON.  However, when formatting the output
suitable for printing, the program did not check the limit_reporters
option and thus allowed reporters to see the summaries of bugs they
did not report.
Jeroen Latour discovered that the page responsible for displaying a
list of bugs in a particular project, did not check whether the user
actually has access to the project, which is transmitted by a cookie
variable.  It accidentally trusted the fact that only projects
accessible to the user were listed in the drop-down menu.  This
provides a malicious user with an opportunity to display the bugs of a
private project selected.
These problems have been fixed in version 0.17.1-2.2 for the current
stable distribution (woody) and in version 0.17.4a-2 for the unstable
distribution (sid).  The old stable distribution (potato) is not
affected, since it doesn't contain the mantis package.
Additional information:
We recommend that you upgrade your mantis packages immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='mantis DPKG is earlier than 0.17.1-2.2' test_ref='oval:org.debian.oval:tst:333'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:154' class='vulnerability'>
      <metadata>
        <title>privilege escalation</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>fam</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0875' ref_id='CVE-2002-0875'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-08-15</date>
          <moreinfo>
A &lt;a href="http://oss.sgi.com/bugzilla/show_bug.cgi?id=151">flaw&lt;/a>
was discovered in FAM's group handling.  In the effect users
are unable to read FAM directories they have group read and execute
permissions on.  However, also unprivileged users can potentially
learn names of files that only users in root's group should be able to
view.
This problem been fixed in version 2.6.6.1-5.2 for the current stable
stable distribution (woody) and in version 2.6.8-1 (or any later
version) for the unstable distribution (sid).  The old stable
distribution (potato) is not affected, since it doesn't contain fam
packages.
We recommend that you upgrade your fam packages.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libfam-dev DPKG is earlier than 2.6.6.1-5.2' test_ref='oval:org.debian.oval:tst:334'/>
            <criterion comment='libfam0 DPKG is earlier than 2.6.6.1-5.2' test_ref='oval:org.debian.oval:tst:335'/>
            <criterion comment='fam DPKG is earlier than 2.6.6.1-5.2' test_ref='oval:org.debian.oval:tst:336'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:155' class='vulnerability'>
      <metadata>
        <title>privacy escalation with Konqueror</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>kdelibs</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0970' ref_id='CVE-2002-0970'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-08-17</date>
          <moreinfo>
Due to a security engineering oversight, the SSL library from KDE,
which Konqueror uses, doesn't check whether an intermediate
certificate for a connection is signed by the certificate authority as
safe for the purpose, but accepts it when it is signed.  This makes it
possible for anyone with a valid VeriSign SSL site certificate to
forge any other VeriSign SSL site certificate, and abuse Konqueror
users.
A local root exploit using artsd has been discovered which exploited
an insecure use of a format string.  The exploit wasn't working on a
Debian system since artsd wasn't running setuid root.  Neither artsd
nor artswrapper need to be setuid root anymore since current computer
systems are fast enough to handle the audio data in time.
These problems have been fixed in version 2.2.2-13.woody.2 for the
current stable distribution (woody).  The old stable
distribution (potato) is not affected, since it doesn't contain KDE
packages.  The unstable distribution (sid) is not yet fixed, but new
packages are expected in the future, the fixed version will be version
2.2.2-14 or higher.
We recommend that you upgrade your kdelibs and libarts packages and
restart Konqueror.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='kdelibs3-doc DPKG is earlier than 2.2.2-13.woody.2' test_ref='oval:org.debian.oval:tst:337'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libarts DPKG is earlier than 2.2.2-13.woody.2' test_ref='oval:org.debian.oval:tst:338'/>
            <criterion comment='libkmid-alsa DPKG is earlier than 2.2.2-13.woody.2' test_ref='oval:org.debian.oval:tst:339'/>
            <criterion comment='kdelibs3-bin DPKG is earlier than 2.2.2-13.woody.2' test_ref='oval:org.debian.oval:tst:340'/>
            <criterion comment='libarts-alsa DPKG is earlier than 2.2.2-13.woody.2' test_ref='oval:org.debian.oval:tst:341'/>
            <criterion comment='kdelibs3 DPKG is earlier than 2.2.2-13.woody.2' test_ref='oval:org.debian.oval:tst:342'/>
            <criterion comment='kdelibs3-cups DPKG is earlier than 2.2.2-13.woody.2' test_ref='oval:org.debian.oval:tst:343'/>
            <criterion comment='libkmid-dev DPKG is earlier than 2.2.2-13.woody.2' test_ref='oval:org.debian.oval:tst:344'/>
            <criterion comment='libkmid DPKG is earlier than 2.2.2-13.woody.2' test_ref='oval:org.debian.oval:tst:345'/>
            <criterion comment='libarts-dev DPKG is earlier than 2.2.2-13.woody.2' test_ref='oval:org.debian.oval:tst:346'/>
            <criterion comment='kdelibs-dev DPKG is earlier than 2.2.2-13.woody.2' test_ref='oval:org.debian.oval:tst:347'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:156' class='vulnerability'>
      <metadata>
        <title>arbitrary script execution</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>epic4-script-light</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0984' ref_id='CVE-2002-0984'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-08-22</date>
          <moreinfo>
All versions of the EPIC script Light prior to 2.7.30p5 (on the 2.7
branch) and prior to 2.8pre10 (on the 2.8 branch) running on any
platform are vulnerable to a remotely-exploitable bug, which can lead
to nearly arbitrary code execution.
This problem has been fixed in version 2.7.30p5-1.1 for the current
stable distribution (woody) and in version 2.7.30p5-2 for the unstable
distribution (sid).  The old stable distribution (potato) is not
affected, since it doesn't contain the Light package.
We recommend that you upgrade your epic4-script-light package and
restart your IRC client.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='epic4-script-light DPKG is earlier than 2.7.30p5-1.1' test_ref='oval:org.debian.oval:tst:348'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:157' class='vulnerability'>
      <metadata>
        <title>denial of service</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>irssi-text</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0983' ref_id='CVE-2002-0983'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-08-23</date>
          <moreinfo>
The IRC client irssi is vulnerable to a denial of service condition.
The problem occurs when a user attempts to join a channel that has an
overly long topic description.  When a certain string is appended to
the topic, irssi will crash.
This problem has been fixed in version 0.8.4-3.1 for the current
stable distribution (woody) and in version 0.8.5-2 for the
unstable distribution (sid).  The old stable distribution (potato) is
not affected, since the corresponding portions of code are not
present.  The same applies to irssi-gnome and irssi-gtk, which don't
seem to be affected as well.
We recommend that you upgrade your irssi-text package.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='irssi-text DPKG is earlier than 0.8.4-3.1' test_ref='oval:org.debian.oval:tst:349'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:158' class='vulnerability'>
      <metadata>
        <title>arbitrary program execution</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>gaim</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0989' ref_id='CVE-2002-0989'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-08-27</date>
          <moreinfo>
The developers of Gaim, an instant messenger client that combines
several different networks, found a vulnerability in the hyperlink
handling code.  The 'Manual' browser command passes an untrusted
string to the shell without escaping or reliable quoting, permitting
an attacker to execute arbitrary commands on the users machine.
Unfortunately, Gaim doesn't display the hyperlink before the user
clicks on it.  Users who use other inbuilt browser commands aren't
vulnerable.
This problem has been fixed in version 0.58-2.2 for the current
stable distribution (woody) and in version 0.59.1-2 for the unstable
distribution (sid).  The old stable distribution (potato) is not
affected since it doesn't ship the Gaim program.
The fixed version of Gaim no longer passes the user's manual browser
command to the shell.  Commands which contain the %s in quotes will
need to be amended, so they don't contain any quotes.  The 'Manual'
browser command can be edited in the 'General' pane of the
'Preferences' dialog, which can be accessed by clicking 'Options' from
the login window, or 'Tools' and then 'Preferences' from the menu bar
in the buddy list window.
We recommend that you upgrade your gaim package immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='gaim-common DPKG is earlier than 0.58-2.2' test_ref='oval:org.debian.oval:tst:350'/>
            <criterion comment='gaim-gnome DPKG is earlier than 0.58-2.2' test_ref='oval:org.debian.oval:tst:351'/>
            <criterion comment='gaim DPKG is earlier than 0.58-2.2' test_ref='oval:org.debian.oval:tst:352'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:159' class='vulnerability'>
      <metadata>
        <title>insecure temporary files</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>python</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1119' ref_id='CVE-2002-1119'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-08-28</date>
          <moreinfo>
Zack Weinberg discovered an insecure use of a temporary file in
os._execvpe from os.py.  It uses a predictable name which could lead
execution of arbitrary code.
This problem has been fixed in several versions of Python: For the
current stable distribution (woody) it has been fixed in version
1.5.2-23.1 of Python 1.5, in version 2.1.3-3.1 of Python 2.1 and in
version 2.2.1-4.1 of Python 2.2.  For the old stable distribution
(potato) this has been fixed in version 1.5.2-10potato12 for Python
1.5.  For the unstable distribution (sid) this has been fixed in
version 1.5.2-24 of Python 1.5, in version 2.1.3-6a of Python 2.1 and
in version 2.2.1-8 of Python 2.2.  Python 2.3 is not affected by this
problem.
We recommend that you upgrade your Python packages immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='python-elisp DPKG is earlier than 1.5.2-10potato13' test_ref='oval:org.debian.oval:tst:353'/>
                <criterion comment='python-regrtest DPKG is earlier than 1.5.2-10potato13' test_ref='oval:org.debian.oval:tst:354'/>
                <criterion comment='idle DPKG is earlier than 1.5.2-10potato13' test_ref='oval:org.debian.oval:tst:355'/>
                <criterion comment='python-examples DPKG is earlier than 1.5.2-10potato13' test_ref='oval:org.debian.oval:tst:356'/>
              </criteria>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='python-tk DPKG is earlier than 1.5.2-10potato13' test_ref='oval:org.debian.oval:tst:357'/>
              <criterion comment='python-base DPKG is earlier than 1.5.2-10potato13' test_ref='oval:org.debian.oval:tst:358'/>
              <criterion comment='python-zlib DPKG is earlier than 1.5.2-10potato13' test_ref='oval:org.debian.oval:tst:359'/>
              <criterion comment='python-mpz DPKG is earlier than 1.5.2-10potato13' test_ref='oval:org.debian.oval:tst:360'/>
              <criterion comment='python-gdbm DPKG is earlier than 1.5.2-10potato13' test_ref='oval:org.debian.oval:tst:361'/>
              <criterion comment='python-dev DPKG is earlier than 1.5.2-10potato13' test_ref='oval:org.debian.oval:tst:362'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='python-tk DPKG is earlier than 2.1.3-3.2' test_ref='oval:org.debian.oval:tst:363'/>
                <criterion comment='python2.1-doc DPKG is earlier than 2.1.3-3.2' test_ref='oval:org.debian.oval:tst:364'/>
                <criterion comment='python1.5-examples DPKG is earlier than 1.5.2-23.2' test_ref='oval:org.debian.oval:tst:365'/>
                <criterion comment='idle-python1.5 DPKG is earlier than 1.5.2-23.2' test_ref='oval:org.debian.oval:tst:366'/>
                <criterion comment='python DPKG is earlier than 2.1.3-3.2' test_ref='oval:org.debian.oval:tst:367'/>
                <criterion comment='python-xmlbase DPKG is earlier than 2.1.3-3.2' test_ref='oval:org.debian.oval:tst:368'/>
                <criterion comment='python-examples DPKG is earlier than 2.1.3-3.2' test_ref='oval:org.debian.oval:tst:369'/>
                <criterion comment='python2.2-examples DPKG is earlier than 2.2.1-4.2' test_ref='oval:org.debian.oval:tst:370'/>
                <criterion comment='python2.2-elisp DPKG is earlier than 2.2.1-4.2' test_ref='oval:org.debian.oval:tst:371'/>
                <criterion comment='python-elisp DPKG is earlier than 2.1.3-3.2' test_ref='oval:org.debian.oval:tst:372'/>
                <criterion comment='idle DPKG is earlier than 2.1.3-3.2' test_ref='oval:org.debian.oval:tst:373'/>
                <criterion comment='python2.1-examples DPKG is earlier than 2.1.3-3.2' test_ref='oval:org.debian.oval:tst:374'/>
                <criterion comment='idle-python2.1 DPKG is earlier than 2.1.3-3.2' test_ref='oval:org.debian.oval:tst:375'/>
                <criterion comment='idle-python2.2 DPKG is earlier than 2.2.1-4.2' test_ref='oval:org.debian.oval:tst:376'/>
                <criterion comment='python-mpz DPKG is earlier than 2.1.3-3.2' test_ref='oval:org.debian.oval:tst:377'/>
                <criterion comment='python-gdbm DPKG is earlier than 2.1.3-3.2' test_ref='oval:org.debian.oval:tst:378'/>
                <criterion comment='python2.2-doc DPKG is earlier than 2.2.1-4.2' test_ref='oval:org.debian.oval:tst:379'/>
                <criterion comment='python-doc DPKG is earlier than 2.1.3-3.2' test_ref='oval:org.debian.oval:tst:380'/>
                <criterion comment='python-dev DPKG is earlier than 2.1.3-3.2' test_ref='oval:org.debian.oval:tst:381'/>
                <criterion comment='python2.1-elisp DPKG is earlier than 2.1.3-3.2' test_ref='oval:org.debian.oval:tst:382'/>
              </criteria>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='python1.5 DPKG is earlier than 1.5.2-23.2' test_ref='oval:org.debian.oval:tst:383'/>
              <criterion comment='python2.1-gdbm DPKG is earlier than 2.1.3-3.2' test_ref='oval:org.debian.oval:tst:384'/>
              <criterion comment='python1.5-mpz DPKG is earlier than 1.5.2-23.2' test_ref='oval:org.debian.oval:tst:385'/>
              <criterion comment='python1.5-tk DPKG is earlier than 1.5.2-23.2' test_ref='oval:org.debian.oval:tst:386'/>
              <criterion comment='python1.5-dev DPKG is earlier than 1.5.2-23.2' test_ref='oval:org.debian.oval:tst:387'/>
              <criterion comment='python2.2 DPKG is earlier than 2.2.1-4.2' test_ref='oval:org.debian.oval:tst:388'/>
              <criterion comment='python2.1 DPKG is earlier than 2.1.3-3.2' test_ref='oval:org.debian.oval:tst:389'/>
              <criterion comment='python2.1-dev DPKG is earlier than 2.1.3-3.2' test_ref='oval:org.debian.oval:tst:390'/>
              <criterion comment='python2.1-mpz DPKG is earlier than 2.1.3-3.2' test_ref='oval:org.debian.oval:tst:391'/>
              <criterion comment='python2.1-tk DPKG is earlier than 2.1.3-3.2' test_ref='oval:org.debian.oval:tst:392'/>
              <criterion comment='python1.5-gdbm DPKG is earlier than 1.5.2-23.2' test_ref='oval:org.debian.oval:tst:393'/>
              <criterion comment='python2.2-gdbm DPKG is earlier than 2.2.1-4.2' test_ref='oval:org.debian.oval:tst:394'/>
              <criterion comment='python2.2-xmlbase DPKG is earlier than 2.2.1-4.2' test_ref='oval:org.debian.oval:tst:395'/>
              <criterion comment='python2.1-xmlbase DPKG is earlier than 2.1.3-3.2' test_ref='oval:org.debian.oval:tst:396'/>
              <criterion comment='python2.2-mpz DPKG is earlier than 2.2.1-4.2' test_ref='oval:org.debian.oval:tst:397'/>
              <criterion comment='python2.2-tk DPKG is earlier than 2.2.1-4.2' test_ref='oval:org.debian.oval:tst:398'/>
              <criterion comment='python2.2-dev DPKG is earlier than 2.2.1-4.2' test_ref='oval:org.debian.oval:tst:399'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:160' class='vulnerability'>
      <metadata>
        <title>insecure temporary file creation</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>scrollkeeper</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0662' ref_id='CVE-2002-0662'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-09-03</date>
          <moreinfo>
Spybreak discovered a problem in scrollkeeper, a free electronic
cataloging system for documentation.  The scrollkeeper-get-cl program
creates temporary files in an insecure manner in /tmp using guessable
filenames.  Since scrollkeeper is called automatically when a user
logs into a Gnome session, an attacker with local access can easily
create and overwrite files as another user.
This problem has been fixed in version 0.3.6-3.1 for the current
stable distribution (woody) and in version 0.3.11-2 for the unstable
distribution (sid).  The old stable distribution (potato) is not
affected, since it doesn't contain the scrollkeeper package.
We recommend that you upgrade your scrollkeeper packages immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libscrollkeeper0 DPKG is earlier than 0.3.6-3.1' test_ref='oval:org.debian.oval:tst:400'/>
            <criterion comment='libscrollkeeper-dev DPKG is earlier than 0.3.6-3.1' test_ref='oval:org.debian.oval:tst:401'/>
            <criterion comment='scrollkeeper DPKG is earlier than 0.3.6-3.1' test_ref='oval:org.debian.oval:tst:402'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:161' class='vulnerability'>
      <metadata>
        <title>privilege escalation</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>mantis</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1115' ref_id='CVE-2002-1115'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1116' ref_id='CVE-2002-1116'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-09-04</date>
          <moreinfo>
A problem with user privileges has been discovered in the Mantis
package, a PHP based bug tracking system.  The Mantis system didn't
check whether a user is permitted to view a bug, but displays it right
away if the user entered a valid bug id.
Another bug in Mantis caused the 'View Bugs' page to list bugs from
both public and private projects when no projects are accessible to
the current user.
These problems have been fixed in version 0.17.1-2.5 for the current
stable distribution (woody) and in version 0.17.5-2 for the unstable
distribution (sid).  The old stable distribution (potato) is not
affected, since it doesn't contain the mantis package.
Additional information:
We recommend that you upgrade your mantis packages.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='mantis DPKG is earlier than 0.17.1-2.5' test_ref='oval:org.debian.oval:tst:403'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:162' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>ethereal</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0834' ref_id='CVE-2002-0834'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-09-06</date>
          <moreinfo>
Ethereal developers discovered a buffer overflow in the ISIS protocol
dissector.  It may be possible to make Ethereal crash or hang by
injecting a purposefully malformed packet onto the wire, or by
convincing someone to read a malformed packet trace file.  It may be
possible to make Ethereal run arbitrary code by exploiting the buffer
and pointer problems.
This problem has been fixed in version 0.9.4-1woody2 for the current
stable distribution (woody), in version 0.8.0-4potato.1 for
the old stable distribution (potato) and in version 0.9.6-1 for the
unstable distribution (sid).
We recommend that you upgrade your ethereal packages.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='ethereal DPKG is earlier than 0.8.0-4potato.1' test_ref='oval:org.debian.oval:tst:404'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='ethereal-dev DPKG is earlier than 0.9.4-1woody2' test_ref='oval:org.debian.oval:tst:405'/>
              <criterion comment='ethereal-common DPKG is earlier than 0.9.4-1woody2' test_ref='oval:org.debian.oval:tst:406'/>
              <criterion comment='tethereal DPKG is earlier than 0.9.4-1woody2' test_ref='oval:org.debian.oval:tst:407'/>
              <criterion comment='ethereal DPKG is earlier than 0.9.4-1woody2' test_ref='oval:org.debian.oval:tst:408'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:163' class='vulnerability'>
      <metadata>
        <title>cross site scripting</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>mhonarc</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0738' ref_id='CVE-2002-0738'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-09-09</date>
          <moreinfo>
Jason Molenda and Hiromitsu Takagi
&lt;a href="http://online.securityfocus.com/archive/1/268455">found&lt;/a>
ways to exploit cross site
scripting bugs in mhonarc, a mail to HTML converter.  When processing
maliciously crafted mails of type text/html mhonarc does not
deactivate all scripting parts properly.  This is fixed in upstream
version 2.5.3.
If you are worried about security, it is recommended that you disable
support of text/html messages in your mail archives.  There is no
guarantee that the mhtxthtml.pl library is robust enough to eliminate
all possible exploits that can occur with HTML data.
To exclude HTML data, you can use the MIMEEXCS resource.  For example:
The type "text/x-html" is probably not used any more, but is good to
include it, just-in-case.
If you are concerned that this could block out the entire contents of
some messages, then you could do the following instead:
This treats the HTML as text/plain.
The above problems have been fixed in version 2.5.2-1.1 for the
current stable distribution (woody), in version 2.4.4-1.1 for
the old stable distribution (potato) and in version 2.5.11-1 for the
unstable distribution (sid).
We recommend that you upgrade your mhonarc packages.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criterion comment='mhonarc DPKG is earlier than 2.4.4-1.1' test_ref='oval:org.debian.oval:tst:409'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criterion comment='mhonarc DPKG is earlier than 2.5.2-1.1' test_ref='oval:org.debian.oval:tst:410'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:164' class='vulnerability'>
      <metadata>
        <title>arbitrary code execution</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>cacti</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1477' ref_id='CVE-2002-1477'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1478' ref_id='CVE-2002-1478'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-09-10</date>
          <moreinfo>
A problem in cacti, a PHP based frontend to rrdtool for monitoring
systems and services, has been discovered.  This could lead into cacti
executing arbitrary program code under the user id of the web server.
This problem, however, is only persistent to users who already have
administrator privileges in the cacti system.
This problem has been fixed by removing any dollar signs and backticks
from the title string in version 0.6.7-2.1 for the current stable
distribution (woody) and in version 0.6.8a-2 for the unstable
distribution (sid).  The old stable distribution (potato) is not
affected since it doesn't contain the cacti package.
We recommend that you upgrade your cacti package immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='cacti DPKG is earlier than 0.6.7-2.1' test_ref='oval:org.debian.oval:tst:411'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:165' class='vulnerability'>
      <metadata>
        <title>buffer overflows</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>postgresql</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0972' ref_id='CVE-2002-0972'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1398' ref_id='CVE-2002-1398'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1400' ref_id='CVE-2002-1400'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1401' ref_id='CVE-2002-1401'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1402' ref_id='CVE-2002-1402'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-09-12</date>
          <moreinfo>
Mordred Labs and others found several vulnerabilities in PostgreSQL,
an object-relational SQL database.  They are inherited from several
buffer overflows and integer overflows.  Specially crafted long date
and time input, currency, repeat data and long timezone names could
cause the PostgreSQL server to crash as well as specially crafted
input data for lpad() and rpad().  More buffer/integer overflows were
found in circle_poly(), path_encode() and path_addr().
Except for the last three, these problems are fixed in the upstream
release 7.2.2 of PostgreSQL which is the recommended version to use.
Most of these problems do not exist in the version of PostgreSQL that
Debian ships in the potato release since the corresponding
functionality is not yet implemented.  However, PostgreSQL 6.5.3 is
quite old and may bear more risks than we are aware of, which may
include further buffer overflows, and certainly include bugs that
threaten the integrity of your data.
You are strongly advised not to use this release but to upgrade your
system to Debian 3.0 (stable) including PostgreSQL release 7.2.1
instead, where many bugs have been fixed and new features introduced
to increase compatibility with the SQL standards.
If you consider an upgrade, please make sure to dump the entire
database system using the pg_dumpall utility.  Please take into
consideration that the newer PostgreSQL is more strict in its input
handling.  This means that tests like "foo = NULL" which are not valid
won't be accepted anymore.  It also means that when using UNICODE
encoding, ISO 8859-1 and ISO 8859-15 are no longer valid encodings to
use when inserting data into the relation.  In such a case you are
advised to convert the dump in question using
&lt;kbd>recode latin1..utf-16&lt;/kbd>.
These problems have been fixed in version 7.2.1-2woody2 for the
current stable distribution (woody) and in version 7.2.2-2 for the
unstable distribution (sid).  The old stable distribution (potato) is
partially affected and we ship a fixed version 6.5.3-27.2 for it.
We recommend that you upgrade your PostgreSQL packages.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criterion comment='postgresql-doc DPKG is earlier than 6.5.3-27.2' test_ref='oval:org.debian.oval:tst:412'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libpgsql2 DPKG is earlier than 6.5.3-27.2' test_ref='oval:org.debian.oval:tst:413'/>
              <criterion comment='libpgtcl DPKG is earlier than 6.5.3-27.2' test_ref='oval:org.debian.oval:tst:414'/>
              <criterion comment='postgresql DPKG is earlier than 6.5.3-27.2' test_ref='oval:org.debian.oval:tst:415'/>
              <criterion comment='pgaccess DPKG is earlier than 6.5.3-27.2' test_ref='oval:org.debian.oval:tst:416'/>
              <criterion comment='libpgperl DPKG is earlier than 6.5.3-27.2' test_ref='oval:org.debian.oval:tst:417'/>
              <criterion comment='odbc-postgresql DPKG is earlier than 6.5.3-27.2' test_ref='oval:org.debian.oval:tst:418'/>
              <criterion comment='postgresql-contrib DPKG is earlier than 6.5.3-27.2' test_ref='oval:org.debian.oval:tst:419'/>
              <criterion comment='postgresql-pl DPKG is earlier than 6.5.3-27.2' test_ref='oval:org.debian.oval:tst:420'/>
              <criterion comment='postgresql-test DPKG is earlier than 6.5.3-27.2' test_ref='oval:org.debian.oval:tst:421'/>
              <criterion comment='python-pygresql DPKG is earlier than 6.5.3-27.2' test_ref='oval:org.debian.oval:tst:422'/>
              <criterion comment='postgresql-dev DPKG is earlier than 6.5.3-27.2' test_ref='oval:org.debian.oval:tst:423'/>
              <criterion comment='postgresql-client DPKG is earlier than 6.5.3-27.2' test_ref='oval:org.debian.oval:tst:424'/>
              <criterion comment='ecpg DPKG is earlier than 6.5.3-27.2' test_ref='oval:org.debian.oval:tst:425'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criterion comment='postgresql-doc DPKG is earlier than 7.2.1-2woody2' test_ref='oval:org.debian.oval:tst:426'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libpgsql2 DPKG is earlier than 7.2.1-2woody2' test_ref='oval:org.debian.oval:tst:427'/>
              <criterion comment='libpgtcl DPKG is earlier than 7.2.1-2woody2' test_ref='oval:org.debian.oval:tst:428'/>
              <criterion comment='postgresql DPKG is earlier than 7.2.1-2woody2' test_ref='oval:org.debian.oval:tst:429'/>
              <criterion comment='pgaccess DPKG is earlier than 7.2.1-2woody2' test_ref='oval:org.debian.oval:tst:430'/>
              <criterion comment='courier-authpostgresql DPKG is earlier than 0.37.3-3.1' test_ref='oval:org.debian.oval:tst:431'/>
              <criterion comment='postgresql-contrib DPKG is earlier than 7.2.1-2woody2' test_ref='oval:org.debian.oval:tst:432'/>
              <criterion comment='odbc-postgresql DPKG is earlier than 7.2.1-2woody2' test_ref='oval:org.debian.oval:tst:433'/>
              <criterion comment='libecpg3 DPKG is earlier than 7.2.1-2woody2' test_ref='oval:org.debian.oval:tst:434'/>
              <criterion comment='libpgperl DPKG is earlier than 7.2.1-2woody2' test_ref='oval:org.debian.oval:tst:435'/>
              <criterion comment='python-pygresql DPKG is earlier than 7.2.1-2woody2' test_ref='oval:org.debian.oval:tst:436'/>
              <criterion comment='postgresql-dev DPKG is earlier than 7.2.1-2woody2' test_ref='oval:org.debian.oval:tst:437'/>
              <criterion comment='postgresql-client DPKG is earlier than 7.2.1-2woody2' test_ref='oval:org.debian.oval:tst:438'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:166' class='vulnerability'>
      <metadata>
        <title>buffer overflows</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>purity</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1124' ref_id='CVE-2002-1124'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-09-13</date>
          <moreinfo>
Two buffer overflows have been discovered in purity, a game for nerds
and hackers, which is installed setgid games on a Debian system.  This
problem could be exploited to gain unauthorized access to the group
games.  A malicious user could alter the highscore of several games.
This problem has been fixed in version 1-14.2 for the current stable
distribution (woody), in version 1-9.1 for the old stable distribution
(potato) and in version 1-16 for the unstable distribution (sid).
We recommend that you upgrade your purity packages.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='purity DPKG is earlier than 1-9.1' test_ref='oval:org.debian.oval:tst:439'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='purity DPKG is earlier than 1-14.2' test_ref='oval:org.debian.oval:tst:440'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:167' class='vulnerability'>
      <metadata>
        <title>cross site scripting</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>Konquerer</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1151' ref_id='CVE-2002-1151'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-09-16</date>
          <moreinfo>
A cross site scripting problem has been discovered in Konqueror, a
famous browser for KDE and other programs using KHTML.  The KDE team
&lt;a href="http://www.kde.org/info/security/advisory-20020908-2.txt">reports&lt;/a>
that Konqueror's cross site scripting protection fails to
initialize the domains on sub-(i)frames correctly.  As a result,
JavaScript is able to access any foreign subframe which is defined in
the HTML source.  Users of Konqueror and other KDE software that uses
the KHTML rendering engine may become victim of a cookie stealing and
other cross site scripting attacks.
This problem has been fixed in version 2.2.2-13.woody.3 for the
current stable distribution (woody) and in version 2.2.2-14 for the
unstable distribution (sid).  The old stable distribution (potato) is
not affected since it didn't ship KDE.
We recommend that you upgrade your kdelibs package and restart
Konqueror.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='kdelibs3-doc DPKG is earlier than 2.2.2-13.woody.3' test_ref='oval:org.debian.oval:tst:441'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libarts DPKG is earlier than 2.2.2-13.woody.3' test_ref='oval:org.debian.oval:tst:442'/>
            <criterion comment='libkmid-alsa DPKG is earlier than 2.2.2-13.woody.3' test_ref='oval:org.debian.oval:tst:443'/>
            <criterion comment='kdelibs3-bin DPKG is earlier than 2.2.2-13.woody.3' test_ref='oval:org.debian.oval:tst:444'/>
            <criterion comment='libarts-alsa DPKG is earlier than 2.2.2-13.woody.3' test_ref='oval:org.debian.oval:tst:445'/>
            <criterion comment='kdelibs3 DPKG is earlier than 2.2.2-13.woody.3' test_ref='oval:org.debian.oval:tst:446'/>
            <criterion comment='kdelibs3-cups DPKG is earlier than 2.2.2-13.woody.3' test_ref='oval:org.debian.oval:tst:447'/>
            <criterion comment='libkmid-dev DPKG is earlier than 2.2.2-13.woody.3' test_ref='oval:org.debian.oval:tst:448'/>
            <criterion comment='libkmid DPKG is earlier than 2.2.2-13.woody.3' test_ref='oval:org.debian.oval:tst:449'/>
            <criterion comment='libarts-dev DPKG is earlier than 2.2.2-13.woody.3' test_ref='oval:org.debian.oval:tst:450'/>
            <criterion comment='kdelibs-dev DPKG is earlier than 2.2.2-13.woody.3' test_ref='oval:org.debian.oval:tst:451'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:168' class='vulnerability'>
      <metadata>
        <title>bypassing safe_mode, CRLF injection</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>PHP3, PHP4</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0985' ref_id='CVE-2002-0985'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0986' ref_id='CVE-2002-0986'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1783' ref_id='CVE-2002-1783'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-09-18</date>
          <moreinfo>
Wojciech Purczynski found out that it is possible for scripts to pass
arbitrary text to sendmail as commandline extension when sending a
mail through PHP even when safe_mode is turned on.  Passing 5th
argument should be disabled if PHP is configured in safe_mode, which
is the case for newer PHP versions and for the versions below.  This
does not affect PHP3, though.
Wojciech Purczynski also found out that arbitrary ASCII control
characters may be injected into string arguments of the mail() function.
If mail() arguments are taken from user's input it may give the user
ability to alter message content including mail headers.
Ulf Härnhammar discovered that file() and fopen() are vulnerable to
CRLF injection.  An attacker could use it to escape certain
restrictions and add arbitrary text to alleged HTTP requests that are
passed through.
However this only happens if something is passed to these functions
which is neither a valid file name nor a valid url.  Any string that
contains control chars cannot be a valid url.  Before you pass a
string that should be a url to any function you must use urlencode()
to encode it.
Three problems have been identified in PHP:
These problems have been fixed in version 3.0.18-23.1woody1 for PHP3
and 4.1.2-5 for PHP4 for the current stable distribution (woody), in
version 3.0.18-0potato1.2 for PHP3 and 4.0.3pl1-0potato4 for PHP4 in
the old stable distribution (potato) and in version 3.0.18-23.2 for
PHP3 and 4.2.3-3 for PHP4 for the unstable distribution (sid).
We recommend that you upgrade your PHP packages.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='php4-dev DPKG is earlier than 4.0.3pl1-0potato4' test_ref='oval:org.debian.oval:tst:452'/>
                <criterion comment='php3-doc DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:453'/>
              </criteria>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:18'/>
                <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:19'/>
                <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:20'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:21'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:30'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='php4-cgi-mhash DPKG is earlier than 4.0.3pl1-0potato4' test_ref='oval:org.debian.oval:tst:454'/>
                <criterion comment='php3-cgi-snmp DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:455'/>
                <criterion comment='php4-cgi-pgsql DPKG is earlier than 4.0.3pl1-0potato4' test_ref='oval:org.debian.oval:tst:456'/>
                <criterion comment='php3-snmp DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:457'/>
                <criterion comment='php3-magick DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:458'/>
                <criterion comment='php4-cgi-ldap DPKG is earlier than 4.0.3pl1-0potato4' test_ref='oval:org.debian.oval:tst:459'/>
                <criterion comment='php4-mhash DPKG is earlier than 4.0.3pl1-0potato4' test_ref='oval:org.debian.oval:tst:460'/>
                <criterion comment='php3-cgi-pgsql DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:461'/>
                <criterion comment='php3-cgi-ldap DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:462'/>
                <criterion comment='php4-cgi-imap DPKG is earlier than 4.0.3pl1-0potato4' test_ref='oval:org.debian.oval:tst:463'/>
                <criterion comment='php3-dev DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:464'/>
                <criterion comment='php3-cgi DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:465'/>
                <criterion comment='php4-mysql DPKG is earlier than 4.0.3pl1-0potato4' test_ref='oval:org.debian.oval:tst:466'/>
                <criterion comment='php3-cgi-imap DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:467'/>
                <criterion comment='php4 DPKG is earlier than 4.0.3pl1-0potato4' test_ref='oval:org.debian.oval:tst:468'/>
                <criterion comment='php4-imap DPKG is earlier than 4.0.3pl1-0potato4' test_ref='oval:org.debian.oval:tst:469'/>
                <criterion comment='php4-cgi DPKG is earlier than 4.0.3pl1-0potato4' test_ref='oval:org.debian.oval:tst:470'/>
                <criterion comment='php3 DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:471'/>
                <criterion comment='php4-pgsql DPKG is earlier than 4.0.3pl1-0potato4' test_ref='oval:org.debian.oval:tst:472'/>
                <criterion comment='php3-mhash DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:473'/>
                <criterion comment='php4-snmp DPKG is earlier than 4.0.3pl1-0potato4' test_ref='oval:org.debian.oval:tst:474'/>
                <criterion comment='php3-pgsql DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:475'/>
                <criterion comment='php4-ldap DPKG is earlier than 4.0.3pl1-0potato4' test_ref='oval:org.debian.oval:tst:476'/>
                <criterion comment='php4-xml DPKG is earlier than 4.0.3pl1-0potato4' test_ref='oval:org.debian.oval:tst:477'/>
                <criterion comment='php3-cgi-xml DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:478'/>
                <criterion comment='php3-mysql DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:479'/>
                <criterion comment='php3-gd DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:480'/>
                <criterion comment='php3-xml DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:481'/>
                <criterion comment='php3-cgi-mhash DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:482'/>
                <criterion comment='php4-cgi-xml DPKG is earlier than 4.0.3pl1-0potato4' test_ref='oval:org.debian.oval:tst:483'/>
                <criterion comment='php3-cgi-magick DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:484'/>
                <criterion comment='php4-cgi-snmp DPKG is earlier than 4.0.3pl1-0potato4' test_ref='oval:org.debian.oval:tst:485'/>
                <criterion comment='php4-gd DPKG is earlier than 4.0.3pl1-0potato4' test_ref='oval:org.debian.oval:tst:486'/>
                <criterion comment='php4-cgi-gd DPKG is earlier than 4.0.3pl1-0potato4' test_ref='oval:org.debian.oval:tst:487'/>
                <criterion comment='php3-imap DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:488'/>
                <criterion comment='php3-ldap DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:489'/>
                <criterion comment='php3-cgi-gd DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:490'/>
                <criterion comment='php3-cgi-mysql DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:491'/>
                <criterion comment='php4-cgi-mysql DPKG is earlier than 4.0.3pl1-0potato4' test_ref='oval:org.debian.oval:tst:492'/>
              </criteria>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:22'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='php3-dev DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:493'/>
                <criterion comment='php3-xml DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:494'/>
                <criterion comment='php3-cgi-mhash DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:495'/>
                <criterion comment='php3-pgsql DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:496'/>
                <criterion comment='php3-cgi-snmp DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:497'/>
                <criterion comment='php3-cgi DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:498'/>
                <criterion comment='php3-magick DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:499'/>
                <criterion comment='php3-mysql DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:500'/>
                <criterion comment='php3-cgi-magick DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:501'/>
                <criterion comment='php3-snmp DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:502'/>
                <criterion comment='php3-cgi-xml DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:503'/>
                <criterion comment='php3-mhash DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:504'/>
                <criterion comment='php3-cgi-imap DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:505'/>
                <criterion comment='php3-ldap DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:506'/>
                <criterion comment='php3-imap DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:507'/>
                <criterion comment='php3-cgi-gd DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:508'/>
                <criterion comment='php3-cgi-pgsql DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:509'/>
                <criterion comment='php3-cgi-mysql DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:510'/>
                <criterion comment='php3-gd DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:511'/>
                <criterion comment='php3-cgi-ldap DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:512'/>
                <criterion comment='php3 DPKG is earlier than 3.0.18-0potato1.2' test_ref='oval:org.debian.oval:tst:513'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='php4-pear DPKG is earlier than 4.1.2-5' test_ref='oval:org.debian.oval:tst:514'/>
                <criterion comment='php4-dev DPKG is earlier than 4.1.2-5' test_ref='oval:org.debian.oval:tst:515'/>
                <criterion comment='php3-doc DPKG is earlier than 3.0.18-23.1woody1' test_ref='oval:org.debian.oval:tst:516'/>
              </criteria>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='php3-cgi-snmp DPKG is earlier than 3.0.18-23.1woody1' test_ref='oval:org.debian.oval:tst:517'/>
              <criterion comment='php4-recode DPKG is earlier than 4.1.2-5' test_ref='oval:org.debian.oval:tst:518'/>
              <criterion comment='php4-xslt DPKG is earlier than 4.1.2-5' test_ref='oval:org.debian.oval:tst:519'/>
              <criterion comment='php3-snmp DPKG is earlier than 3.0.18-23.1woody1' test_ref='oval:org.debian.oval:tst:520'/>
              <criterion comment='php3-cgi-xml DPKG is earlier than 3.0.18-23.1woody1' test_ref='oval:org.debian.oval:tst:521'/>
              <criterion comment='php4-mcal DPKG is earlier than 4.1.2-5' test_ref='oval:org.debian.oval:tst:522'/>
              <criterion comment='php4-domxml DPKG is earlier than 4.1.2-5' test_ref='oval:org.debian.oval:tst:523'/>
              <criterion comment='php4-mhash DPKG is earlier than 4.1.2-5' test_ref='oval:org.debian.oval:tst:524'/>
              <criterion comment='php4-snmp DPKG is earlier than 4.1.2-5' test_ref='oval:org.debian.oval:tst:525'/>
              <criterion comment='php3-cgi-ldap DPKG is earlier than 3.0.18-23.1woody1' test_ref='oval:org.debian.oval:tst:526'/>
              <criterion comment='php3-dev DPKG is earlier than 3.0.18-23.1woody1' test_ref='oval:org.debian.oval:tst:527'/>
              <criterion comment='php3-cgi DPKG is earlier than 3.0.18-23.1woody1' test_ref='oval:org.debian.oval:tst:528'/>
              <criterion comment='caudium-php4 DPKG is earlier than 4.1.2-5' test_ref='oval:org.debian.oval:tst:529'/>
              <criterion comment='php4-mysql DPKG is earlier than 4.1.2-5' test_ref='oval:org.debian.oval:tst:530'/>
              <criterion comment='php3-cgi-imap DPKG is earlier than 3.0.18-23.1woody1' test_ref='oval:org.debian.oval:tst:531'/>
              <criterion comment='php4 DPKG is earlier than 4.1.2-5' test_ref='oval:org.debian.oval:tst:532'/>
              <criterion comment='php4-imap DPKG is earlier than 4.1.2-5' test_ref='oval:org.debian.oval:tst:533'/>
              <criterion comment='php4-cgi DPKG is earlier than 4.1.2-5' test_ref='oval:org.debian.oval:tst:534'/>
              <criterion comment='php3 DPKG is earlier than 3.0.18-23.1woody1' test_ref='oval:org.debian.oval:tst:535'/>
              <criterion comment='php3-mhash DPKG is earlier than 3.0.18-23.1woody1' test_ref='oval:org.debian.oval:tst:536'/>
              <criterion comment='php4-odbc DPKG is earlier than 4.1.2-5' test_ref='oval:org.debian.oval:tst:537'/>
              <criterion comment='php4-ldap DPKG is earlier than 4.1.2-5' test_ref='oval:org.debian.oval:tst:538'/>
              <criterion comment='php4-curl DPKG is earlier than 4.1.2-5' test_ref='oval:org.debian.oval:tst:539'/>
              <criterion comment='php3-magick DPKG is earlier than 3.0.18-23.1woody1' test_ref='oval:org.debian.oval:tst:540'/>
              <criterion comment='php3-mysql DPKG is earlier than 3.0.18-23.1woody1' test_ref='oval:org.debian.oval:tst:541'/>
              <criterion comment='php3-gd DPKG is earlier than 3.0.18-23.1woody1' test_ref='oval:org.debian.oval:tst:542'/>
              <criterion comment='php3-xml DPKG is earlier than 3.0.18-23.1woody1' test_ref='oval:org.debian.oval:tst:543'/>
              <criterion comment='php4-sybase DPKG is earlier than 4.1.2-5' test_ref='oval:org.debian.oval:tst:544'/>
              <criterion comment='php3-cgi-mhash DPKG is earlier than 3.0.18-23.1woody1' test_ref='oval:org.debian.oval:tst:545'/>
              <criterion comment='php3-cgi-magick DPKG is earlier than 3.0.18-23.1woody1' test_ref='oval:org.debian.oval:tst:546'/>
              <criterion comment='php4-gd DPKG is earlier than 4.1.2-5' test_ref='oval:org.debian.oval:tst:547'/>
              <criterion comment='php3-imap DPKG is earlier than 3.0.18-23.1woody1' test_ref='oval:org.debian.oval:tst:548'/>
              <criterion comment='php3-ldap DPKG is earlier than 3.0.18-23.1woody1' test_ref='oval:org.debian.oval:tst:549'/>
              <criterion comment='php3-cgi-gd DPKG is earlier than 3.0.18-23.1woody1' test_ref='oval:org.debian.oval:tst:550'/>
              <criterion comment='php3-cgi-mysql DPKG is earlier than 3.0.18-23.1woody1' test_ref='oval:org.debian.oval:tst:551'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:169' class='vulnerability'>
      <metadata>
        <title>cross site scripting</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>htcheck</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1195' ref_id='CVE-2002-1195'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-09-25</date>
          <moreinfo>
Ulf Härnhammar
&lt;a href="http://marc.theaimsgroup.com/?l=bugtraq&amp;amp;m=103184269605160">\
discovered&lt;/a> a problem in ht://Check's PHP interface.
The PHP interface displays information unchecked which was gathered
from crawled external web servers.  This could lead into a cross site
scripting attack if somebody has control over the server responses of
a remote web server which is crawled by ht://Check.
This problem has been fixed in version 1.1-1.1 for the current stable
distribution (woody) and in version 1.1-1.2 for the unstable release
(sid).  The old stable release (potato) does not contain the htcheck
package.
We recommend that you upgrade your htcheck package immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='htcheck-php DPKG is earlier than 1.1-1.1' test_ref='oval:org.debian.oval:tst:552'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='htcheck DPKG is earlier than 1.1-1.1' test_ref='oval:org.debian.oval:tst:553'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:170' class='vulnerability'>
      <metadata>
        <title>source code disclosure</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>tomcat4</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1148' ref_id='CVE-2002-1148'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-10-04</date>
          <moreinfo>
A security vulnerability has been found in all Tomcat 4.x releases.
This problem allows an attacker to use a specially crafted URL to
return the unprocessed source code of a JSP page, or, under special
circumstances, a static resource which would otherwise have been
protected by security constraints, without the need for being properly
authenticated.
This problem has been fixed in version 4.0.3-3woody1 for the current
stable distribution (woody) and in version 4.1.12-1 for the unstable
release (sid).  The old stable release (potato) does not contain
tomcat packages.  Also, packages for tomcat3 are not vulnerable to
this problem.
We recommend that you upgrade your tomcat package immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='tomcat4-webapps DPKG is earlier than 4.0.3-3woody1' test_ref='oval:org.debian.oval:tst:554'/>
              <criterion comment='libtomcat4-java DPKG is earlier than 4.0.3-3woody1' test_ref='oval:org.debian.oval:tst:555'/>
              <criterion comment='tomcat4 DPKG is earlier than 4.0.3-3woody1' test_ref='oval:org.debian.oval:tst:556'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:171' class='vulnerability'>
      <metadata>
        <title>buffer overflows</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>fetchmail, fetchmail-ssl</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1175' ref_id='CVE-2002-1175'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1174' ref_id='CVE-2002-1174'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-10-07</date>
          <moreinfo>
Stefan Esser &lt;a href="http://security.e-matters.de/advisories/032002.html">\
discovered&lt;/a> several buffer overflows and a broken boundary
check within fetchmail.  If fetchmail is running in multidrop mode
these flaws can be used by remote attackers to crash it or to execute
arbitrary code under the user id of the user running fetchmail.
Depending on the configuration this even allows a remote root
compromise.
These problems have been fixed in version 5.9.11-6.1 for both
fetchmail and fetchmail-ssl for the current stable distribution
(woody), in version 5.3.3-4.2 for fetchmail for the old stable
distribution (potato) and in version 6.1.0-1 for both fetchmail and
fetchmail-ssl for the unstable distribution (sid).  There are no
fetchmail-ssl packages for the old stable distribution (potato) and
thus no updates.
We recommend that you upgrade your fetchmail packages immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criterion comment='fetchmailconf DPKG is earlier than 5.3.3-4.2' test_ref='oval:org.debian.oval:tst:557'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='fetchmail DPKG is earlier than 5.3.3-4.2' test_ref='oval:org.debian.oval:tst:558'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='fetchmail-common DPKG is earlier than 5.9.11-6.1' test_ref='oval:org.debian.oval:tst:559'/>
                <criterion comment='fetchmailconf DPKG is earlier than 5.9.11-6.1' test_ref='oval:org.debian.oval:tst:560'/>
              </criteria>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='fetchmail DPKG is earlier than 5.9.11-6.1' test_ref='oval:org.debian.oval:tst:561'/>
              <criterion comment='fetchmail-ssl DPKG is earlier than 5.9.11-6.1' test_ref='oval:org.debian.oval:tst:562'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:172' class='vulnerability'>
      <metadata>
        <title>insecure temporary files</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>tkmail</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1193' ref_id='CVE-2002-1193'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-10-08</date>
          <moreinfo>
It has been discovered that tkmail creates temporary files insecurely.
Exploiting this an attacker with local access can easily create and
overwrite files as another user.
This problem has been fixed in version 4.0beta9-8.1 for the current
stable distribution (woody), in version 4.0beta9-4.1 for the old
stable distribution (potato) and in version 4.0beta9-9 for the
unstable distribution (sid).
We recommend that you upgrade your tkmail packages.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='tkmail DPKG is earlier than 4.0beta9-4.1' test_ref='oval:org.debian.oval:tst:563'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='tkmail DPKG is earlier than 4.0beta9-8.1' test_ref='oval:org.debian.oval:tst:564'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:173' class='vulnerability'>
      <metadata>
        <title>privilege escalation</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>bugzilla</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1196' ref_id='CVE-2002-1196'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-10-09</date>
          <moreinfo>
The developers of Bugzilla, a web-based bug tracking system,
discovered a problem in the handling of more than 47 groups.  When a
new product is added to an installation with 47 groups or more and
"usebuggroups" is enabled, the new group will be assigned a groupset
bit using Perl math that is not exact beyond 2&lt;sup>48&lt;/sup>.
This results in
the new group being defined with a "bit" that has several bits set.
As users are given access to the new group, those users will also gain
access to spurious lower group privileges.  Also, group bits were not
always reused when groups were deleted.
This problem has been fixed in version 2.14.2-0woody2 for the current
stable distribution (woody) and will soon be fixed in the unstable
distribution (sid).  The old stable distribution (potato) doesn't
contain a bugzilla package.
We recommend that you upgrade your bugzilla package.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='bugzilla DPKG is earlier than 2.14.2-0woody2' test_ref='oval:org.debian.oval:tst:565'/>
              <criterion comment='bugzilla-doc DPKG is earlier than 2.14.2-0woody2' test_ref='oval:org.debian.oval:tst:566'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:174' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>heartbeat</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1215' ref_id='CVE-2002-1215'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-10-14</date>
          <moreinfo>
Nathan Wallwork &lt;a href="http://linux-ha.org/security/sec01.txt">\
discovered&lt;/a> a buffer overflow in heartbeat, a subsystem
for High-Availability Linux.  A remote attacker could send a specially
crafted UDP packet that overflows a buffer, leaving heartbeat to
execute arbitrary code as root.
This problem has been fixed in version 0.4.9.0l-7.2 for the current
stable distribution (woody) and version 0.4.9.2-1 for the unstable
distribution (sid).  The old stable distribution (potato) doesn't
contain a heartbeat package.
We recommend that you upgrade your heartbeat package immediately if
you run internet connected servers that are heartbeat-monitored.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='ldirectord DPKG is earlier than 0.4.9.0l-7.2' test_ref='oval:org.debian.oval:tst:567'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libstonith-dev DPKG is earlier than 0.4.9.0l-7.2' test_ref='oval:org.debian.oval:tst:568'/>
            <criterion comment='heartbeat DPKG is earlier than 0.4.9.0l-7.2' test_ref='oval:org.debian.oval:tst:569'/>
            <criterion comment='stonith DPKG is earlier than 0.4.9.0l-7.2' test_ref='oval:org.debian.oval:tst:570'/>
            <criterion comment='libstonith0 DPKG is earlier than 0.4.9.0l-7.2' test_ref='oval:org.debian.oval:tst:571'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:175' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>syslog-ng</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1200' ref_id='CVE-2002-1200'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-10-15</date>
          <moreinfo>
Balazs Scheidler &lt;a href="http://www.balabit.hu/static/zsa/ZSA-2002-014-en.txt">\
discovered&lt;/a> a problem in the way syslog-ng handles macro
expansion.  When a macro is expanded a static length buffer is used
accompanied by a counter.  However, when constant characters are
appended, the counter is not updated properly, leading to incorrect
boundary checking.  An attacker may be able to use specially crafted
log messages inserted via UDP which overflows the buffer.
This problem has been fixed in version 1.5.15-1.1 for the current
stable distribution (woody), in version 1.4.0rc3-3.2 for the old
stable distribution (potato) and version 1.5.21-1 for the unstable
distribution (sid).
We recommend that you upgrade your syslog-ng package immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='syslog-ng DPKG is earlier than 1.4.0rc3-3.2' test_ref='oval:org.debian.oval:tst:572'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='syslog-ng DPKG is earlier than 1.5.15-1.1' test_ref='oval:org.debian.oval:tst:573'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:176' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>gv</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0838' ref_id='CVE-2002-0838'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-10-16</date>
          <moreinfo>
Zen-parse discovered a buffer overflow in gv, a PostScript and PDF
viewer for X11.  This problem is triggered by scanning the PostScript
file and can be exploited by an attacker sending a malformed
PostScript or PDF file.  The attacker is able to cause arbitrary code
to be run with the privileges of the victim.
This problem has been fixed in version 3.5.8-26.1 for the current
stable distribution (woody), in version 3.5.8-17.1 for the old stable
distribution (potato) and version 3.5.8-27 for the unstable
distribution (sid).
We recommend that you upgrade your gv package.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='gv DPKG is earlier than 3.5.8-17.1' test_ref='oval:org.debian.oval:tst:574'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='gv DPKG is earlier than 3.5.8-26.1' test_ref='oval:org.debian.oval:tst:575'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:178' class='vulnerability'>
      <metadata>
        <title>remote command execution</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>heimdal</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1225' ref_id='CVE-2002-1225'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1226' ref_id='CVE-2002-1226'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-10-17</date>
          <moreinfo>
The SuSE Security Team has reviewed critical parts of the Heimdal
package such as the kadmind and kdc server.  While doing so several
potential buffer overflows and other bugs have been uncovered and
fixed.  Remote attackers can probably gain remote root access on
systems without fixes.  Since these services usually run on
authentication servers these bugs are considered very serious.
These problems have been fixed in version 0.4e-7.woody.4 for the
current stable distribution (woody), in version 0.2l-7.4 for the old
stable distribution (potato) and version 0.4e-21 for the unstable
distribution (sid).
We recommend that you upgrade your Heimdal packages immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criterion comment='heimdal-docs DPKG is earlier than 0.2l-7.4' test_ref='oval:org.debian.oval:tst:576'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='heimdal-dev DPKG is earlier than 0.2l-7.4' test_ref='oval:org.debian.oval:tst:577'/>
              <criterion comment='heimdal-servers-x DPKG is earlier than 0.2l-7.4' test_ref='oval:org.debian.oval:tst:578'/>
              <criterion comment='heimdal-lib DPKG is earlier than 0.2l-7.4' test_ref='oval:org.debian.oval:tst:579'/>
              <criterion comment='heimdal-servers DPKG is earlier than 0.2l-7.4' test_ref='oval:org.debian.oval:tst:580'/>
              <criterion comment='heimdal-clients-x DPKG is earlier than 0.2l-7.4' test_ref='oval:org.debian.oval:tst:581'/>
              <criterion comment='heimdal-kdc DPKG is earlier than 0.2l-7.4' test_ref='oval:org.debian.oval:tst:582'/>
              <criterion comment='heimdal-clients DPKG is earlier than 0.2l-7.4' test_ref='oval:org.debian.oval:tst:583'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='heimdal-lib DPKG is earlier than 0.4e-7.woody.4' test_ref='oval:org.debian.oval:tst:584'/>
                <criterion comment='heimdal-docs DPKG is earlier than 0.4e-7.woody.4' test_ref='oval:org.debian.oval:tst:585'/>
              </criteria>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libroken9-heimdal DPKG is earlier than 0.4e-7.woody.4' test_ref='oval:org.debian.oval:tst:586'/>
              <criterion comment='heimdal-clients DPKG is earlier than 0.4e-7.woody.4' test_ref='oval:org.debian.oval:tst:587'/>
              <criterion comment='libotp0-heimdal DPKG is earlier than 0.4e-7.woody.4' test_ref='oval:org.debian.oval:tst:588'/>
              <criterion comment='heimdal-servers-x DPKG is earlier than 0.4e-7.woody.4' test_ref='oval:org.debian.oval:tst:589'/>
              <criterion comment='libkadm5clnt4-heimdal DPKG is earlier than 0.4e-7.woody.4' test_ref='oval:org.debian.oval:tst:590'/>
              <criterion comment='heimdal-dev DPKG is earlier than 0.4e-7.woody.4' test_ref='oval:org.debian.oval:tst:591'/>
              <criterion comment='libkafs0-heimdal DPKG is earlier than 0.4e-7.woody.4' test_ref='oval:org.debian.oval:tst:592'/>
              <criterion comment='libkadm5srv7-heimdal DPKG is earlier than 0.4e-7.woody.4' test_ref='oval:org.debian.oval:tst:593'/>
              <criterion comment='heimdal-servers DPKG is earlier than 0.4e-7.woody.4' test_ref='oval:org.debian.oval:tst:594'/>
              <criterion comment='heimdal-clients-x DPKG is earlier than 0.4e-7.woody.4' test_ref='oval:org.debian.oval:tst:595'/>
              <criterion comment='libgssapi1-heimdal DPKG is earlier than 0.4e-7.woody.4' test_ref='oval:org.debian.oval:tst:596'/>
              <criterion comment='libss0-heimdal DPKG is earlier than 0.4e-7.woody.4' test_ref='oval:org.debian.oval:tst:597'/>
              <criterion comment='libhdb7-heimdal DPKG is earlier than 0.4e-7.woody.4' test_ref='oval:org.debian.oval:tst:598'/>
              <criterion comment='libsl0-heimdal DPKG is earlier than 0.4e-7.woody.4' test_ref='oval:org.debian.oval:tst:599'/>
              <criterion comment='libasn1-5-heimdal DPKG is earlier than 0.4e-7.woody.4' test_ref='oval:org.debian.oval:tst:600'/>
              <criterion comment='libkrb5-17-heimdal DPKG is earlier than 0.4e-7.woody.4' test_ref='oval:org.debian.oval:tst:601'/>
              <criterion comment='heimdal-kdc DPKG is earlier than 0.4e-7.woody.4' test_ref='oval:org.debian.oval:tst:602'/>
              <criterion comment='libcomerr1-heimdal DPKG is earlier than 0.4e-7.woody.4' test_ref='oval:org.debian.oval:tst:603'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:179' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>gnome-gv</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0838' ref_id='CVE-2002-0838'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-10-18</date>
          <moreinfo>
Zen-parse discovered a buffer overflow in gv, a PostScript and PDF
viewer for X11.  The same code is present in gnome-gv.  This problem
is triggered by scanning the PostScript file and can be exploited by
an attacker sending a malformed PostScript or PDF file.  The attacker
is able to cause arbitrary code to be run with the privileges of the
victim.
This problem has been fixed in version 1.1.96-3.1 for the current
stable distribution (woody), in version 0.82-2.1 for the old stable
distribution (potato) and version 1.99.7-9 for the unstable
distribution (sid).
We recommend that you upgrade your gnome-gv package.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='gnome-gv DPKG is earlier than 0.82-2.1' test_ref='oval:org.debian.oval:tst:604'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='gnome-gv DPKG is earlier than 1.1.96-3.1' test_ref='oval:org.debian.oval:tst:605'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:180' class='vulnerability'>
      <metadata>
        <title>information leak</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>nis</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1232' ref_id='CVE-2002-1232'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-10-21</date>
          <moreinfo>
Thorsten Kukuck discovered a problem in the ypserv program which is
part of the Network Information Services (NIS).  A memory leak in all
versions of ypserv prior to 2.5 is remotely exploitable.  When a
malicious user could request a non-existing map the server will leak
parts of an old domainname and mapname.
This problem has been fixed in version 3.9-6.1 for the current stable
distribution (woody), in version 3.8-2.1 for the old stable
distribution (potato) and in version 3.9-6.2 for the unstable
distribution (sid).
We recommend that you upgrade your nis package.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='nis DPKG is earlier than 3.8-2.1' test_ref='oval:org.debian.oval:tst:606'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='nis DPKG is earlier than 3.9-6.1' test_ref='oval:org.debian.oval:tst:607'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:181' class='vulnerability'>
      <metadata>
        <title>cross site scripting</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>libapache-mod-ssl</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1157' ref_id='CVE-2002-1157'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-10-22</date>
          <moreinfo>
Joe Orton discovered a cross site scripting problem in mod_ssl, an
Apache module that adds Strong cryptography (i.e. HTTPS support) to
the webserver.  The module will return the server name unescaped in
the response to an HTTP request on an SSL port.
Like the other recent Apache XSS bugs, this only affects servers using
a combination of "UseCanonicalName off" (default in the Debian package
of Apache) and wildcard DNS.  This is very unlikely to happen, though.
Apache 2.0/mod_ssl is not vulnerable since it already escapes this
HTML.
With this setting turned on, whenever Apache needs to construct a
self-referencing URL (a URL that refers back to the server the
response is coming from) it will use ServerName and Port to form a
"canonical" name.  With this setting off, Apache will use the
hostname:port that the client supplied, when possible.  This also
affects SERVER_NAME and SERVER_PORT in CGI scripts.
This problem has been fixed in version 2.8.9-2.1 for the current
stable distribution (woody), in version 2.4.10-1.3.9-1potato4 for the
old stable distribution (potato) and version 2.8.9-2.3 for the
unstable distribution (sid).
We recommend that you upgrade your libapache-mod-ssl package.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criterion comment='libapache-mod-ssl-doc DPKG is earlier than 2.4.10-1.3.9-1potato4' test_ref='oval:org.debian.oval:tst:608'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libapache-mod-ssl DPKG is earlier than 2.4.10-1.3.9-1potato4' test_ref='oval:org.debian.oval:tst:609'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criterion comment='libapache-mod-ssl-doc DPKG is earlier than 2.8.9-2.1' test_ref='oval:org.debian.oval:tst:610'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libapache-mod-ssl DPKG is earlier than 2.8.9-2.1' test_ref='oval:org.debian.oval:tst:611'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:182' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>kdegraphics</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0838' ref_id='CVE-2002-0838'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-10-28</date>
          <moreinfo>
Zen-parse discovered a buffer overflow in gv, a PostScript and PDF
viewer for X11.  The same code is present in kghostview which is part
of the KDE-Graphics package.  This problem is triggered by scanning
the PostScript file and can be exploited by an attacker sending a
malformed PostScript or PDF file.  The attacker is able to cause
arbitrary code to be run with the privileges of the victim.
This problem has been fixed in version 2.2.2-6.8 for the current
stable distribution (woody) and in version 2.2.2-6.9 for the unstable
distribution (sid).  The old stable distribution (potato) is not
affected since no KDE is included.
We recommend that you upgrade your kghostview package.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='ksnapshot DPKG is earlier than 2.2.2-6.8' test_ref='oval:org.debian.oval:tst:612'/>
            <criterion comment='kruler DPKG is earlier than 2.2.2-6.8' test_ref='oval:org.debian.oval:tst:613'/>
            <criterion comment='kiconedit DPKG is earlier than 2.2.2-6.8' test_ref='oval:org.debian.oval:tst:614'/>
            <criterion comment='kcoloredit DPKG is earlier than 2.2.2-6.8' test_ref='oval:org.debian.oval:tst:615'/>
            <criterion comment='kpaint DPKG is earlier than 2.2.2-6.8' test_ref='oval:org.debian.oval:tst:616'/>
            <criterion comment='kghostview DPKG is earlier than 2.2.2-6.8' test_ref='oval:org.debian.oval:tst:617'/>
            <criterion comment='kfract DPKG is earlier than 2.2.2-6.8' test_ref='oval:org.debian.oval:tst:618'/>
            <criterion comment='kview DPKG is earlier than 2.2.2-6.8' test_ref='oval:org.debian.oval:tst:619'/>
            <criterion comment='kamera DPKG is earlier than 2.2.2-6.8' test_ref='oval:org.debian.oval:tst:620'/>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:206'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:21'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:19'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:20'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:207'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:235'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:30'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:208'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:22'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kooka DPKG is earlier than 2.2.2-6.8' test_ref='oval:org.debian.oval:tst:621'/>
              <criterion comment='libkscan-dev DPKG is earlier than 2.2.2-6.8' test_ref='oval:org.debian.oval:tst:622'/>
              <criterion comment='libkscan1 DPKG is earlier than 2.2.2-6.8' test_ref='oval:org.debian.oval:tst:623'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:183' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>krb5</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1235' ref_id='CVE-2002-1235'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-10-29</date>
          <moreinfo>
Tom Yu and Sam Hartman of MIT discovered another stack buffer overflow
in the kadm_ser_wrap_in function in the Kerberos v4 administration
server.  This kadmind bug has a working exploit code circulating,
hence it is considered serious.  The MIT krb5 implementation
includes support for version 4, including a complete v4 library,
server side support for krb4, and limited client support for v4.
This problem has been fixed in version 1.2.4-5woody3 for the current
stable distribution (woody) and in version 1.2.6-2 for the unstable
distribution (sid).  The old stable distribution (potato) is not
affected since no krb5 packages are included.
We recommend that you upgrade your krb5 packages immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='krb5-doc DPKG is earlier than 1.2.4-5woody3' test_ref='oval:org.debian.oval:tst:624'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='krb5-rsh-server DPKG is earlier than 1.2.4-5woody3' test_ref='oval:org.debian.oval:tst:625'/>
            <criterion comment='ssh-krb5 DPKG is earlier than 3.4p1-0woody1' test_ref='oval:org.debian.oval:tst:626'/>
            <criterion comment='krb5-telnetd DPKG is earlier than 1.2.4-5woody3' test_ref='oval:org.debian.oval:tst:627'/>
            <criterion comment='libkrb5-dev DPKG is earlier than 1.2.4-5woody3' test_ref='oval:org.debian.oval:tst:628'/>
            <criterion comment='libkrb53 DPKG is earlier than 1.2.4-5woody3' test_ref='oval:org.debian.oval:tst:629'/>
            <criterion comment='krb5-ftpd DPKG is earlier than 1.2.4-5woody3' test_ref='oval:org.debian.oval:tst:630'/>
            <criterion comment='krb5-admin-server DPKG is earlier than 1.2.4-5woody3' test_ref='oval:org.debian.oval:tst:631'/>
            <criterion comment='libkadm55 DPKG is earlier than 1.2.4-5woody3' test_ref='oval:org.debian.oval:tst:632'/>
            <criterion comment='krb5-user DPKG is earlier than 1.2.4-5woody3' test_ref='oval:org.debian.oval:tst:633'/>
            <criterion comment='krb5-clients DPKG is earlier than 1.2.4-5woody3' test_ref='oval:org.debian.oval:tst:634'/>
            <criterion comment='libkrb5-17-heimdal DPKG is earlier than 0.4e-7.woody.4' test_ref='oval:org.debian.oval:tst:635'/>
            <criterion comment='krb5-kdc DPKG is earlier than 1.2.4-5woody3' test_ref='oval:org.debian.oval:tst:636'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:184' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>krb4</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1235' ref_id='CVE-2002-1235'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-10-30</date>
          <moreinfo>
Tom Yu and Sam Hartman of MIT discovered another stack buffer overflow
in the kadm_ser_wrap_in function in the Kerberos v4 administration
server.  This kadmind bug has a working exploit code circulating,
hence it is considered serious.
This problem has been fixed in version 1.1-8-2.2 for the current
stable distribution (woody), in version 1.0-2.2 for the old stable
distribution (potato) and in version 1.1-11-8 for the unstable
distribution (sid).
We recommend that you upgrade your krb4 packages immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:18'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:30'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:21'/>
                <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:22'/>
                <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:19'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='kerberos4kth1 DPKG is earlier than 1.0-2.2' test_ref='oval:org.debian.oval:tst:637'/>
                <criterion comment='kerberos4kth-user DPKG is earlier than 1.0-2.2' test_ref='oval:org.debian.oval:tst:638'/>
                <criterion comment='kerberos4kth-clients DPKG is earlier than 1.0-2.2' test_ref='oval:org.debian.oval:tst:639'/>
                <criterion comment='kerberos4kth-x11 DPKG is earlier than 1.0-2.2' test_ref='oval:org.debian.oval:tst:640'/>
                <criterion comment='kerberos4kth-services DPKG is earlier than 1.0-2.2' test_ref='oval:org.debian.oval:tst:641'/>
                <criterion comment='kerberos4kth-dev DPKG is earlier than 1.0-2.2' test_ref='oval:org.debian.oval:tst:642'/>
                <criterion comment='kerberos4kth-kdc DPKG is earlier than 1.0-2.2' test_ref='oval:org.debian.oval:tst:643'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='kerberos4kth1 DPKG is earlier than 1.1-8-2.2' test_ref='oval:org.debian.oval:tst:644'/>
                <criterion comment='kerberos4kth-docs DPKG is earlier than 1.1-8-2.2' test_ref='oval:org.debian.oval:tst:645'/>
                <criterion comment='kerberos4kth-services DPKG is earlier than 1.1-8-2.2' test_ref='oval:org.debian.oval:tst:646'/>
                <criterion comment='kerberos4kth-user DPKG is earlier than 1.1-8-2.2' test_ref='oval:org.debian.oval:tst:647'/>
                <criterion comment='kerberos4kth-x11 DPKG is earlier than 1.1-8-2.2' test_ref='oval:org.debian.oval:tst:648'/>
              </criteria>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libkdb-1-kerberos4kth DPKG is earlier than 1.1-8-2.2' test_ref='oval:org.debian.oval:tst:649'/>
              <criterion comment='kerberos4kth-servers DPKG is earlier than 1.1-8-2.2' test_ref='oval:org.debian.oval:tst:650'/>
              <criterion comment='kerberos4kth-clients DPKG is earlier than 1.1-8-2.2' test_ref='oval:org.debian.oval:tst:651'/>
              <criterion comment='libkadm1-kerberos4kth DPKG is earlier than 1.1-8-2.2' test_ref='oval:org.debian.oval:tst:652'/>
              <criterion comment='libacl1-kerberos4kth DPKG is earlier than 1.1-8-2.2' test_ref='oval:org.debian.oval:tst:653'/>
              <criterion comment='kerberos4kth-clients-x DPKG is earlier than 1.1-8-2.2' test_ref='oval:org.debian.oval:tst:654'/>
              <criterion comment='kerberos4kth-servers-x DPKG is earlier than 1.1-8-2.2' test_ref='oval:org.debian.oval:tst:655'/>
              <criterion comment='kerberos4kth-dev-common DPKG is earlier than 1.1-8-2.2' test_ref='oval:org.debian.oval:tst:656'/>
              <criterion comment='kerberos4kth-dev DPKG is earlier than 1.1-8-2.2' test_ref='oval:org.debian.oval:tst:657'/>
              <criterion comment='kerberos4kth-kdc DPKG is earlier than 1.1-8-2.2' test_ref='oval:org.debian.oval:tst:658'/>
              <criterion comment='libkrb-1-kerberos4kth DPKG is earlier than 1.1-8-2.2' test_ref='oval:org.debian.oval:tst:659'/>
              <criterion comment='kerberos4kth-kip DPKG is earlier than 1.1-8-2.2' test_ref='oval:org.debian.oval:tst:660'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:185' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>heimdal</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1235' ref_id='CVE-2002-1235'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-10-31</date>
          <moreinfo>
A stack buffer overflow in the kadm_ser_wrap_in function in the
Kerberos v4 administration server was discovered, which is provided by
Heimdal as well.  A working exploit for this kadmind bug is already
circulating, hence it is considered serious.  The broken library also
contains a vulnerability which could lead to another root exploit.
These problems have been fixed in version 0.4e-7.woody.5 for the
current stable distribution (woody), in version 0.2l-7.6 for the old
stable distribution (potato) and in version 0.4e-22 for the unstable
distribution (sid).
We recommend that you upgrade your heimdal packages immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criterion comment='heimdal-docs DPKG is earlier than 0.2l-7.6' test_ref='oval:org.debian.oval:tst:661'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='heimdal-dev DPKG is earlier than 0.2l-7.6' test_ref='oval:org.debian.oval:tst:662'/>
              <criterion comment='heimdal-servers-x DPKG is earlier than 0.2l-7.6' test_ref='oval:org.debian.oval:tst:663'/>
              <criterion comment='heimdal-lib DPKG is earlier than 0.2l-7.6' test_ref='oval:org.debian.oval:tst:664'/>
              <criterion comment='heimdal-servers DPKG is earlier than 0.2l-7.6' test_ref='oval:org.debian.oval:tst:665'/>
              <criterion comment='heimdal-clients-x DPKG is earlier than 0.2l-7.6' test_ref='oval:org.debian.oval:tst:666'/>
              <criterion comment='heimdal-kdc DPKG is earlier than 0.2l-7.6' test_ref='oval:org.debian.oval:tst:667'/>
              <criterion comment='heimdal-clients DPKG is earlier than 0.2l-7.6' test_ref='oval:org.debian.oval:tst:668'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='heimdal-lib DPKG is earlier than 0.4e-7.woody.5' test_ref='oval:org.debian.oval:tst:669'/>
                <criterion comment='heimdal-docs DPKG is earlier than 0.4e-7.woody.5' test_ref='oval:org.debian.oval:tst:670'/>
              </criteria>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libroken9-heimdal DPKG is earlier than 0.4e-7.woody.5' test_ref='oval:org.debian.oval:tst:671'/>
              <criterion comment='heimdal-clients DPKG is earlier than 0.4e-7.woody.5' test_ref='oval:org.debian.oval:tst:672'/>
              <criterion comment='libotp0-heimdal DPKG is earlier than 0.4e-7.woody.5' test_ref='oval:org.debian.oval:tst:673'/>
              <criterion comment='heimdal-servers-x DPKG is earlier than 0.4e-7.woody.5' test_ref='oval:org.debian.oval:tst:674'/>
              <criterion comment='libkadm5clnt4-heimdal DPKG is earlier than 0.4e-7.woody.5' test_ref='oval:org.debian.oval:tst:675'/>
              <criterion comment='heimdal-dev DPKG is earlier than 0.4e-7.woody.5' test_ref='oval:org.debian.oval:tst:676'/>
              <criterion comment='libkafs0-heimdal DPKG is earlier than 0.4e-7.woody.5' test_ref='oval:org.debian.oval:tst:677'/>
              <criterion comment='libkadm5srv7-heimdal DPKG is earlier than 0.4e-7.woody.5' test_ref='oval:org.debian.oval:tst:678'/>
              <criterion comment='heimdal-servers DPKG is earlier than 0.4e-7.woody.5' test_ref='oval:org.debian.oval:tst:679'/>
              <criterion comment='heimdal-clients-x DPKG is earlier than 0.4e-7.woody.5' test_ref='oval:org.debian.oval:tst:680'/>
              <criterion comment='libgssapi1-heimdal DPKG is earlier than 0.4e-7.woody.5' test_ref='oval:org.debian.oval:tst:681'/>
              <criterion comment='libss0-heimdal DPKG is earlier than 0.4e-7.woody.5' test_ref='oval:org.debian.oval:tst:682'/>
              <criterion comment='libhdb7-heimdal DPKG is earlier than 0.4e-7.woody.5' test_ref='oval:org.debian.oval:tst:683'/>
              <criterion comment='libsl0-heimdal DPKG is earlier than 0.4e-7.woody.5' test_ref='oval:org.debian.oval:tst:684'/>
              <criterion comment='libasn1-5-heimdal DPKG is earlier than 0.4e-7.woody.5' test_ref='oval:org.debian.oval:tst:685'/>
              <criterion comment='libkrb5-17-heimdal DPKG is earlier than 0.4e-7.woody.5' test_ref='oval:org.debian.oval:tst:686'/>
              <criterion comment='heimdal-kdc DPKG is earlier than 0.4e-7.woody.5' test_ref='oval:org.debian.oval:tst:687'/>
              <criterion comment='libcomerr1-heimdal DPKG is earlier than 0.4e-7.woody.5' test_ref='oval:org.debian.oval:tst:688'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:186' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>log2mail</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1251' ref_id='CVE-2002-1251'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-11-01</date>
          <moreinfo>
Enrico Zini discovered a buffer overflow in log2mail, a daemon for
watching logfiles and sending lines with matching patterns via mail.
The log2mail daemon is started upon system boot and runs as root.  A
specially crafted (remote) log message could overflow a static buffer,
potentially leaving log2mail to execute arbitrary code as root.
This problem has been fixed in version 0.2.5.1 the current
stable distribution (woody) and in version 0.2.6-1 for the unstable
distribution (sid).  The old stable distribution (potato) is not
affected since it doesn't contain a log2mail package.
We recommend that you upgrade your log2mail package.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='log2mail DPKG is earlier than 0.2.5.1' test_ref='oval:org.debian.oval:tst:689'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:187' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>apache</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0839' ref_id='CVE-2002-0839'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0840' ref_id='CVE-2002-0840'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0843' ref_id='CVE-2002-0843'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0131' ref_id='CVE-2001-0131'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1233' ref_id='CVE-2002-1233'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-11-04</date>
          <moreinfo>
According to David Wagner, iDEFENSE and the Apache HTTP Server
Project, several remotely exploitable vulnerabilities have been found
in the Apache package, a commonly used webserver.  These
vulnerabilities could allow an attacker to enact a denial of service
against a server or execute a cross scripting attack.  The Common
Vulnerabilities and Exposures (CVE) project identified the following
vulnerabilities:
   This is the same vulnerability as CAN-2002-1233, which was fixed in
   potato already but got lost later and was never applied upstream.
These problems have been fixed in version 1.3.26-0woody3 for the
current stable distribution (woody) and in 1.3.9-14.3 for the old
stable distribution (potato).  Corrected packages for the unstable
distribution (sid) are expected soon.
We recommend that you upgrade your Apache package immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criterion comment='apache-doc DPKG is earlier than 1.3.9-14.3' test_ref='oval:org.debian.oval:tst:690'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='apache DPKG is earlier than 1.3.9-14.3' test_ref='oval:org.debian.oval:tst:691'/>
              <criterion comment='apache-common DPKG is earlier than 1.3.9-14.3' test_ref='oval:org.debian.oval:tst:692'/>
              <criterion comment='apache-dev DPKG is earlier than 1.3.9-14.3' test_ref='oval:org.debian.oval:tst:693'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criterion comment='apache-doc DPKG is earlier than 1.3.26-0woody3' test_ref='oval:org.debian.oval:tst:694'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='apache DPKG is earlier than 1.3.26-0woody3' test_ref='oval:org.debian.oval:tst:695'/>
              <criterion comment='apache-common DPKG is earlier than 1.3.26-0woody3' test_ref='oval:org.debian.oval:tst:696'/>
              <criterion comment='apache-dev DPKG is earlier than 1.3.26-0woody3' test_ref='oval:org.debian.oval:tst:697'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:188' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>apache-ssl</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0839' ref_id='CVE-2002-0839'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0840' ref_id='CVE-2002-0840'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0843' ref_id='CVE-2002-0843'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0131' ref_id='CVE-2001-0131'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1233' ref_id='CVE-2002-1233'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-11-05</date>
          <moreinfo>
According to David Wagner, iDEFENSE and the Apache HTTP Server
Project, several vulnerabilities have been found in the Apache
package, a commonly used webserver.  Most of the code is shared
between the Apache and Apache-SSL packages, so vulnerabilities are
shared as well.  These vulnerabilities could allow an attacker to
enact a denial of service against a server or execute a cross
scripting attack, or steal cookies from other web site users.
Vulnerabilities in the included legacy programs htdigest, htpasswd and
ApacheBench can be exploited when called via CGI.  Additionally the
insecure temporary file creation in htdigest and htpasswd can also be
exploited locally.  The Common Vulnerabilities and Exposures (CVE)
project identified the following vulnerabilities:
   This is the same vulnerability as CAN-2002-1233, which was fixed in
   potato already but got lost later and was never applied upstream.
   (binaries not included in apache-ssl package though)
These problems have been fixed in version 1.3.26.1+1.48-0woody3 for
the current stable distribution (woody) and in 1.3.9.13-4.2 for the
old stable distribution (potato).  Corrected packages for the unstable
distribution (sid) are expected soon.
We recommend that you upgrade your Apache-SSL package immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='apache-ssl DPKG is earlier than 1.3.9.13-4.2' test_ref='oval:org.debian.oval:tst:698'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='apache-ssl DPKG is earlier than 1.3.26.1+1.48-0woody3' test_ref='oval:org.debian.oval:tst:699'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:189' class='vulnerability'>
      <metadata>
        <title>local root exploit</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>luxman</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1245' ref_id='CVE-2002-1245'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-11-06</date>
          <moreinfo>
iDEFENSE &lt;a href="http://www.idefense.com/advisory/11.06.02.txt">\
reported&lt;/a> about a vulnerability in LuxMan, a maze game for
GNU/Linux, similar to the PacMan arcade game.  When successfully
exploited a local attacker gains read-write access to the memory,
leading to a local root compromise in many ways, examples of which
include scanning the file for fragments of the master password file
and modifying kernel memory to re-map system calls.
This problem has been fixed in version 0.41-17.1 for the current stable
distribution (woody) and in version 0.41-19 for the unstable
distribution (sid).  The old stable distribution (potato) is not
affected since it doesn't contain a luxman package.
We recommend that you upgrade your luxman package immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:21'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='luxman DPKG is earlier than 0.41-17.1' test_ref='oval:org.debian.oval:tst:700'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:190' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>wmaker</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1277' ref_id='CVE-2002-1277'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-11-07</date>
          <moreinfo>
Al Viro found a problem in the image handling code use in Window Maker,
a popular NEXTSTEP like window manager. When creating an image it would
allocate a buffer by multiplying the image width and height, but did not
check for an overflow. This makes it possible to overflow the buffer.
This could be exploited by using specially crafted image files (for
example when previewing themes).
This problem has been fixed in version 0.80.0-4.1 for the current stable
distribution (woody).  Packages for the mipsel architecture are not yet
available.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:206'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:19'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:245'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:21'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:207'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:235'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:30'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:20'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:22'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libwraster2 DPKG is earlier than 0.80.0-4.1' test_ref='oval:org.debian.oval:tst:701'/>
              <criterion comment='libwraster2-dev DPKG is earlier than 0.80.0-4.1' test_ref='oval:org.debian.oval:tst:702'/>
              <criterion comment='wmaker DPKG is earlier than 0.80.0-4.1' test_ref='oval:org.debian.oval:tst:703'/>
              <criterion comment='libwmaker0-dev DPKG is earlier than 0.80.0-4.1' test_ref='oval:org.debian.oval:tst:704'/>
              <criterion comment='libwings-dev DPKG is earlier than 0.80.0-4.1' test_ref='oval:org.debian.oval:tst:705'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:191' class='vulnerability'>
      <metadata>
        <title>cross site scripting</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>squirrelmail</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1131' ref_id='CVE-2002-1131'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1132' ref_id='CVE-2002-1132'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1276' ref_id='CVE-2002-1276'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-11-07</date>
          <moreinfo>
Several cross site scripting vulnerabilities have been found in
squirrelmail, a feature-rich webmail package written in PHP4.  The
Common Vulnerabilities and Exposures (CVE) project identified the
following vulnerabilities:
These problems have been fixed in version 1.2.6-1.1 for the current stable
distribution (woody) and in version 1.2.8-1.1 for the unstable
distribution (sid).  The old stable distribution (potato) is not
affected since it doesn't contain a squirrelmail package.
We recommend that you upgrade your squirrelmail package.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='squirrelmail DPKG is earlier than 1.2.6-1.2' test_ref='oval:org.debian.oval:tst:706'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:192' class='vulnerability'>
      <metadata>
        <title>arbitrary code execution</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>html2ps</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1275' ref_id='CVE-2002-1275'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-11-08</date>
          <moreinfo>
The SuSE Security Team found a vulnerability in html2ps, an HTML to
PostScript converter, that opened files based on unsanitized input
insecurely.  This problem can be exploited when html2ps is installed
as filter within lprng and the attacker has previously gained access
to the lp account.
These problems have been fixed in version 1.0b3-1.1 for the current
stable distribution (woody), in version 1.0b1-8.1 for the old stable
distribution (potato) and in version 1.0b3-2 for the unstable
distribution (sid).
We recommend that you upgrade your html2ps package.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criterion comment='html2ps DPKG is earlier than 1.0b1-8.2' test_ref='oval:org.debian.oval:tst:707'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criterion comment='html2ps DPKG is earlier than 1.0b3-1.2' test_ref='oval:org.debian.oval:tst:708'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:193' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>kdenetwork</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1247' ref_id='CVE-2002-1247'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-11-11</date>
          <moreinfo>
iDEFENSE &lt;a href="http://www.idefense.com/advisory/11.11.02.txt">\
reports&lt;/a> a security vulnerability in the klisa package, that
provides a LAN information service similar to "Network Neighbourhood",
which was discovered by Texonet.  It is possible for a local attacker
to exploit a buffer overflow condition in resLISa, a restricted
version of KLISa.  The vulnerability exists in the parsing of the
LOGNAME environment variable, an overly long value will overwrite the
instruction pointer thereby allowing an attacker to seize control of
the executable.
This problem has been fixed in version 2.2.2-14.2 for the current stable
distribution (woody) and in version 2.2.2-14.3 for the unstable
distribution (sid).  The old stable distribution (potato) is not
affected since it doesn't contain a kdenetwork package.
We recommend that you upgrade your klisa package immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libkdenetwork1 DPKG is earlier than 2.2.2-14.2' test_ref='oval:org.debian.oval:tst:709'/>
            <criterion comment='kdict DPKG is earlier than 2.2.2-14.2' test_ref='oval:org.debian.oval:tst:710'/>
            <criterion comment='libmimelib-dev DPKG is earlier than 2.2.2-14.2' test_ref='oval:org.debian.oval:tst:711'/>
            <criterion comment='knode DPKG is earlier than 2.2.2-14.2' test_ref='oval:org.debian.oval:tst:712'/>
            <criterion comment='ksirc DPKG is earlier than 2.2.2-14.2' test_ref='oval:org.debian.oval:tst:713'/>
            <criterion comment='korn DPKG is earlier than 2.2.2-14.2' test_ref='oval:org.debian.oval:tst:714'/>
            <criterion comment='klisa DPKG is earlier than 2.2.2-14.2' test_ref='oval:org.debian.oval:tst:715'/>
            <criterion comment='kit DPKG is earlier than 2.2.2-14.2' test_ref='oval:org.debian.oval:tst:716'/>
            <criterion comment='knewsticker DPKG is earlier than 2.2.2-14.2' test_ref='oval:org.debian.oval:tst:717'/>
            <criterion comment='ktalkd DPKG is earlier than 2.2.2-14.2' test_ref='oval:org.debian.oval:tst:718'/>
            <criterion comment='kmail DPKG is earlier than 2.2.2-14.2' test_ref='oval:org.debian.oval:tst:719'/>
            <criterion comment='libmimelib1 DPKG is earlier than 2.2.2-14.2' test_ref='oval:org.debian.oval:tst:720'/>
            <criterion comment='kppp DPKG is earlier than 2.2.2-14.2' test_ref='oval:org.debian.oval:tst:721'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:194' class='vulnerability'>
      <metadata>
        <title>buffer overflows</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>masqmail</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1279' ref_id='CVE-2002-1279'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-11-12</date>
          <moreinfo>
A set of buffer overflows have been discovered in masqmail, a mail
transport agent for hosts without permanent internet connection.  In
addition to this privileges were dropped only after reading a user
supplied configuration file.  Together this could be exploited to gain
unauthorized root access to the machine on which masqmail is
installed.
These problems have been fixed in version 0.1.16-2.1 for the current
stable distribution (woody) and in version 0.2.15-1 for the unstable
distribution (sid).  The old stable distribution (potato) is not
affected since it doesn't contain a masqmail package.
We recommend that you upgrade your masqmail package immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='masqmail DPKG is earlier than 0.1.16-2.1' test_ref='oval:org.debian.oval:tst:722'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:195' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>apache-perl</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0839' ref_id='CVE-2002-0839'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0840' ref_id='CVE-2002-0840'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0843' ref_id='CVE-2002-0843'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0131' ref_id='CVE-2001-0131'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1233' ref_id='CVE-2002-1233'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-11-13</date>
          <moreinfo>
According to David Wagner, iDEFENSE and the Apache HTTP Server
Project, several vulnerabilities have been found in the Apache server
package, a commonly used webserver.  Most of the code is shared
between the Apache and Apache-Perl packages, so vulnerabilities are
shared as well.
These vulnerabilities could allow an attacker to enact a denial of
service against a server or execute a cross site scripting attack, or
steal cookies from other web site users.  The Common Vulnerabilities
and Exposures (CVE) project identified the following vulnerabilities:
These problems have been fixed in version 1.3.26-1-1.26-0woody2 for
the current stable distribution (woody), in
1.3.9-14.1-1.21.20000309-1.1 for the old stable distribution (potato)
and in version 1.3.26-1.1-1.27-3-1 for the unstable distribution
(sid).
We recommend that you upgrade your Apache-Perl package immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='apache-perl DPKG is earlier than 1.3.9-14.1-1.21.20000309-1.1' test_ref='oval:org.debian.oval:tst:723'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='apache-perl DPKG is earlier than 1.3.26-1-1.26-0woody2' test_ref='oval:org.debian.oval:tst:724'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:196' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>bind</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0029' ref_id='CVE-2002-0029'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1219' ref_id='CVE-2002-1219'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1220' ref_id='CVE-2002-1220'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1221' ref_id='CVE-2002-1221'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-11-14</date>
          <moreinfo>
[Bind version 9, the bind9 package, is not affected by these problems.]
ISS X-Force has discovered several serious vulnerabilities in the Berkeley
Internet Name Domain Server (BIND).  BIND is the most common implementation
of the DNS (Domain Name Service) protocol, which is used on the vast
majority of DNS servers on the Internet.  DNS is a vital Internet protocol
that maintains a database of easy-to-remember domain names (host names) and
their corresponding numerical IP addresses.
Circumstantial evidence suggests that the Internet Software Consortium
(ISC), maintainers of BIND, was made aware of these issues in mid-October.
Distributors of Open Source operating systems, including Debian, were
notified of these vulnerabilities via CERT about 12 hours before the release
of the advisories on November 12th.  This notification did not include any
details that allowed us to identify the vulnerable code, much less prepare
timely fixes.
Unfortunately ISS and the ISC released their security advisories with only
descriptions of the vulnerabilities, without any patches.  Even though there
were no signs that these exploits are known to the black-hat community, and
there were no reports of active attacks, such attacks could have been
developed in the meantime - with no fixes available.
We can all express our regret at the inability of the ironically named
Internet Software Consortium to work with the Internet community in handling
this problem.  Hopefully this will not become a model for dealing with
security issues in the future.
The Common Vulnerabilities and Exposures (CVE) project identified the
following vulnerabilities:
These problems have been fixed in version 8.3.3-2.0woody1 for the current
stable distribution (woody), in version 8.2.3-0.potato.3 for the previous stable
distribution (potato) and in version 8.3.3-3 for the unstable distribution
(sid).  The fixed packages for unstable will enter the archive today.
We recommend that you upgrade your bind package immediately, update to
bind9, or switch to another DNS server implementation.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='bind-doc DPKG is earlier than 8.2.3-0.potato.3' test_ref='oval:org.debian.oval:tst:725'/>
                <criterion comment='task-dns-server DPKG is earlier than 8.2.3-0.potato.3' test_ref='oval:org.debian.oval:tst:726'/>
              </criteria>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='dnsutils DPKG is earlier than 8.2.3-0.potato.3' test_ref='oval:org.debian.oval:tst:727'/>
              <criterion comment='bind DPKG is earlier than 8.2.3-0.potato.3' test_ref='oval:org.debian.oval:tst:728'/>
              <criterion comment='bind-dev DPKG is earlier than 8.2.3-0.potato.3' test_ref='oval:org.debian.oval:tst:729'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criterion comment='bind-doc DPKG is earlier than 8.3.3-2.0woody1' test_ref='oval:org.debian.oval:tst:730'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='bind DPKG is earlier than 8.3.3-2.0woody1' test_ref='oval:org.debian.oval:tst:731'/>
              <criterion comment='bind-dev DPKG is earlier than 8.3.3-2.0woody1' test_ref='oval:org.debian.oval:tst:732'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:197' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>courier</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1311' ref_id='CVE-2002-1311'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-11-15</date>
          <moreinfo>
A problem in the Courier sqwebmail package, a CGI program to grant
authenticated access to local mailboxes, has been discovered.  The
program did not drop permissions fast enough upon startup under
certain circumstances so a local shell user can execute the sqwebmail
binary and manage to read an arbitrary file on the local filesystem.
This problem has been fixed in version 0.37.3-2.3 for the current
stable distribution (woody) and in version 0.40.0-1 for the unstable
distribution (sid).  The old stable distribution (potato) does not
contain Courier sqwebmail packages.  &lt;code>courier-ssl&lt;/code> packages
are also not affected since they don't expose an sqwebmail package.
We recommend that you upgrade your sqwebmail package immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='courier-doc DPKG is earlier than 0.37.3-2.3' test_ref='oval:org.debian.oval:tst:733'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='courier-maildrop DPKG is earlier than 0.37.3-2.3' test_ref='oval:org.debian.oval:tst:734'/>
            <criterion comment='courier-base DPKG is earlier than 0.37.3-2.3' test_ref='oval:org.debian.oval:tst:735'/>
            <criterion comment='courier-debug DPKG is earlier than 0.37.3-2.3' test_ref='oval:org.debian.oval:tst:736'/>
            <criterion comment='courier-authdaemon DPKG is earlier than 0.37.3-2.3' test_ref='oval:org.debian.oval:tst:737'/>
            <criterion comment='courier-webadmin DPKG is earlier than 0.37.3-2.3' test_ref='oval:org.debian.oval:tst:738'/>
            <criterion comment='courier-mta DPKG is earlier than 0.37.3-2.3' test_ref='oval:org.debian.oval:tst:739'/>
            <criterion comment='courier-mlm DPKG is earlier than 0.37.3-2.3' test_ref='oval:org.debian.oval:tst:740'/>
            <criterion comment='courier-authmysql DPKG is earlier than 0.37.3-2.3' test_ref='oval:org.debian.oval:tst:741'/>
            <criterion comment='courier-ldap DPKG is earlier than 0.37.3-2.3' test_ref='oval:org.debian.oval:tst:742'/>
            <criterion comment='sqwebmail DPKG is earlier than 0.37.3-2.3' test_ref='oval:org.debian.oval:tst:743'/>
            <criterion comment='courier-pop DPKG is earlier than 0.37.3-2.3' test_ref='oval:org.debian.oval:tst:744'/>
            <criterion comment='courier-imap DPKG is earlier than 1.4.3-2.3' test_ref='oval:org.debian.oval:tst:745'/>
            <criterion comment='courier-pcp DPKG is earlier than 0.37.3-2.3' test_ref='oval:org.debian.oval:tst:746'/>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:30'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='courier-imap-ssl DPKG is earlier than 1.4.3-3.1' test_ref='oval:org.debian.oval:tst:747'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:198' class='vulnerability'>
      <metadata>
        <title>denial of service</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>nullmailer</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1313' ref_id='CVE-2002-1313'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-11-18</date>
          <moreinfo>
A problem has been discovered in nullmailer, a simple relay-only mail
transport agent for hosts that relay mail to a fixed set of smart
relays.  When a mail is to be delivered locally to a user that doesn't
exist, nullmailer tries to deliver it, discovers a user unknown error
and stops delivering.  Unfortunately, it stops delivering entirely,
not only this mail.  Hence, it's very easy to craft a denial of service.
This problem has been fixed in version 1.00RC5-16.1woody2 for the
current stable distribution (woody) and in version 1.00RC5-17 for the
unstable distribution (sid).  The old stable distribution (potato)
does not contain a nullmailer package.
We recommend that you upgrade your nullmailer package.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='nullmailer DPKG is earlier than 1.00RC5-16.1woody2' test_ref='oval:org.debian.oval:tst:748'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:199' class='vulnerability'>
      <metadata>
        <title>cross site scripting</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>mhonarc</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1307' ref_id='CVE-2002-1307'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-11-19</date>
          <moreinfo>
Steven Christey discovered a cross site scripting vulnerability in
mhonarc, a mail to HTML converter.  Carefully crafted message headers
can introduce cross site scripting when mhonarc is configured to
display all headers lines on the web.  However, it is often useful to
restrict the displayed header lines to To, From and Subject, in which
case the vulnerability cannot be exploited.
This problem has been fixed in version 2.5.2-1.2 for the current
stable distribution (woody), in version 2.4.4-1.2 for the old stable
distribution (potato) and in version 2.5.13-1 for the unstable
distribution (sid).
We recommend that you upgrade your mhonarc package.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criterion comment='mhonarc DPKG is earlier than 2.4.4-1.2' test_ref='oval:org.debian.oval:tst:749'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criterion comment='mhonarc DPKG is earlier than 2.5.2-1.2' test_ref='oval:org.debian.oval:tst:750'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:200' class='vulnerability'>
      <metadata>
        <title>remote exploit</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>samba</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1318' ref_id='CVE-2002-1318'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-11-22</date>
          <moreinfo>
Steve Langasek found an exploitable bug in the password handling
code in samba: when converting from DOS code-page to little endian
UCS2 unicode a buffer length was not checked and a buffer could
be overflowed. There is no known exploit for this, but an upgrade
is strongly recommended.
This problem has been fixed in version 2.2.3a-12 of the Debian
samba packages and upstream version 2.2.7.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='samba-doc DPKG is earlier than 2.2.3a-12' test_ref='oval:org.debian.oval:tst:751'/>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:206'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:245'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:21'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:235'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:30'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:20'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:22'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='smbfs DPKG is earlier than 2.2.3a-12' test_ref='oval:org.debian.oval:tst:752'/>
              <criterion comment='samba DPKG is earlier than 2.2.3a-12' test_ref='oval:org.debian.oval:tst:753'/>
              <criterion comment='swat DPKG is earlier than 2.2.3a-12' test_ref='oval:org.debian.oval:tst:754'/>
              <criterion comment='libsmbclient DPKG is earlier than 2.2.3a-12' test_ref='oval:org.debian.oval:tst:755'/>
              <criterion comment='smbclient DPKG is earlier than 2.2.3a-12' test_ref='oval:org.debian.oval:tst:756'/>
              <criterion comment='winbind DPKG is earlier than 2.2.3a-12' test_ref='oval:org.debian.oval:tst:757'/>
              <criterion comment='libpam-smbpass DPKG is earlier than 2.2.3a-12' test_ref='oval:org.debian.oval:tst:758'/>
              <criterion comment='libsmbclient-dev DPKG is earlier than 2.2.3a-12' test_ref='oval:org.debian.oval:tst:759'/>
              <criterion comment='samba-common DPKG is earlier than 2.2.3a-12' test_ref='oval:org.debian.oval:tst:760'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:201' class='vulnerability'>
      <metadata>
        <title>denial of service</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>freeswan</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0666' ref_id='CVE-2002-0666'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-12-02</date>
          <moreinfo>
Bindview &lt;a href="http://razor.bindview.com/publish/advisories/adv_ipsec.html">\
discovered&lt;/a> a problem in several IPSEC implementations that do
not properly handle certain very short packets.  IPSEC is a set of
security extensions to IP which provide authentication and encryption.
Free/SWan in Debian is affected by this and is said to cause a kernel
panic.
This problem has been fixed in version 1.96-1.4 for the current stable
distribution (woody) and in version 1.99-1 for the unstable
distribution (sid).  The old stable distribution (potato) does not
contain Free/SWan packages.
We recommend that you upgrade your freeswan package.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='kernel-patch-freeswan DPKG is earlier than 1.96-1.4' test_ref='oval:org.debian.oval:tst:761'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='freeswan DPKG is earlier than 1.96-1.4' test_ref='oval:org.debian.oval:tst:762'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:202' class='vulnerability'>
      <metadata>
        <title>insecure temporary files</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>im</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1395' ref_id='CVE-2002-1395'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-12-03</date>
          <moreinfo>
Tatsuya Kinoshita discovered that IM, which contains interface
commands and Perl libraries for E-mail and NetNews, creates temporary
files insecurely.
These problems have been fixed in version 141-18.1 for the current
stable distribution (woody), in version 133-2.2 of the old stable
distribution (potato) and in version 141-20 for the unstable
distribution (sid).
We recommend that you upgrade your IM package.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criterion comment='im DPKG is earlier than 133-2.3' test_ref='oval:org.debian.oval:tst:763'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criterion comment='im DPKG is earlier than 141-18.2' test_ref='oval:org.debian.oval:tst:764'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:203' class='vulnerability'>
      <metadata>
        <title>arbitrary command execution</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>smb2www</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1342' ref_id='CVE-2002-1342'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-12-04</date>
          <moreinfo>
Robert Luberda found a security problem in smb2www, a Windows Network
client that is accessible through a web browser.  This could lead a
remote attacker to execute arbitrary programs under the user id
www-data on the host where smb2www is running.
This problem has been fixed in version 980804-16.1 for the current
stable distribution (woody), in version 980804-8.1 of the old stable
distribution (potato) and in version 980804-17 for the unstable
distribution (sid).
We recommend that you upgrade your smb2www package immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criterion comment='smb2www DPKG is earlier than 980804-8.1' test_ref='oval:org.debian.oval:tst:765'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criterion comment='smb2www DPKG is earlier than 980804-16.1' test_ref='oval:org.debian.oval:tst:766'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:204' class='vulnerability'>
      <metadata>
        <title>arbitrary program execution</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>kdelibs</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1281' ref_id='CVE-2002-1281'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1282' ref_id='CVE-2002-1282'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-12-05</date>
          <moreinfo>
The KDE team has &lt;a href="http://www.kde.org/info/security/advisory-20021111-1.txt">\
discovered&lt;/a> a vulnerability in the support for various
network protocols via the KIO.  The implementation of the rlogin and telnet
protocols allows a carefully crafted URL in an HTML page, HTML email or
other KIO-enabled application to execute arbitrary commands on the
system using the victim's account on the vulnerable machine.
This problem has been fixed by disabling rlogin and telnet in version
2.2.2-13.woody.5 for the current stable distribution (woody).  The old
stable distribution (potato) is not affected since it doesn't contain
KDE.  A correction for the package in the unstable distribution (sid)
is not yet available.
We recommend that you upgrade your kdelibs3 package immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='kdelibs3-doc DPKG is earlier than 2.2.2-13.woody.5' test_ref='oval:org.debian.oval:tst:767'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libarts DPKG is earlier than 2.2.2-13.woody.5' test_ref='oval:org.debian.oval:tst:768'/>
            <criterion comment='libkmid-alsa DPKG is earlier than 2.2.2-13.woody.5' test_ref='oval:org.debian.oval:tst:769'/>
            <criterion comment='kdelibs3-bin DPKG is earlier than 2.2.2-13.woody.5' test_ref='oval:org.debian.oval:tst:770'/>
            <criterion comment='libarts-alsa DPKG is earlier than 2.2.2-13.woody.5' test_ref='oval:org.debian.oval:tst:771'/>
            <criterion comment='kdelibs3 DPKG is earlier than 2.2.2-13.woody.5' test_ref='oval:org.debian.oval:tst:772'/>
            <criterion comment='kdelibs3-cups DPKG is earlier than 2.2.2-13.woody.5' test_ref='oval:org.debian.oval:tst:773'/>
            <criterion comment='libkmid-dev DPKG is earlier than 2.2.2-13.woody.5' test_ref='oval:org.debian.oval:tst:774'/>
            <criterion comment='libkmid DPKG is earlier than 2.2.2-13.woody.5' test_ref='oval:org.debian.oval:tst:775'/>
            <criterion comment='libarts-dev DPKG is earlier than 2.2.2-13.woody.5' test_ref='oval:org.debian.oval:tst:776'/>
            <criterion comment='kdelibs-dev DPKG is earlier than 2.2.2-13.woody.5' test_ref='oval:org.debian.oval:tst:777'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:206' class='vulnerability'>
      <metadata>
        <title>denial of service</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>tcpdump</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1350' ref_id='CVE-2002-1350'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-12-10</date>
          <moreinfo>
The BGP decoding routines for tcpdump used incorrect bounds checking
when copying data. This could be abused by introducing malicious traffic
on a sniffed network for a denial of service attack against tcpdump,
or possibly even remote code execution.
This has been fixed in version 3.6.2-2.2.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:206'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:19'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:245'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:21'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:207'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:235'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:30'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:20'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:22'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='tcpdump DPKG is earlier than 3.6.2-2.2' test_ref='oval:org.debian.oval:tst:778'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:207' class='vulnerability'>
      <metadata>
        <title>arbitrary command execution</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>tetex-bin</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0836' ref_id='CVE-2002-0836'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-12-11</date>
          <moreinfo>
The SuSE security team discovered a vulnerability in kpathsea library
(libkpathsea) which is used by xdvi and dvips.  Both programs call the
system() function insecurely, which allows a remote attacker to
execute arbitrary commands via cleverly crafted DVI files.
If dvips is used in a print filter, this allows a local or remote
attacker with print permission execute arbitrary code as the printer
user (usually lp).
This problem has been fixed in version 1.0.7+20011202-7.1 for the
current stable distribution (woody), in version 1.0.6-7.3 for the old
stable distribution (potato) and in version 1.0.7+20021025-4 for the
unstable distribution (sid).  xdvik-ja and dvipsk-ja are vulnerable as
well, but link to the kpathsea library dynamically and will
automatically be fixed after a new libkpathsea is installed.
We recommend that you upgrade your tetex-lib package immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='tetex-dev DPKG is earlier than 1.0.6-7.3' test_ref='oval:org.debian.oval:tst:779'/>
              <criterion comment='tetex-lib DPKG is earlier than 1.0.6-7.3' test_ref='oval:org.debian.oval:tst:780'/>
              <criterion comment='tetex-bin DPKG is earlier than 1.0.6-7.3' test_ref='oval:org.debian.oval:tst:781'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libkpathsea-dev DPKG is earlier than 1.0.7+20011202-7.1' test_ref='oval:org.debian.oval:tst:782'/>
              <criterion comment='libkpathsea3 DPKG is earlier than 1.0.7+20011202-7.1' test_ref='oval:org.debian.oval:tst:783'/>
              <criterion comment='tetex-bin DPKG is earlier than 1.0.7+20011202-7.1' test_ref='oval:org.debian.oval:tst:784'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:208' class='vulnerability'>
      <metadata>
        <title>broken safe compartment</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>perl, perl-5.004, perl-5.005</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1323' ref_id='CVE-2002-1323'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-12-12</date>
          <moreinfo>
A security hole has been discovered in Safe.pm which is used in all
versions of Perl.  The Safe extension module allows the creation of
compartments in which perl code can be evaluated in a new namespace
and the code evaluated in the compartment cannot refer to variables
outside this namespace.  However, when a Safe compartment has already
been used, there's no guarantee that it is Safe any longer, because
there's a way for code to be executed within the Safe compartment to
alter its operation mask.  Thus, programs that use a Safe compartment
only once aren't affected by this bug.
This problem has been fixed in version 5.6.1-8.2 for the current
stable distribution (woody), in version 5.004.05-6.2 and 5.005.03-7.2
for the old stable distribution (potato) and in version 5.8.0-14 for
the unstable distribution (sid).
We recommend that you upgrade your Perl packages.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='perl-5.004-doc DPKG is earlier than 5.004.05-6.2' test_ref='oval:org.debian.oval:tst:785'/>
                <criterion comment='perl-5.005-doc DPKG is earlier than 5.005.03-7.2' test_ref='oval:org.debian.oval:tst:786'/>
              </criteria>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='perl-5.004-suid DPKG is earlier than 5.004.05-6.2' test_ref='oval:org.debian.oval:tst:787'/>
              <criterion comment='perl-5.005-suid DPKG is earlier than 5.005.03-7.2' test_ref='oval:org.debian.oval:tst:788'/>
              <criterion comment='perl-5.004-base DPKG is earlier than 5.004.05-6.2' test_ref='oval:org.debian.oval:tst:789'/>
              <criterion comment='perl-5.004 DPKG is earlier than 5.004.05-6.2' test_ref='oval:org.debian.oval:tst:790'/>
              <criterion comment='perl-5.005 DPKG is earlier than 5.005.03-7.2' test_ref='oval:org.debian.oval:tst:791'/>
              <criterion comment='perl-5.004-debug DPKG is earlier than 5.004.05-6.2' test_ref='oval:org.debian.oval:tst:792'/>
              <criterion comment='perl-5.005-base DPKG is earlier than 5.005.03-7.2' test_ref='oval:org.debian.oval:tst:793'/>
              <criterion comment='perl-5.005-debug DPKG is earlier than 5.005.03-7.2' test_ref='oval:org.debian.oval:tst:794'/>
              <criterion comment='perl-5.005-thread DPKG is earlier than 5.005.03-7.2' test_ref='oval:org.debian.oval:tst:795'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='perl-modules DPKG is earlier than 5.6.1-8.2' test_ref='oval:org.debian.oval:tst:796'/>
                <criterion comment='perl-doc DPKG is earlier than 5.6.1-8.2' test_ref='oval:org.debian.oval:tst:797'/>
                <criterion comment='libcgi-fast-perl DPKG is earlier than 5.6.1-8.2' test_ref='oval:org.debian.oval:tst:798'/>
              </criteria>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libperl-dev DPKG is earlier than 5.6.1-8.2' test_ref='oval:org.debian.oval:tst:799'/>
              <criterion comment='perl-suid DPKG is earlier than 5.6.1-8.2' test_ref='oval:org.debian.oval:tst:800'/>
              <criterion comment='perl DPKG is earlier than 5.6.1-8.2' test_ref='oval:org.debian.oval:tst:801'/>
              <criterion comment='perl-base DPKG is earlier than 5.6.1-8.2' test_ref='oval:org.debian.oval:tst:802'/>
              <criterion comment='libperl5.6 DPKG is earlier than 5.6.1-8.2' test_ref='oval:org.debian.oval:tst:803'/>
              <criterion comment='perl-debug DPKG is earlier than 5.6.1-8.2' test_ref='oval:org.debian.oval:tst:804'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:209' class='vulnerability'>
      <metadata>
        <title>directory traversal</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>wget</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1344' ref_id='CVE-2002-1344'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1565' ref_id='CVE-2002-1565'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-12-12</date>
          <moreinfo>
Two problems have been found in the wget package as distributed in
Debian GNU/Linux:
Both problems have been fixed in version 1.5.3-3.1 for Debian GNU/Linux
2.2/potato and version 1.8.1-6.1 for Debian GNU/Linux 3.0/woody.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='wget DPKG is earlier than 1.5.3-3.1' test_ref='oval:org.debian.oval:tst:805'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:206'/>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:18'/>
                <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:19'/>
                <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:245'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:21'/>
                <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:207'/>
                <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:235'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:30'/>
                <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:20'/>
                <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:22'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='wget DPKG is earlier than 1.8.1-6.1' test_ref='oval:org.debian.oval:tst:806'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:210' class='vulnerability'>
      <metadata>
        <title>CRLF injection</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>lynx, lynx-ssl</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1405' ref_id='CVE-2002-1405'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-12-13</date>
          <moreinfo>
lynx (a text-only web browser) did not properly check for illegal
characters in all places, including processing of command line options,
which could be used to insert extra HTTP headers in a request.
For Debian GNU/Linux 2.2/potato this has been fixed in version 2.8.3-1.1
of the lynx package and version 2.8.3.1-1.1 of the lynx-ssl package.
For Debian GNU/Linux 3.0/woody this has been fixed in version 2.8.4.1b-3.2
of the lynx package and version 1:2.8.4.1b-3.1 of the lynx-ssl package.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='lynx-ssl DPKG is earlier than 2.8.3.1-1.1' test_ref='oval:org.debian.oval:tst:807'/>
              <criterion comment='lynx DPKG is earlier than 2.8.3-1.1' test_ref='oval:org.debian.oval:tst:808'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:206'/>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:18'/>
                <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:245'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:21'/>
                <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:207'/>
                <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:235'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:30'/>
                <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:20'/>
                <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:208'/>
                <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:22'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='lynx-ssl DPKG is earlier than 2.8.4.1b-3.1' test_ref='oval:org.debian.oval:tst:809'/>
                <criterion comment='lynx DPKG is earlier than 2.8.4.1b-3.2' test_ref='oval:org.debian.oval:tst:810'/>
              </criteria>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:19'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='lynx DPKG is earlier than 2.8.4.1b-3.2' test_ref='oval:org.debian.oval:tst:811'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:211' class='vulnerability'>
      <metadata>
        <title>denial of service</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>micq</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1362' ref_id='CVE-2002-1362'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-12-13</date>
          <moreinfo>
Rüdiger Kuhlmann, upstream developer of mICQ, a text based ICQ client,
discovered a problem in mICQ.  Receiving certain ICQ message types
that do not contain the required 0xFE separator causes all versions to
crash.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='micq DPKG is earlier than 0.4.3-4.1' test_ref='oval:org.debian.oval:tst:812'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='micq DPKG is earlier than 0.4.9-0woody3' test_ref='oval:org.debian.oval:tst:813'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:212' class='vulnerability'>
      <metadata>
        <title>multiple problems</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>mysql</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1373' ref_id='CVE-2002-1373'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1374' ref_id='CVE-2002-1374'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1375' ref_id='CVE-2002-1375'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1376' ref_id='CVE-2002-1376'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-12-17</date>
          <moreinfo>
While performing an audit of MySQL e-matters found several problems:
For Debian GNU/Linux 3.0/woody this has been fixed in version 3.23.49-8.2
and version 3.22.32-6.3 for Debian GNU/Linux 2.2/potato.
We recommend that you upgrade your mysql packages as soon as possible.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criterion comment='mysql-doc DPKG is earlier than 3.22.32-6.3' test_ref='oval:org.debian.oval:tst:814'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='mysql-client DPKG is earlier than 3.22.32-6.3' test_ref='oval:org.debian.oval:tst:815'/>
              <criterion comment='mysql-server DPKG is earlier than 3.22.32-6.3' test_ref='oval:org.debian.oval:tst:816'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='mysql-doc DPKG is earlier than 3.23.49-8.2' test_ref='oval:org.debian.oval:tst:817'/>
                <criterion comment='mysql-common DPKG is earlier than 3.23.49-8.2' test_ref='oval:org.debian.oval:tst:818'/>
              </criteria>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:206'/>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:18'/>
                <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:19'/>
                <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:245'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:21'/>
                <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:235'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:30'/>
                <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:20'/>
                <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:208'/>
                <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:22'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='mysql-client DPKG is earlier than 3.23.49-8.2' test_ref='oval:org.debian.oval:tst:819'/>
                <criterion comment='libmysqlclient10 DPKG is earlier than 3.23.49-8.2' test_ref='oval:org.debian.oval:tst:820'/>
                <criterion comment='libmysqlclient10-dev DPKG is earlier than 3.23.49-8.2' test_ref='oval:org.debian.oval:tst:821'/>
                <criterion comment='mysql-server DPKG is earlier than 3.23.49-8.2' test_ref='oval:org.debian.oval:tst:822'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:213' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>libpng, libpng3</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1363' ref_id='CVE-2002-1363'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-12-19</date>
          <moreinfo>
Glenn Randers-Pehrson discovered a problem in connection with 16-bit
samples from libpng, an interface for reading and writing PNG
(Portable Network Graphics) format files.  The starting offsets for
the loops are calculated incorrectly which causes a buffer overrun
beyond the beginning of the row buffer.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libpng2-dev DPKG is earlier than 1.0.5-1.1' test_ref='oval:org.debian.oval:tst:823'/>
              <criterion comment='libpng2 DPKG is earlier than 1.0.5-1.1' test_ref='oval:org.debian.oval:tst:824'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libpng2-dev DPKG is earlier than 1.0.12-3.woody.3' test_ref='oval:org.debian.oval:tst:825'/>
              <criterion comment='libpng3 DPKG is earlier than 1.2.1-1.1.woody.3' test_ref='oval:org.debian.oval:tst:826'/>
              <criterion comment='libpng-dev DPKG is earlier than 1.2.1-1.1.woody.3' test_ref='oval:org.debian.oval:tst:827'/>
              <criterion comment='libpng2 DPKG is earlier than 1.0.12-3.woody.3' test_ref='oval:org.debian.oval:tst:828'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:214' class='vulnerability'>
      <metadata>
        <title>buffer overflows</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>kdenetwork</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1306' ref_id='CVE-2002-1306'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-12-20</date>
          <moreinfo>
Olaf Kirch from SuSE Linux AG discovered another vulnerability in the
klisa package, that provides a LAN information service similar to
"Network Neighbourhood".  The lisa daemon contains a buffer overflow
vulnerability which potentially enables any local user, as well as
any remote attacker on the LAN who is able to gain control of the LISa
port (7741 by default), to obtain root privileges.  In addition, a
remote attacker potentially may be able to gain access to a victim's
account by using an "rlan://" URL in an HTML page or via another KDE
application.
This problem has been fixed in version 2.2.2-14.5 for the current
stable distribution (woody) and in version 2.2.2-14.20 for the
unstable distribution (sid).  The old stable distribution (potato) is
not affected since it doesn't contain a kdenetwork package.
We recommend that you upgrade your klisa package immediately.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libkdenetwork1 DPKG is earlier than 2.2.2-14.5' test_ref='oval:org.debian.oval:tst:829'/>
            <criterion comment='kdict DPKG is earlier than 2.2.2-14.5' test_ref='oval:org.debian.oval:tst:830'/>
            <criterion comment='libmimelib-dev DPKG is earlier than 2.2.2-14.5' test_ref='oval:org.debian.oval:tst:831'/>
            <criterion comment='knode DPKG is earlier than 2.2.2-14.5' test_ref='oval:org.debian.oval:tst:832'/>
            <criterion comment='ksirc DPKG is earlier than 2.2.2-14.5' test_ref='oval:org.debian.oval:tst:833'/>
            <criterion comment='korn DPKG is earlier than 2.2.2-14.5' test_ref='oval:org.debian.oval:tst:834'/>
            <criterion comment='klisa DPKG is earlier than 2.2.2-14.5' test_ref='oval:org.debian.oval:tst:835'/>
            <criterion comment='kit DPKG is earlier than 2.2.2-14.5' test_ref='oval:org.debian.oval:tst:836'/>
            <criterion comment='knewsticker DPKG is earlier than 2.2.2-14.5' test_ref='oval:org.debian.oval:tst:837'/>
            <criterion comment='ktalkd DPKG is earlier than 2.2.2-14.5' test_ref='oval:org.debian.oval:tst:838'/>
            <criterion comment='kmail DPKG is earlier than 2.2.2-14.5' test_ref='oval:org.debian.oval:tst:839'/>
            <criterion comment='libmimelib1 DPKG is earlier than 2.2.2-14.5' test_ref='oval:org.debian.oval:tst:840'/>
            <criterion comment='kppp DPKG is earlier than 2.2.2-14.5' test_ref='oval:org.debian.oval:tst:841'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:215' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>cyrus-imapd</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1580' ref_id='CVE-2002-1580'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-12-23</date>
          <moreinfo>
Timo Sirainen discovered a buffer overflow in the Cyrus IMAP server,
which could be exploited by a remote attacker prior to logging in.  A
malicious user could craft a request to run commands on the server under
the UID and GID of the cyrus server.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='cyrus-nntp DPKG is earlier than 1.5.19-2.2' test_ref='oval:org.debian.oval:tst:842'/>
              <criterion comment='cyrus-dev DPKG is earlier than 1.5.19-2.2' test_ref='oval:org.debian.oval:tst:843'/>
              <criterion comment='cyrus-pop3d DPKG is earlier than 1.5.19-2.2' test_ref='oval:org.debian.oval:tst:844'/>
              <criterion comment='cyrus-common DPKG is earlier than 1.5.19-2.2' test_ref='oval:org.debian.oval:tst:845'/>
              <criterion comment='cyrus-admin DPKG is earlier than 1.5.19-2.2' test_ref='oval:org.debian.oval:tst:846'/>
              <criterion comment='cyrus-imapd DPKG is earlier than 1.5.19-2.2' test_ref='oval:org.debian.oval:tst:847'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='cyrus-nntp DPKG is earlier than 1.5.19-9.1' test_ref='oval:org.debian.oval:tst:848'/>
              <criterion comment='cyrus-dev DPKG is earlier than 1.5.19-9.1' test_ref='oval:org.debian.oval:tst:849'/>
              <criterion comment='cyrus-pop3d DPKG is earlier than 1.5.19-9.1' test_ref='oval:org.debian.oval:tst:850'/>
              <criterion comment='cyrus-common DPKG is earlier than 1.5.19-9.1' test_ref='oval:org.debian.oval:tst:851'/>
              <criterion comment='cyrus-admin DPKG is earlier than 1.5.19-9.1' test_ref='oval:org.debian.oval:tst:852'/>
              <criterion comment='cyrus-imapd DPKG is earlier than 1.5.19-9.1' test_ref='oval:org.debian.oval:tst:853'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:216' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>fetchmail</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1365' ref_id='CVE-2002-1365'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-12-24</date>
          <moreinfo>
Stefan Esser of e-matters discovered a buffer overflow in fetchmail,
an SSL enabled POP3, APOP and IMAP mail gatherer/forwarder.  When
fetchmail retrieves a mail all headers that contain addresses are
searched for local addresses.  If a hostname is missing, fetchmail
appends it but doesn't reserve enough space for it.  This heap
overflow can be used by remote attackers to crash it or to execute
arbitrary code with the privileges of the user running fetchmail.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criterion comment='fetchmailconf DPKG is earlier than 5.3.3-4.3' test_ref='oval:org.debian.oval:tst:854'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='fetchmail DPKG is earlier than 5.3.3-4.3' test_ref='oval:org.debian.oval:tst:855'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='fetchmail-common DPKG is earlier than 5.9.11-6.2' test_ref='oval:org.debian.oval:tst:856'/>
                <criterion comment='fetchmailconf DPKG is earlier than 5.9.11-6.2' test_ref='oval:org.debian.oval:tst:857'/>
              </criteria>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='fetchmail DPKG is earlier than 5.9.11-6.2' test_ref='oval:org.debian.oval:tst:858'/>
              <criterion comment='fetchmail-ssl DPKG is earlier than 5.9.11-6.2' test_ref='oval:org.debian.oval:tst:859'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:217' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>typespeed</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1389' ref_id='CVE-2002-1389'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-12-27</date>
          <moreinfo>
A problem has been discovered in the typespeed, a game that lets you
measure your typematic speed.  By overflowing a buffer  a local
attacker could execute arbitrary commands under the group id games.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='typespeed DPKG is earlier than 0.4.0-5.1' test_ref='oval:org.debian.oval:tst:860'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='typespeed DPKG is earlier than 0.4.1-2.1' test_ref='oval:org.debian.oval:tst:861'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:218' class='vulnerability'>
      <metadata>
        <title>cross site scripting</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>bugzilla</product>
        </affected>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-12-30</date>
          <moreinfo>
A cross site scripting vulnerability has been reported for Bugzilla, a
web-based bug tracking system.  Bugzilla does not properly sanitize
any input submitted by users for use in quips.  As a result, it is possible for a
remote attacker to create a malicious link containing script code
which will be executed in the browser of a legitimate user, in the
context of the website running Bugzilla.  This issue may be exploited
to steal cookie-based authentication credentials from legitimate users
of the website running the vulnerable software.
This vulnerability only affects users who have the 'quips' feature
enabled and who upgraded from version 2.10 which did not exist inside
of Debian.  The Debian package history of Bugzilla starts with 1.13
and jumped to 2.13.  However, users could have installed version 2.10
prior to the Debian package.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:200'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='bugzilla DPKG is earlier than 2.14.2-0woody3' test_ref='oval:org.debian.oval:tst:862'/>
              <criterion comment='bugzilla-doc DPKG is earlier than 2.14.2-0woody3' test_ref='oval:org.debian.oval:tst:863'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:219' class='vulnerability'>
      <metadata>
        <title>remote command execution</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 2.2</platform>
          <product>dhcpcd</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1403' ref_id='CVE-2002-1403'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2002-12-31</date>
          <moreinfo>
Simon Kelly discovered a vulnerability in dhcpcd, an RFC2131 and
RFC1541 compliant DHCP client daemon, that runs with root privileges
on client machines.  A malicious administrator of the regular or an
untrusted DHCP server may execute any command with root privileges on
the DHCP client machine by sending the command enclosed in shell
metacharacters in one of the options provided by the DHCP server.
This problem has been fixed in version 1.3.17pl2-8.1 for the old
stable distribution (potato) and in version 1.3.22pl2-2 for the
testing (sarge) and unstable (sid) distributions.  The current stable
distribution (woody) does not contain a dhcpcd package.
We recommend that you upgrade your dhcpcd package (on the client
machine).</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 2.2 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='dhcpcd DPKG is earlier than 1.3.17pl2-8.1' test_ref='oval:org.debian.oval:tst:864'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
  </definitions>
  <tests>
    <textfilecontent_test comment='Debian GNU/Linux 2.2 is installed' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#independent' id='oval:org.debian.oval:tst:1' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:1'/>
      <state state_ref='oval:org.debian.oval:ste:1'/>
    </textfilecontent_test>
    <dpkginfo_test comment='mutt is earlier than 1.2.5-5' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:2' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:2'/>
      <state state_ref='oval:org.debian.oval:ste:2'/>
    </dpkginfo_test>
    <dpkginfo_test comment='eximon is earlier than 3.12-10.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:3' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:3'/>
      <state state_ref='oval:org.debian.oval:ste:3'/>
    </dpkginfo_test>
    <dpkginfo_test comment='exim is earlier than 3.12-10.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:4' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:4'/>
      <state state_ref='oval:org.debian.oval:ste:3'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libgtop-dev is earlier than 1.0.6-1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:5' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:5'/>
      <state state_ref='oval:org.debian.oval:ste:4'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libgtop1 is earlier than 1.0.6-1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:6' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:6'/>
      <state state_ref='oval:org.debian.oval:ste:4'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libgtop-daemon is earlier than 1.0.6-1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:7' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:7'/>
      <state state_ref='oval:org.debian.oval:ste:4'/>
    </dpkginfo_test>
    <uname_test comment='Installed architecture is all' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#unix' id='oval:org.debian.oval:tst:8' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:8'/>
    </uname_test>
    <dpkginfo_test comment='xchat-common is earlier than 1.4.3-1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:9' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:9'/>
      <state state_ref='oval:org.debian.oval:ste:5'/>
    </dpkginfo_test>
    <dpkginfo_test comment='xchat-gnome is earlier than 1.4.3-1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:10' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:10'/>
      <state state_ref='oval:org.debian.oval:ste:5'/>
    </dpkginfo_test>
    <dpkginfo_test comment='xchat-text is earlier than 1.4.3-1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:11' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:11'/>
      <state state_ref='oval:org.debian.oval:ste:5'/>
    </dpkginfo_test>
    <dpkginfo_test comment='xchat is earlier than 1.4.3-1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:12' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:12'/>
      <state state_ref='oval:org.debian.oval:ste:5'/>
    </dpkginfo_test>
    <dpkginfo_test comment='gzip is earlier than 1.2.4-33.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:13' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:13'/>
      <state state_ref='oval:org.debian.oval:ste:6'/>
    </dpkginfo_test>
    <dpkginfo_test comment='sudo is earlier than 1.6.2p2-2.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:14' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:14'/>
      <state state_ref='oval:org.debian.oval:ste:7'/>
    </dpkginfo_test>
    <dpkginfo_test comment='at is earlier than 3.1.8-10.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:15' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:15'/>
      <state state_ref='oval:org.debian.oval:ste:8'/>
    </dpkginfo_test>
    <dpkginfo_test comment='glibc-doc is earlier than 2.1.3-20' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:16' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:16'/>
      <state state_ref='oval:org.debian.oval:ste:9'/>
    </dpkginfo_test>
    <dpkginfo_test comment='i18ndata is earlier than 2.1.3-20' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:17' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:17'/>
      <state state_ref='oval:org.debian.oval:ste:9'/>
    </dpkginfo_test>
    <uname_test comment='Installed architecture is sparc' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#unix' id='oval:org.debian.oval:tst:18' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:8'/>
      <state state_ref='oval:org.debian.oval:ste:10'/>
    </uname_test>
    <uname_test comment='Installed architecture is m68k' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#unix' id='oval:org.debian.oval:tst:19' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:8'/>
      <state state_ref='oval:org.debian.oval:ste:11'/>
    </uname_test>
    <uname_test comment='Installed architecture is powerpc' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#unix' id='oval:org.debian.oval:tst:20' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:8'/>
      <state state_ref='oval:org.debian.oval:ste:12'/>
    </uname_test>
    <uname_test comment='Installed architecture is i386' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#unix' id='oval:org.debian.oval:tst:21' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:8'/>
      <state state_ref='oval:org.debian.oval:ste:13'/>
    </uname_test>
    <uname_test comment='Installed architecture is arm' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#unix' id='oval:org.debian.oval:tst:22' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:8'/>
      <state state_ref='oval:org.debian.oval:ste:14'/>
    </uname_test>
    <dpkginfo_test comment='nscd is earlier than 2.1.3-20' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:23' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:18'/>
      <state state_ref='oval:org.debian.oval:ste:9'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libc6-dev is earlier than 2.1.3-20' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:24' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:19'/>
      <state state_ref='oval:org.debian.oval:ste:9'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libc6-pic is earlier than 2.1.3-20' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:25' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:20'/>
      <state state_ref='oval:org.debian.oval:ste:9'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libc6 is earlier than 2.1.3-20' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:26' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:21'/>
      <state state_ref='oval:org.debian.oval:ste:9'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libc6-prof is earlier than 2.1.3-20' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:27' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:22'/>
      <state state_ref='oval:org.debian.oval:ste:9'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libc6-dbg is earlier than 2.1.3-20' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:28' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:23'/>
      <state state_ref='oval:org.debian.oval:ste:9'/>
    </dpkginfo_test>
    <dpkginfo_test comment='locales is earlier than 2.1.3-20' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:29' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:24'/>
      <state state_ref='oval:org.debian.oval:ste:9'/>
    </dpkginfo_test>
    <uname_test comment='Installed architecture is alpha' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#unix' id='oval:org.debian.oval:tst:30' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:8'/>
      <state state_ref='oval:org.debian.oval:ste:15'/>
    </uname_test>
    <dpkginfo_test comment='libc6.1-pic is earlier than 2.1.3-20' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:31' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:25'/>
      <state state_ref='oval:org.debian.oval:ste:9'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libc6.1-dev is earlier than 2.1.3-20' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:32' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:26'/>
      <state state_ref='oval:org.debian.oval:ste:9'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libc6.1-dbg is earlier than 2.1.3-20' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:33' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:27'/>
      <state state_ref='oval:org.debian.oval:ste:9'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libnss1-compat is earlier than 2.1.3-20' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:34' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:28'/>
      <state state_ref='oval:org.debian.oval:ste:9'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libc6.1-prof is earlier than 2.1.3-20' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:35' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:29'/>
      <state state_ref='oval:org.debian.oval:ste:9'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libc6.1 is earlier than 2.1.3-20' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:36' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:30'/>
      <state state_ref='oval:org.debian.oval:ste:9'/>
    </dpkginfo_test>
    <dpkginfo_test comment='nscd is earlier than 2.1.3-20' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:37' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:18'/>
      <state state_ref='oval:org.debian.oval:ste:9'/>
    </dpkginfo_test>
    <dpkginfo_test comment='locales is earlier than 2.1.3-20' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:38' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:24'/>
      <state state_ref='oval:org.debian.oval:ste:9'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libnss1-compat is earlier than 2.1.3-20' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:39' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:28'/>
      <state state_ref='oval:org.debian.oval:ste:9'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libnss1-compat is earlier than 2.1.3-20' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:40' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:28'/>
      <state state_ref='oval:org.debian.oval:ste:9'/>
    </dpkginfo_test>
    <dpkginfo_test comment='cipe-source is earlier than 1.3.0-3' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:41' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:31'/>
      <state state_ref='oval:org.debian.oval:ste:16'/>
    </dpkginfo_test>
    <dpkginfo_test comment='cipe-common is earlier than 1.3.0-3' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:42' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:32'/>
      <state state_ref='oval:org.debian.oval:ste:16'/>
    </dpkginfo_test>
    <dpkginfo_test comment='enscript is earlier than 1.6.2-4.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:43' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:33'/>
      <state state_ref='oval:org.debian.oval:ste:17'/>
    </dpkginfo_test>
    <dpkginfo_test comment='rsync is earlier than 2.3.2-1.5' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:44' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:34'/>
      <state state_ref='oval:org.debian.oval:ste:18'/>
    </dpkginfo_test>
    <dpkginfo_test comment='jgroff is earlier than 1.15+ja-3.4' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:45' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:35'/>
      <state state_ref='oval:org.debian.oval:ste:19'/>
    </dpkginfo_test>
    <dpkginfo_test comment='wmtv is earlier than 0.6.5-2potato2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:46' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:36'/>
      <state state_ref='oval:org.debian.oval:ste:20'/>
    </dpkginfo_test>
    <dpkginfo_test comment='faqomatic is earlier than 2.603-1.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:47' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:37'/>
      <state state_ref='oval:org.debian.oval:ste:21'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libcupsys1 is earlier than 1.0.4-10' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:48' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:38'/>
      <state state_ref='oval:org.debian.oval:ste:22'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libcupsys1-dev is earlier than 1.0.4-10' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:49' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:39'/>
      <state state_ref='oval:org.debian.oval:ste:22'/>
    </dpkginfo_test>
    <dpkginfo_test comment='cupsys is earlier than 1.0.4-10' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:50' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:40'/>
      <state state_ref='oval:org.debian.oval:ste:22'/>
    </dpkginfo_test>
    <dpkginfo_test comment='cupsys-bsd is earlier than 1.0.4-10' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:51' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:41'/>
      <state state_ref='oval:org.debian.oval:ste:22'/>
    </dpkginfo_test>
    <dpkginfo_test comment='snmp is earlier than 4.1.1-2.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:52' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:42'/>
      <state state_ref='oval:org.debian.oval:ste:23'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libsnmp4.1 is earlier than 4.1.1-2.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:53' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:43'/>
      <state state_ref='oval:org.debian.oval:ste:23'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libsnmp4.1-dev is earlier than 4.1.1-2.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:54' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:44'/>
      <state state_ref='oval:org.debian.oval:ste:23'/>
    </dpkginfo_test>
    <dpkginfo_test comment='snmpd is earlier than 4.1.1-2.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:55' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:45'/>
      <state state_ref='oval:org.debian.oval:ste:23'/>
    </dpkginfo_test>
    <dpkginfo_test comment='hanterm is earlier than 3.3.1p17-5.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:56' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:46'/>
      <state state_ref='oval:org.debian.oval:ste:24'/>
    </dpkginfo_test>
    <dpkginfo_test comment='ncurses-term is earlier than 5.0-6.0potato2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:57' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:47'/>
      <state state_ref='oval:org.debian.oval:ste:25'/>
    </dpkginfo_test>
    <dpkginfo_test comment='ncurses-base is earlier than 5.0-6.0potato2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:58' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:48'/>
      <state state_ref='oval:org.debian.oval:ste:25'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libncurses5-dev is earlier than 5.0-6.0potato2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:59' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:49'/>
      <state state_ref='oval:org.debian.oval:ste:25'/>
    </dpkginfo_test>
    <dpkginfo_test comment='ncurses-bin is earlier than 5.0-6.0potato2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:60' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:50'/>
      <state state_ref='oval:org.debian.oval:ste:25'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libncurses5-dbg is earlier than 5.0-6.0potato2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:61' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:51'/>
      <state state_ref='oval:org.debian.oval:ste:25'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libncurses5 is earlier than 5.0-6.0potato2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:62' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:52'/>
      <state state_ref='oval:org.debian.oval:ste:25'/>
    </dpkginfo_test>
    <dpkginfo_test comment='gnujsp is earlier than 1.0.0-5' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:63' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:53'/>
      <state state_ref='oval:org.debian.oval:ste:26'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php4-dev is earlier than 4.0.3pl1-0potato3' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:64' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:54'/>
      <state state_ref='oval:org.debian.oval:ste:27'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-doc is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:65' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:55'/>
      <state state_ref='oval:org.debian.oval:ste:28'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php4-cgi-mhash is earlier than 4.0.3pl1-0potato3' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:66' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:56'/>
      <state state_ref='oval:org.debian.oval:ste:29'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-cgi-snmp is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:67' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:57'/>
      <state state_ref='oval:org.debian.oval:ste:30'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php4-cgi-pgsql is earlier than 4.0.3pl1-0potato3' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:68' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:58'/>
      <state state_ref='oval:org.debian.oval:ste:31'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-snmp is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:69' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:59'/>
      <state state_ref='oval:org.debian.oval:ste:32'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-magick is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:70' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:60'/>
      <state state_ref='oval:org.debian.oval:ste:32'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php4-cgi-ldap is earlier than 4.0.3pl1-0potato3' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:71' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:61'/>
      <state state_ref='oval:org.debian.oval:ste:33'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php4-mhash is earlier than 4.0.3pl1-0potato3' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:72' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:62'/>
      <state state_ref='oval:org.debian.oval:ste:33'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-cgi-pgsql is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:73' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:63'/>
      <state state_ref='oval:org.debian.oval:ste:34'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-cgi-ldap is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:74' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:64'/>
      <state state_ref='oval:org.debian.oval:ste:34'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php4-cgi-imap is earlier than 4.0.3pl1-0potato3' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:75' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:65'/>
      <state state_ref='oval:org.debian.oval:ste:35'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-dev is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:76' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:66'/>
      <state state_ref='oval:org.debian.oval:ste:36'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-cgi is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:77' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:67'/>
      <state state_ref='oval:org.debian.oval:ste:36'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php4-mysql is earlier than 4.0.3pl1-0potato3' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:78' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:68'/>
      <state state_ref='oval:org.debian.oval:ste:37'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-cgi-imap is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:79' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:69'/>
      <state state_ref='oval:org.debian.oval:ste:38'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php4 is earlier than 4.0.3pl1-0potato3' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:80' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:70'/>
      <state state_ref='oval:org.debian.oval:ste:39'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php4-imap is earlier than 4.0.3pl1-0potato3' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:81' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:71'/>
      <state state_ref='oval:org.debian.oval:ste:39'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php4-cgi is earlier than 4.0.3pl1-0potato3' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:82' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:72'/>
      <state state_ref='oval:org.debian.oval:ste:39'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3 is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:83' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:73'/>
      <state state_ref='oval:org.debian.oval:ste:40'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php4-pgsql is earlier than 4.0.3pl1-0potato3' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:84' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:74'/>
      <state state_ref='oval:org.debian.oval:ste:41'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-mhash is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:85' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:75'/>
      <state state_ref='oval:org.debian.oval:ste:42'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php4-snmp is earlier than 4.0.3pl1-0potato3' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:86' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:76'/>
      <state state_ref='oval:org.debian.oval:ste:43'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-pgsql is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:87' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:77'/>
      <state state_ref='oval:org.debian.oval:ste:44'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php4-ldap is earlier than 4.0.3pl1-0potato3' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:88' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:78'/>
      <state state_ref='oval:org.debian.oval:ste:45'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php4-xml is earlier than 4.0.3pl1-0potato3' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:89' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:79'/>
      <state state_ref='oval:org.debian.oval:ste:45'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-cgi-xml is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:90' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:80'/>
      <state state_ref='oval:org.debian.oval:ste:46'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-mysql is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:91' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:81'/>
      <state state_ref='oval:org.debian.oval:ste:46'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-gd is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:92' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:82'/>
      <state state_ref='oval:org.debian.oval:ste:46'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-xml is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:93' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:83'/>
      <state state_ref='oval:org.debian.oval:ste:46'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-cgi-mhash is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:94' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:84'/>
      <state state_ref='oval:org.debian.oval:ste:46'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php4-cgi-xml is earlier than 4.0.3pl1-0potato3' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:95' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:85'/>
      <state state_ref='oval:org.debian.oval:ste:47'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-cgi-magick is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:96' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:86'/>
      <state state_ref='oval:org.debian.oval:ste:48'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php4-cgi-snmp is earlier than 4.0.3pl1-0potato3' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:97' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:87'/>
      <state state_ref='oval:org.debian.oval:ste:49'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php4-gd is earlier than 4.0.3pl1-0potato3' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:98' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:88'/>
      <state state_ref='oval:org.debian.oval:ste:49'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php4-cgi-gd is earlier than 4.0.3pl1-0potato3' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:99' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:89'/>
      <state state_ref='oval:org.debian.oval:ste:49'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-imap is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:100' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:90'/>
      <state state_ref='oval:org.debian.oval:ste:50'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-ldap is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:101' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:91'/>
      <state state_ref='oval:org.debian.oval:ste:50'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-cgi-gd is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:102' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:92'/>
      <state state_ref='oval:org.debian.oval:ste:50'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-cgi-mysql is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:103' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:93'/>
      <state state_ref='oval:org.debian.oval:ste:50'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php4-cgi-mysql is earlier than 4.0.3pl1-0potato3' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:104' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:94'/>
      <state state_ref='oval:org.debian.oval:ste:51'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-dev is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:105' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:66'/>
      <state state_ref='oval:org.debian.oval:ste:52'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-cgi-mhash is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:106' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:84'/>
      <state state_ref='oval:org.debian.oval:ste:52'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-pgsql is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:107' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:77'/>
      <state state_ref='oval:org.debian.oval:ste:52'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-cgi-snmp is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:108' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:57'/>
      <state state_ref='oval:org.debian.oval:ste:52'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-cgi-magick is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:109' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:86'/>
      <state state_ref='oval:org.debian.oval:ste:52'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-magick is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:110' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:60'/>
      <state state_ref='oval:org.debian.oval:ste:52'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-mysql is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:111' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:81'/>
      <state state_ref='oval:org.debian.oval:ste:52'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-cgi is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:112' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:67'/>
      <state state_ref='oval:org.debian.oval:ste:52'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-snmp is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:113' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:59'/>
      <state state_ref='oval:org.debian.oval:ste:52'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-cgi-xml is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:114' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:80'/>
      <state state_ref='oval:org.debian.oval:ste:52'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-mhash is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:115' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:75'/>
      <state state_ref='oval:org.debian.oval:ste:52'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-cgi-imap is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:116' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:69'/>
      <state state_ref='oval:org.debian.oval:ste:52'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3 is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:117' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:73'/>
      <state state_ref='oval:org.debian.oval:ste:52'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-ldap is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:118' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:91'/>
      <state state_ref='oval:org.debian.oval:ste:52'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-imap is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:119' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:90'/>
      <state state_ref='oval:org.debian.oval:ste:52'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-cgi-gd is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:120' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:92'/>
      <state state_ref='oval:org.debian.oval:ste:52'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-cgi-pgsql is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:121' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:63'/>
      <state state_ref='oval:org.debian.oval:ste:52'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-cgi-mysql is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:122' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:93'/>
      <state state_ref='oval:org.debian.oval:ste:52'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-gd is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:123' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:82'/>
      <state state_ref='oval:org.debian.oval:ste:52'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-cgi-ldap is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:124' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:64'/>
      <state state_ref='oval:org.debian.oval:ste:52'/>
    </dpkginfo_test>
    <dpkginfo_test comment='php3-xml is earlier than 3.0.18-0potato1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:125' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:83'/>
      <state state_ref='oval:org.debian.oval:ste:52'/>
    </dpkginfo_test>
    <dpkginfo_test comment='cfs is earlier than 1.3.3-8.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:126' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:95'/>
      <state state_ref='oval:org.debian.oval:ste:53'/>
    </dpkginfo_test>
    <dpkginfo_test comment='cvs-doc is earlier than 1.10.7-9' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:127' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:96'/>
      <state state_ref='oval:org.debian.oval:ste:54'/>
    </dpkginfo_test>
    <dpkginfo_test comment='cvs is earlier than 1.10.7-9' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:128' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:97'/>
      <state state_ref='oval:org.debian.oval:ste:54'/>
    </dpkginfo_test>
    <dpkginfo_test comment='xsane is earlier than 0.50-5.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:129' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:98'/>
      <state state_ref='oval:org.debian.oval:ste:55'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libapache-mod-ssl-doc is earlier than 2.4.10-1.3.9-1potato1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:130' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:99'/>
      <state state_ref='oval:org.debian.oval:ste:56'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libapache-mod-ssl is earlier than 2.4.10-1.3.9-1potato1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:131' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:100'/>
      <state state_ref='oval:org.debian.oval:ste:56'/>
    </dpkginfo_test>
    <dpkginfo_test comment='apache-ssl is earlier than 1.3.9.13-4' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:132' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:101'/>
      <state state_ref='oval:org.debian.oval:ste:57'/>
    </dpkginfo_test>
    <dpkginfo_test comment='xtell is earlier than 1.91.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:133' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:102'/>
      <state state_ref='oval:org.debian.oval:ste:58'/>
    </dpkginfo_test>
    <dpkginfo_test comment='erlang-java is earlier than 49.1-10.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:134' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:103'/>
      <state state_ref='oval:org.debian.oval:ste:59'/>
    </dpkginfo_test>
    <dpkginfo_test comment='erlang-base is earlier than 49.1-10.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:135' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:104'/>
      <state state_ref='oval:org.debian.oval:ste:59'/>
    </dpkginfo_test>
    <dpkginfo_test comment='freeamp-doc is earlier than 2.0.6-2.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:136' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:105'/>
      <state state_ref='oval:org.debian.oval:ste:60'/>
    </dpkginfo_test>
    <dpkginfo_test comment='erlang-erl is earlier than 49.1-10.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:137' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:106'/>
      <state state_ref='oval:org.debian.oval:ste:61'/>
    </dpkginfo_test>
    <dpkginfo_test comment='rsync is earlier than 2.3.2-1.6' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:138' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:34'/>
      <state state_ref='oval:org.debian.oval:ste:62'/>
    </dpkginfo_test>
    <dpkginfo_test comment='zlib-bin is earlier than 1.1.3-5.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:139' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:107'/>
      <state state_ref='oval:org.debian.oval:ste:63'/>
    </dpkginfo_test>
    <dpkginfo_test comment='amaya is earlier than 2.4-1potato1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:140' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:108'/>
      <state state_ref='oval:org.debian.oval:ste:64'/>
    </dpkginfo_test>
    <dpkginfo_test comment='dictd is earlier than 1.4.9-9potato1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:141' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:109'/>
      <state state_ref='oval:org.debian.oval:ste:65'/>
    </dpkginfo_test>
    <dpkginfo_test comment='ppp is earlier than 2.3.11-1.5' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:142' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:110'/>
      <state state_ref='oval:org.debian.oval:ste:66'/>
    </dpkginfo_test>
    <dpkginfo_test comment='dict is earlier than 1.4.9-9potato1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:143' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:111'/>
      <state state_ref='oval:org.debian.oval:ste:67'/>
    </dpkginfo_test>
    <dpkginfo_test comment='zlib1g is earlier than 1.1.3-5.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:144' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:112'/>
      <state state_ref='oval:org.debian.oval:ste:68'/>
    </dpkginfo_test>
    <dpkginfo_test comment='vrweb is earlier than 1.5-5.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:145' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:113'/>
      <state state_ref='oval:org.debian.oval:ste:69'/>
    </dpkginfo_test>
    <dpkginfo_test comment='zlib1g-dev is earlier than 1.1.3-5.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:146' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:114'/>
      <state state_ref='oval:org.debian.oval:ste:70'/>
    </dpkginfo_test>
    <dpkginfo_test comment='freeamp is earlier than 2.0.6-2.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:147' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:115'/>
      <state state_ref='oval:org.debian.oval:ste:71'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libfreeamp-esound is earlier than 2.0.6-2.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:148' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:116'/>
      <state state_ref='oval:org.debian.oval:ste:71'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libfreeamp-alsa is earlier than 2.0.6-2.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:149' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:117'/>
      <state state_ref='oval:org.debian.oval:ste:71'/>
    </dpkginfo_test>
    <dpkginfo_test comment='zlib1-altdev is earlier than 1.1.3-5.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:150' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:118'/>
      <state state_ref='oval:org.debian.oval:ste:72'/>
    </dpkginfo_test>
    <dpkginfo_test comment='zlib1 is earlier than 1.1.3-5.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:151' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:119'/>
      <state state_ref='oval:org.debian.oval:ste:72'/>
    </dpkginfo_test>
    <dpkginfo_test comment='erlang is earlier than 49.1-10.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:152' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:120'/>
      <state state_ref='oval:org.debian.oval:ste:73'/>
    </dpkginfo_test>
    <dpkginfo_test comment='mirrordir is earlier than 0.10.48-2.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:153' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:121'/>
      <state state_ref='oval:org.debian.oval:ste:74'/>
    </dpkginfo_test>
    <dpkginfo_test comment='mirrordir is earlier than 0.10.48-2.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:154' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:121'/>
      <state state_ref='oval:org.debian.oval:ste:74'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libfreeamp-alsa is earlier than 2.0.6-2.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:155' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:117'/>
      <state state_ref='oval:org.debian.oval:ste:75'/>
    </dpkginfo_test>
    <dpkginfo_test comment='freeamp is earlier than 2.0.6-2.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:156' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:115'/>
      <state state_ref='oval:org.debian.oval:ste:75'/>
    </dpkginfo_test>
    <dpkginfo_test comment='mirrordir is earlier than 0.10.48-2.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:157' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:121'/>
      <state state_ref='oval:org.debian.oval:ste:76'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libfreeamp-esound is earlier than 2.0.6-2.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:158' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:116'/>
      <state state_ref='oval:org.debian.oval:ste:77'/>
    </dpkginfo_test>
    <dpkginfo_test comment='mirrordir is earlier than 0.10.48-2.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:159' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:121'/>
      <state state_ref='oval:org.debian.oval:ste:78'/>
    </dpkginfo_test>
    <dpkginfo_test comment='rsync is earlier than 2.3.2-1.6' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:160' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:34'/>
      <state state_ref='oval:org.debian.oval:ste:79'/>
    </dpkginfo_test>
    <dpkginfo_test comment='zlib-bin is earlier than 1.1.3-5.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:161' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:107'/>
      <state state_ref='oval:org.debian.oval:ste:80'/>
    </dpkginfo_test>
    <dpkginfo_test comment='dictd is earlier than 1.4.9-9potato1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:162' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:109'/>
      <state state_ref='oval:org.debian.oval:ste:81'/>
    </dpkginfo_test>
    <dpkginfo_test comment='ppp is earlier than 2.3.11-1.5' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:163' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:110'/>
      <state state_ref='oval:org.debian.oval:ste:82'/>
    </dpkginfo_test>
    <dpkginfo_test comment='dict is earlier than 1.4.9-9potato1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:164' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:111'/>
      <state state_ref='oval:org.debian.oval:ste:83'/>
    </dpkginfo_test>
    <dpkginfo_test comment='zlib1g is earlier than 1.1.3-5.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:165' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:112'/>
      <state state_ref='oval:org.debian.oval:ste:84'/>
    </dpkginfo_test>
    <dpkginfo_test comment='zlib1 is earlier than 1.1.3-5.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:166' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:119'/>
      <state state_ref='oval:org.debian.oval:ste:84'/>
    </dpkginfo_test>
    <dpkginfo_test comment='zlib1g-dev is earlier than 1.1.3-5.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:167' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:114'/>
      <state state_ref='oval:org.debian.oval:ste:84'/>
    </dpkginfo_test>
    <dpkginfo_test comment='zlib1-altdev is earlier than 1.1.3-5.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:168' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:118'/>
      <state state_ref='oval:org.debian.oval:ste:84'/>
    </dpkginfo_test>
    <dpkginfo_test comment='mirrordir is earlier than 0.10.48-2.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:169' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:121'/>
      <state state_ref='oval:org.debian.oval:ste:85'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libfreeamp-alsa is earlier than 2.0.6-2.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:170' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:117'/>
      <state state_ref='oval:org.debian.oval:ste:86'/>
    </dpkginfo_test>
    <dpkginfo_test comment='erlang is earlier than 49.1-10.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:171' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:120'/>
      <state state_ref='oval:org.debian.oval:ste:87'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libfreeamp-esound is earlier than 2.0.6-2.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:172' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:116'/>
      <state state_ref='oval:org.debian.oval:ste:88'/>
    </dpkginfo_test>
    <dpkginfo_test comment='freeamp is earlier than 2.0.6-2.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:173' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:115'/>
      <state state_ref='oval:org.debian.oval:ste:88'/>
    </dpkginfo_test>
    <dpkginfo_test comment='listar-cgi is earlier than 0.129a-2.potato1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:174' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:122'/>
      <state state_ref='oval:org.debian.oval:ste:89'/>
    </dpkginfo_test>
    <dpkginfo_test comment='listar is earlier than 0.129a-2.potato1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:175' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:123'/>
      <state state_ref='oval:org.debian.oval:ste:89'/>
    </dpkginfo_test>
    <dpkginfo_test comment='mtr is earlier than 0.41-6' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:176' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:124'/>
      <state state_ref='oval:org.debian.oval:ste:90'/>
    </dpkginfo_test>
    <dpkginfo_test comment='analog is earlier than 5.22-0potato1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:177' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:125'/>
      <state state_ref='oval:org.debian.oval:ste:91'/>
    </dpkginfo_test>
    <dpkginfo_test comment='imp is earlier than 2.2.6-0.potato.5' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:178' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:126'/>
      <state state_ref='oval:org.debian.oval:ste:92'/>
    </dpkginfo_test>
    <dpkginfo_test comment='horde is earlier than 1.2.6-0.potato.5' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:179' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:127'/>
      <state state_ref='oval:org.debian.oval:ste:93'/>
    </dpkginfo_test>
    <dpkginfo_test comment='xpilot is earlier than 4.1.0-4.U.4alpha2.4.potato1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:180' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:128'/>
      <state state_ref='oval:org.debian.oval:ste:94'/>
    </dpkginfo_test>
    <dpkginfo_test comment='xpilot-client-nas is earlier than 4.1.0-4.U.4alpha2.4.potato1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:181' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:129'/>
      <state state_ref='oval:org.debian.oval:ste:94'/>
    </dpkginfo_test>
    <dpkginfo_test comment='xpilot-client-rplay is earlier than 4.1.0-4.U.4alpha2.4.potato1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:182' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:130'/>
      <state state_ref='oval:org.debian.oval:ste:94'/>
    </dpkginfo_test>
    <dpkginfo_test comment='xpilot-client-nosound is earlier than 4.1.0-4.U.4alpha2.4.potato1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:183' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:131'/>
      <state state_ref='oval:org.debian.oval:ste:94'/>
    </dpkginfo_test>
    <dpkginfo_test comment='xpilot-server is earlier than 4.1.0-4.U.4alpha2.4.potato1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:184' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:132'/>
      <state state_ref='oval:org.debian.oval:ste:94'/>
    </dpkginfo_test>
    <dpkginfo_test comment='sudo is earlier than 1.6.2p2-2.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:185' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:14'/>
      <state state_ref='oval:org.debian.oval:ste:95'/>
    </dpkginfo_test>
    <dpkginfo_test comment='uucp is earlier than 1.06.1-11potato3' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:186' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:133'/>
      <state state_ref='oval:org.debian.oval:ste:96'/>
    </dpkginfo_test>
    <dpkginfo_test comment='ethereal is earlier than 0.8.0-3potato' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:187' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:134'/>
      <state state_ref='oval:org.debian.oval:ste:97'/>
    </dpkginfo_test>
    <dpkginfo_test comment='apache-doc is earlier than 1.3.9-14.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:188' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:135'/>
      <state state_ref='oval:org.debian.oval:ste:98'/>
    </dpkginfo_test>
    <dpkginfo_test comment='apache is earlier than 1.3.9-14.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:189' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:136'/>
      <state state_ref='oval:org.debian.oval:ste:98'/>
    </dpkginfo_test>
    <dpkginfo_test comment='apache-common is earlier than 1.3.9-14.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:190' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:137'/>
      <state state_ref='oval:org.debian.oval:ste:98'/>
    </dpkginfo_test>
    <dpkginfo_test comment='apache-dev is earlier than 1.3.9-14.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:191' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:138'/>
      <state state_ref='oval:org.debian.oval:ste:98'/>
    </dpkginfo_test>
    <dpkginfo_test comment='apache-ssl is earlier than 1.3.9.13-4.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:192' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:101'/>
      <state state_ref='oval:org.debian.oval:ste:99'/>
    </dpkginfo_test>
    <dpkginfo_test comment='apache-perl is earlier than 1.3.9-14.1-1.21.20000309-1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:193' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:139'/>
      <state state_ref='oval:org.debian.oval:ste:100'/>
    </dpkginfo_test>
    <dpkginfo_test comment='ssleay is earlier than 0.9.6c-0.potato.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:194' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:140'/>
      <state state_ref='oval:org.debian.oval:ste:101'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libssl-dev is earlier than 0.9.6c-0.potato.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:195' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:141'/>
      <state state_ref='oval:org.debian.oval:ste:101'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libssl0.9.6 is earlier than 0.9.6c-0.potato.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:196' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:142'/>
      <state state_ref='oval:org.debian.oval:ste:101'/>
    </dpkginfo_test>
    <dpkginfo_test comment='openssl is earlier than 0.9.6c-0.potato.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:197' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:143'/>
      <state state_ref='oval:org.debian.oval:ste:101'/>
    </dpkginfo_test>
    <dpkginfo_test comment='ssh is earlier than 3.4p1-0.0potato1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:198' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:144'/>
      <state state_ref='oval:org.debian.oval:ste:102'/>
    </dpkginfo_test>
    <dpkginfo_test comment='ssh-askpass-gnome is earlier than 3.4p1-0.0potato1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:199' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:145'/>
      <state state_ref='oval:org.debian.oval:ste:102'/>
    </dpkginfo_test>
    <textfilecontent_test comment='Debian GNU/Linux 3.0 is installed' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#independent' id='oval:org.debian.oval:tst:200' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:1'/>
      <state state_ref='oval:org.debian.oval:ste:103'/>
    </textfilecontent_test>
    <dpkginfo_test comment='ssh is earlier than 3.4p1-0.0woody1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:201' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:144'/>
      <state state_ref='oval:org.debian.oval:ste:104'/>
    </dpkginfo_test>
    <dpkginfo_test comment='ssh-askpass-gnome is earlier than 3.4p1-0.0woody1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:202' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:145'/>
      <state state_ref='oval:org.debian.oval:ste:104'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libapache-mod-ssl-doc is earlier than 2.4.10-1.3.9-1potato2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:203' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:99'/>
      <state state_ref='oval:org.debian.oval:ste:105'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libapache-mod-ssl is earlier than 2.4.10-1.3.9-1potato2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:204' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:100'/>
      <state state_ref='oval:org.debian.oval:ste:105'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libapache-mod-ssl-doc is earlier than 2.8.9-2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:205' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:99'/>
      <state state_ref='oval:org.debian.oval:ste:106'/>
    </dpkginfo_test>
    <uname_test comment='Installed architecture is s390' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#unix' id='oval:org.debian.oval:tst:206' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:8'/>
      <state state_ref='oval:org.debian.oval:ste:107'/>
    </uname_test>
    <uname_test comment='Installed architecture is mips' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#unix' id='oval:org.debian.oval:tst:207' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:8'/>
      <state state_ref='oval:org.debian.oval:ste:108'/>
    </uname_test>
    <uname_test comment='Installed architecture is mipsel' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#unix' id='oval:org.debian.oval:tst:208' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:8'/>
      <state state_ref='oval:org.debian.oval:ste:109'/>
    </uname_test>
    <dpkginfo_test comment='libapache-mod-ssl is earlier than 2.8.9-2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:209' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:100'/>
      <state state_ref='oval:org.debian.oval:ste:106'/>
    </dpkginfo_test>
    <dpkginfo_test comment='ssleay is earlier than 0.9.6c-0.potato.3' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:210' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:140'/>
      <state state_ref='oval:org.debian.oval:ste:110'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libssl-dev is earlier than 0.9.6c-0.potato.4' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:211' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:141'/>
      <state state_ref='oval:org.debian.oval:ste:111'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libssl0.9.6 is earlier than 0.9.6c-0.potato.4' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:212' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:142'/>
      <state state_ref='oval:org.debian.oval:ste:111'/>
    </dpkginfo_test>
    <dpkginfo_test comment='openssl is earlier than 0.9.6c-0.potato.4' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:213' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:143'/>
      <state state_ref='oval:org.debian.oval:ste:111'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libssl09 is earlier than 0.9.4-6.potato.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:214' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:146'/>
      <state state_ref='oval:org.debian.oval:ste:112'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libssl-dev is earlier than 0.9.6c-2.woody.0' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:215' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:141'/>
      <state state_ref='oval:org.debian.oval:ste:113'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libssl0.9.6 is earlier than 0.9.6c-2.woody.0' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:216' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:142'/>
      <state state_ref='oval:org.debian.oval:ste:113'/>
    </dpkginfo_test>
    <dpkginfo_test comment='openssl is earlier than 0.9.6c-2.woody.0' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:217' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:143'/>
      <state state_ref='oval:org.debian.oval:ste:113'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libssl09 is earlier than 0.9.4-6.woody.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:218' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:146'/>
      <state state_ref='oval:org.debian.oval:ste:114'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libssl-dev is earlier than 0.9.6c-2.woody.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:219' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:141'/>
      <state state_ref='oval:org.debian.oval:ste:115'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libssl0.9.6 is earlier than 0.9.6c-2.woody.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:220' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:142'/>
      <state state_ref='oval:org.debian.oval:ste:115'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libssl095a is earlier than 0.9.5a-6.woody.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:221' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:147'/>
      <state state_ref='oval:org.debian.oval:ste:116'/>
    </dpkginfo_test>
    <dpkginfo_test comment='openssl is earlier than 0.9.6c-2.woody.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:222' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:143'/>
      <state state_ref='oval:org.debian.oval:ste:117'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libssl-dev is earlier than 0.9.6c-2.woody.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:223' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:141'/>
      <state state_ref='oval:org.debian.oval:ste:117'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libssl0.9.6 is earlier than 0.9.6c-2.woody.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:224' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:142'/>
      <state state_ref='oval:org.debian.oval:ste:117'/>
    </dpkginfo_test>
    <dpkginfo_test comment='openssl is earlier than 0.9.6c-2.woody.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:225' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:143'/>
      <state state_ref='oval:org.debian.oval:ste:117'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libssl-dev is earlier than 0.9.6c-2.woody.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:226' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:141'/>
      <state state_ref='oval:org.debian.oval:ste:117'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libssl0.9.6 is earlier than 0.9.6c-2.woody.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:227' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:142'/>
      <state state_ref='oval:org.debian.oval:ste:117'/>
    </dpkginfo_test>
    <dpkginfo_test comment='openssl is earlier than 0.9.6c-2.woody.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:228' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:143'/>
      <state state_ref='oval:org.debian.oval:ste:117'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libssl-dev is earlier than 0.9.6c-2.woody.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:229' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:141'/>
      <state state_ref='oval:org.debian.oval:ste:117'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libssl0.9.6 is earlier than 0.9.6c-2.woody.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:230' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:142'/>
      <state state_ref='oval:org.debian.oval:ste:117'/>
    </dpkginfo_test>
    <dpkginfo_test comment='openssl is earlier than 0.9.6c-2.woody.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:231' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:143'/>
      <state state_ref='oval:org.debian.oval:ste:117'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libssl-dev is earlier than 0.9.6c-2.woody.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:232' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:141'/>
      <state state_ref='oval:org.debian.oval:ste:117'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libssl0.9.6 is earlier than 0.9.6c-2.woody.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:233' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:142'/>
      <state state_ref='oval:org.debian.oval:ste:117'/>
    </dpkginfo_test>
    <dpkginfo_test comment='openssl is earlier than 0.9.6c-2.woody.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:234' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:143'/>
      <state state_ref='oval:org.debian.oval:ste:117'/>
    </dpkginfo_test>
    <uname_test comment='Installed architecture is ia64' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#unix' id='oval:org.debian.oval:tst:235' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:8'/>
      <state state_ref='oval:org.debian.oval:ste:118'/>
    </uname_test>
    <dpkginfo_test comment='libssl-dev is earlier than 0.9.6c-2.woody.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:236' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:141'/>
      <state state_ref='oval:org.debian.oval:ste:117'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libssl0.9.6 is earlier than 0.9.6c-2.woody.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:237' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:142'/>
      <state state_ref='oval:org.debian.oval:ste:117'/>
    </dpkginfo_test>
    <dpkginfo_test comment='openssl is earlier than 0.9.6c-2.woody.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:238' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:143'/>
      <state state_ref='oval:org.debian.oval:ste:117'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libssl-dev is earlier than 0.9.6c-2.woody.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:239' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:141'/>
      <state state_ref='oval:org.debian.oval:ste:117'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libssl0.9.6 is earlier than 0.9.6c-2.woody.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:240' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:142'/>
      <state state_ref='oval:org.debian.oval:ste:117'/>
    </dpkginfo_test>
    <dpkginfo_test comment='openssl is earlier than 0.9.6c-2.woody.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:241' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:143'/>
      <state state_ref='oval:org.debian.oval:ste:117'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libssl-dev is earlier than 0.9.6c-2.woody.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:242' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:141'/>
      <state state_ref='oval:org.debian.oval:ste:117'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libssl0.9.6 is earlier than 0.9.6c-2.woody.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:243' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:142'/>
      <state state_ref='oval:org.debian.oval:ste:117'/>
    </dpkginfo_test>
    <dpkginfo_test comment='openssl is earlier than 0.9.6c-2.woody.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:244' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:143'/>
      <state state_ref='oval:org.debian.oval:ste:117'/>
    </dpkginfo_test>
    <uname_test comment='Installed architecture is hppa' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#unix' id='oval:org.debian.oval:tst:245' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:8'/>
      <state state_ref='oval:org.debian.oval:ste:119'/>
    </uname_test>
    <dpkginfo_test comment='libssl-dev is earlier than 0.9.6c-2.woody.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:246' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:141'/>
      <state state_ref='oval:org.debian.oval:ste:117'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libssl0.9.6 is earlier than 0.9.6c-2.woody.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:247' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:142'/>
      <state state_ref='oval:org.debian.oval:ste:117'/>
    </dpkginfo_test>
    <dpkginfo_test comment='openssl is earlier than 0.9.6c-2.woody.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:248' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:143'/>
      <state state_ref='oval:org.debian.oval:ste:117'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libmm10-dev is earlier than 1.0.11-1.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:249' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:148'/>
      <state state_ref='oval:org.debian.oval:ste:120'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libmm10 is earlier than 1.0.11-1.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:250' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:149'/>
      <state state_ref='oval:org.debian.oval:ste:120'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libmm11-dev is earlier than 1.1.3-6.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:251' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:150'/>
      <state state_ref='oval:org.debian.oval:ste:121'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libmm11 is earlier than 1.1.3-6.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:252' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:151'/>
      <state state_ref='oval:org.debian.oval:ste:121'/>
    </dpkginfo_test>
    <dpkginfo_test comment='gallery is earlier than 1.2.5-7.woody.0' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:253' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:152'/>
      <state state_ref='oval:org.debian.oval:ste:122'/>
    </dpkginfo_test>
    <dpkginfo_test comment='super is earlier than 3.12.2-2.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:254' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:153'/>
      <state state_ref='oval:org.debian.oval:ste:123'/>
    </dpkginfo_test>
    <dpkginfo_test comment='super is earlier than 3.16.1-1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:255' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:153'/>
      <state state_ref='oval:org.debian.oval:ste:124'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libpng2-dev is earlier than 1.0.12-3.woody.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:256' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:154'/>
      <state state_ref='oval:org.debian.oval:ste:125'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libpng3 is earlier than 1.2.1-1.1.woody.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:257' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:155'/>
      <state state_ref='oval:org.debian.oval:ste:126'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libpng-dev is earlier than 1.2.1-1.1.woody.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:258' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:156'/>
      <state state_ref='oval:org.debian.oval:ste:126'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libpng2 is earlier than 1.0.12-3.woody.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:259' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:157'/>
      <state state_ref='oval:org.debian.oval:ste:127'/>
    </dpkginfo_test>
    <dpkginfo_test comment='mpack is earlier than 1.5-5potato2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:260' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:158'/>
      <state state_ref='oval:org.debian.oval:ste:128'/>
    </dpkginfo_test>
    <dpkginfo_test comment='mpack is earlier than 1.5-7woody2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:261' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:158'/>
      <state state_ref='oval:org.debian.oval:ste:129'/>
    </dpkginfo_test>
    <dpkginfo_test comment='openafs-modules-source is earlier than 1.2.3final2-6' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:262' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:159'/>
      <state state_ref='oval:org.debian.oval:ste:130'/>
    </dpkginfo_test>
    <dpkginfo_test comment='openafs-kpasswd is earlier than 1.2.3final2-6' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:263' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:160'/>
      <state state_ref='oval:org.debian.oval:ste:130'/>
    </dpkginfo_test>
    <dpkginfo_test comment='openafs-client is earlier than 1.2.3final2-6' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:264' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:161'/>
      <state state_ref='oval:org.debian.oval:ste:130'/>
    </dpkginfo_test>
    <dpkginfo_test comment='openafs-fileserver is earlier than 1.2.3final2-6' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:265' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:162'/>
      <state state_ref='oval:org.debian.oval:ste:130'/>
    </dpkginfo_test>
    <dpkginfo_test comment='openafs-dbserver is earlier than 1.2.3final2-6' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:266' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:163'/>
      <state state_ref='oval:org.debian.oval:ste:130'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libopenafs-dev is earlier than 1.2.3final2-6' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:267' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:164'/>
      <state state_ref='oval:org.debian.oval:ste:130'/>
    </dpkginfo_test>
    <dpkginfo_test comment='krb5-doc is earlier than 1.2.4-5woody1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:268' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:165'/>
      <state state_ref='oval:org.debian.oval:ste:131'/>
    </dpkginfo_test>
    <dpkginfo_test comment='krb5-rsh-server is earlier than 1.2.4-5woody1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:269' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:166'/>
      <state state_ref='oval:org.debian.oval:ste:131'/>
    </dpkginfo_test>
    <dpkginfo_test comment='krb5-telnetd is earlier than 1.2.4-5woody1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:270' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:167'/>
      <state state_ref='oval:org.debian.oval:ste:131'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libkrb53 is earlier than 1.2.4-5woody1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:271' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:168'/>
      <state state_ref='oval:org.debian.oval:ste:131'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libkrb5-dev is earlier than 1.2.4-5woody1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:272' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:169'/>
      <state state_ref='oval:org.debian.oval:ste:131'/>
    </dpkginfo_test>
    <dpkginfo_test comment='krb5-ftpd is earlier than 1.2.4-5woody1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:273' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:170'/>
      <state state_ref='oval:org.debian.oval:ste:131'/>
    </dpkginfo_test>
    <dpkginfo_test comment='krb5-admin-server is earlier than 1.2.4-5woody1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:274' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:171'/>
      <state state_ref='oval:org.debian.oval:ste:131'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libkadm55 is earlier than 1.2.4-5woody1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:275' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:172'/>
      <state state_ref='oval:org.debian.oval:ste:131'/>
    </dpkginfo_test>
    <dpkginfo_test comment='krb5-user is earlier than 1.2.4-5woody1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:276' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:173'/>
      <state state_ref='oval:org.debian.oval:ste:131'/>
    </dpkginfo_test>
    <dpkginfo_test comment='krb5-clients is earlier than 1.2.4-5woody1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:277' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:174'/>
      <state state_ref='oval:org.debian.oval:ste:131'/>
    </dpkginfo_test>
    <dpkginfo_test comment='krb5-kdc is earlier than 1.2.4-5woody1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:278' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:175'/>
      <state state_ref='oval:org.debian.oval:ste:131'/>
    </dpkginfo_test>
    <dpkginfo_test comment='wwwoffle is earlier than 2.5c-10.4' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:279' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:176'/>
      <state state_ref='oval:org.debian.oval:ste:132'/>
    </dpkginfo_test>
    <dpkginfo_test comment='wwwoffle is earlier than 2.7a-1.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:280' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:176'/>
      <state state_ref='oval:org.debian.oval:ste:133'/>
    </dpkginfo_test>
    <dpkginfo_test comment='tinyproxy is earlier than 1.4.3-2woody2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:281' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:177'/>
      <state state_ref='oval:org.debian.oval:ste:134'/>
    </dpkginfo_test>
    <dpkginfo_test comment='dietlibc-doc is earlier than 0.12-2.4' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:282' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:178'/>
      <state state_ref='oval:org.debian.oval:ste:135'/>
    </dpkginfo_test>
    <dpkginfo_test comment='dietlibc-dev is earlier than 0.12-2.4' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:283' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:179'/>
      <state state_ref='oval:org.debian.oval:ste:135'/>
    </dpkginfo_test>
    <dpkginfo_test comment='mailman is earlier than 1.1-10.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:284' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:180'/>
      <state state_ref='oval:org.debian.oval:ste:136'/>
    </dpkginfo_test>
    <dpkginfo_test comment='mailman is earlier than 2.0.11-1woody4' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:285' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:180'/>
      <state state_ref='oval:org.debian.oval:ste:137'/>
    </dpkginfo_test>
    <dpkginfo_test comment='hylafax-doc is earlier than 4.0.2-14.3' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:286' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:181'/>
      <state state_ref='oval:org.debian.oval:ste:138'/>
    </dpkginfo_test>
    <dpkginfo_test comment='hylafax-client is earlier than 4.0.2-14.3' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:287' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:182'/>
      <state state_ref='oval:org.debian.oval:ste:138'/>
    </dpkginfo_test>
    <dpkginfo_test comment='hylafax-server is earlier than 4.0.2-14.3' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:288' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:183'/>
      <state state_ref='oval:org.debian.oval:ste:138'/>
    </dpkginfo_test>
    <dpkginfo_test comment='hylafax-doc is earlier than 4.1.1-1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:289' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:181'/>
      <state state_ref='oval:org.debian.oval:ste:139'/>
    </dpkginfo_test>
    <dpkginfo_test comment='hylafax-client is earlier than 4.1.1-1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:290' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:182'/>
      <state state_ref='oval:org.debian.oval:ste:139'/>
    </dpkginfo_test>
    <dpkginfo_test comment='hylafax-server is earlier than 4.1.1-1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:291' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:183'/>
      <state state_ref='oval:org.debian.oval:ste:139'/>
    </dpkginfo_test>
    <dpkginfo_test comment='glibc-doc is earlier than 2.1.3-24' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:292' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:16'/>
      <state state_ref='oval:org.debian.oval:ste:140'/>
    </dpkginfo_test>
    <dpkginfo_test comment='i18ndata is earlier than 2.1.3-24' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:293' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:17'/>
      <state state_ref='oval:org.debian.oval:ste:140'/>
    </dpkginfo_test>
    <dpkginfo_test comment='nscd is earlier than 2.1.3-24' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:294' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:18'/>
      <state state_ref='oval:org.debian.oval:ste:140'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libc6-dev is earlier than 2.1.3-24' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:295' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:19'/>
      <state state_ref='oval:org.debian.oval:ste:140'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libc6-pic is earlier than 2.1.3-24' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:296' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:20'/>
      <state state_ref='oval:org.debian.oval:ste:140'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libc6 is earlier than 2.1.3-24' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:297' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:21'/>
      <state state_ref='oval:org.debian.oval:ste:140'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libc6-prof is earlier than 2.1.3-24' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:298' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:22'/>
      <state state_ref='oval:org.debian.oval:ste:140'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libc6-dbg is earlier than 2.1.3-24' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:299' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:23'/>
      <state state_ref='oval:org.debian.oval:ste:140'/>
    </dpkginfo_test>
    <dpkginfo_test comment='locales is earlier than 2.1.3-24' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:300' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:24'/>
      <state state_ref='oval:org.debian.oval:ste:140'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libc6.1-pic is earlier than 2.1.3-24' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:301' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:25'/>
      <state state_ref='oval:org.debian.oval:ste:140'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libc6.1-dev is earlier than 2.1.3-24' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:302' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:26'/>
      <state state_ref='oval:org.debian.oval:ste:140'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libc6.1-dbg is earlier than 2.1.3-24' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:303' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:27'/>
      <state state_ref='oval:org.debian.oval:ste:140'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libnss1-compat is earlier than 2.1.3-24' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:304' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:28'/>
      <state state_ref='oval:org.debian.oval:ste:140'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libc6.1-prof is earlier than 2.1.3-24' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:305' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:29'/>
      <state state_ref='oval:org.debian.oval:ste:140'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libc6.1 is earlier than 2.1.3-24' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:306' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:30'/>
      <state state_ref='oval:org.debian.oval:ste:140'/>
    </dpkginfo_test>
    <dpkginfo_test comment='nscd is earlier than 2.1.3-24' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:307' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:18'/>
      <state state_ref='oval:org.debian.oval:ste:140'/>
    </dpkginfo_test>
    <dpkginfo_test comment='locales is earlier than 2.1.3-24' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:308' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:24'/>
      <state state_ref='oval:org.debian.oval:ste:140'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libnss1-compat is earlier than 2.1.3-24' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:309' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:28'/>
      <state state_ref='oval:org.debian.oval:ste:140'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libnss1-compat is earlier than 2.1.3-24' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:310' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:28'/>
      <state state_ref='oval:org.debian.oval:ste:140'/>
    </dpkginfo_test>
    <dpkginfo_test comment='glibc-doc is earlier than 2.2.5-11.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:311' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:16'/>
      <state state_ref='oval:org.debian.oval:ste:141'/>
    </dpkginfo_test>
    <dpkginfo_test comment='locales is earlier than 2.2.5-11.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:312' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:24'/>
      <state state_ref='oval:org.debian.oval:ste:141'/>
    </dpkginfo_test>
    <dpkginfo_test comment='nscd is earlier than 2.2.5-11.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:313' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:18'/>
      <state state_ref='oval:org.debian.oval:ste:141'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libc6-dev is earlier than 2.2.5-11.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:314' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:19'/>
      <state state_ref='oval:org.debian.oval:ste:141'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libc6-pic is earlier than 2.2.5-11.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:315' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:20'/>
      <state state_ref='oval:org.debian.oval:ste:141'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libc6 is earlier than 2.2.5-11.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:316' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:21'/>
      <state state_ref='oval:org.debian.oval:ste:141'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libc6-prof is earlier than 2.2.5-11.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:317' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:22'/>
      <state state_ref='oval:org.debian.oval:ste:141'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libc6-dbg is earlier than 2.2.5-11.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:318' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:23'/>
      <state state_ref='oval:org.debian.oval:ste:141'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libc6.1-pic is earlier than 2.2.5-11.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:319' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:25'/>
      <state state_ref='oval:org.debian.oval:ste:141'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libc6.1-dev is earlier than 2.2.5-11.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:320' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:26'/>
      <state state_ref='oval:org.debian.oval:ste:141'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libc6.1-dbg is earlier than 2.2.5-11.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:321' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:27'/>
      <state state_ref='oval:org.debian.oval:ste:141'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libc6.1-prof is earlier than 2.2.5-11.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:322' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:29'/>
      <state state_ref='oval:org.debian.oval:ste:141'/>
    </dpkginfo_test>
    <dpkginfo_test comment='nscd is earlier than 2.2.5-11.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:323' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:18'/>
      <state state_ref='oval:org.debian.oval:ste:141'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libc6.1 is earlier than 2.2.5-11.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:324' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:30'/>
      <state state_ref='oval:org.debian.oval:ste:141'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libc6-sparc64 is earlier than 2.2.5-11.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:325' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:184'/>
      <state state_ref='oval:org.debian.oval:ste:141'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libc6-dev-sparc64 is earlier than 2.2.5-11.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:326' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:185'/>
      <state state_ref='oval:org.debian.oval:ste:141'/>
    </dpkginfo_test>
    <dpkginfo_test comment='interchange-ui is earlier than 4.8.3.20020306-1.woody.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:327' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:186'/>
      <state state_ref='oval:org.debian.oval:ste:142'/>
    </dpkginfo_test>
    <dpkginfo_test comment='interchange-cat-foundation is earlier than 4.8.3.20020306-1.woody.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:328' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:187'/>
      <state state_ref='oval:org.debian.oval:ste:142'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libapache-mod-interchange is earlier than 4.8.3.20020306-1.woody.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:329' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:188'/>
      <state state_ref='oval:org.debian.oval:ste:142'/>
    </dpkginfo_test>
    <dpkginfo_test comment='interchange is earlier than 4.8.3.20020306-1.woody.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:330' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:189'/>
      <state state_ref='oval:org.debian.oval:ste:142'/>
    </dpkginfo_test>
    <dpkginfo_test comment='xinetd is earlier than 2.3.4-1.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:331' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:190'/>
      <state state_ref='oval:org.debian.oval:ste:143'/>
    </dpkginfo_test>
    <dpkginfo_test comment='l2tpd is earlier than 0.67-1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:332' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:191'/>
      <state state_ref='oval:org.debian.oval:ste:144'/>
    </dpkginfo_test>
    <dpkginfo_test comment='mantis is earlier than 0.17.1-2.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:333' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:192'/>
      <state state_ref='oval:org.debian.oval:ste:145'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libfam-dev is earlier than 2.6.6.1-5.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:334' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:193'/>
      <state state_ref='oval:org.debian.oval:ste:146'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libfam0 is earlier than 2.6.6.1-5.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:335' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:194'/>
      <state state_ref='oval:org.debian.oval:ste:146'/>
    </dpkginfo_test>
    <dpkginfo_test comment='fam is earlier than 2.6.6.1-5.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:336' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:195'/>
      <state state_ref='oval:org.debian.oval:ste:146'/>
    </dpkginfo_test>
    <dpkginfo_test comment='kdelibs3-doc is earlier than 2.2.2-13.woody.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:337' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:196'/>
      <state state_ref='oval:org.debian.oval:ste:147'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libarts is earlier than 2.2.2-13.woody.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:338' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:197'/>
      <state state_ref='oval:org.debian.oval:ste:147'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libkmid-alsa is earlier than 2.2.2-13.woody.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:339' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:198'/>
      <state state_ref='oval:org.debian.oval:ste:147'/>
    </dpkginfo_test>
    <dpkginfo_test comment='kdelibs3-bin is earlier than 2.2.2-13.woody.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:340' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:199'/>
      <state state_ref='oval:org.debian.oval:ste:147'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libarts-alsa is earlier than 2.2.2-13.woody.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:341' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:200'/>
      <state state_ref='oval:org.debian.oval:ste:147'/>
    </dpkginfo_test>
    <dpkginfo_test comment='kdelibs3 is earlier than 2.2.2-13.woody.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:342' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:201'/>
      <state state_ref='oval:org.debian.oval:ste:147'/>
    </dpkginfo_test>
    <dpkginfo_test comment='kdelibs3-cups is earlier than 2.2.2-13.woody.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:343' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:202'/>
      <state state_ref='oval:org.debian.oval:ste:147'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libkmid-dev is earlier than 2.2.2-13.woody.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:344' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:203'/>
      <state state_ref='oval:org.debian.oval:ste:147'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libkmid is earlier than 2.2.2-13.woody.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:345' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:204'/>
      <state state_ref='oval:org.debian.oval:ste:147'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libarts-dev is earlier than 2.2.2-13.woody.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:346' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:205'/>
      <state state_ref='oval:org.debian.oval:ste:147'/>
    </dpkginfo_test>
    <dpkginfo_test comment='kdelibs-dev is earlier than 2.2.2-13.woody.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:347' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:206'/>
      <state state_ref='oval:org.debian.oval:ste:147'/>
    </dpkginfo_test>
    <dpkginfo_test comment='epic4-script-light is earlier than 2.7.30p5-1.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:348' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:207'/>
      <state state_ref='oval:org.debian.oval:ste:148'/>
    </dpkginfo_test>
    <dpkginfo_test comment='irssi-text is earlier than 0.8.4-3.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:349' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:208'/>
      <state state_ref='oval:org.debian.oval:ste:149'/>
    </dpkginfo_test>
    <dpkginfo_test comment='gaim-common is earlier than 0.58-2.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:350' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:209'/>
      <state state_ref='oval:org.debian.oval:ste:150'/>
    </dpkginfo_test>
    <dpkginfo_test comment='gaim-gnome is earlier than 0.58-2.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:351' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:210'/>
      <state state_ref='oval:org.debian.oval:ste:150'/>
    </dpkginfo_test>
    <dpkginfo_test comment='gaim is earlier than 0.58-2.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:352' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:211'/>
      <state state_ref='oval:org.debian.oval:ste:150'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python-elisp is earlier than 1.5.2-10potato13' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:353' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:212'/>
      <state state_ref='oval:org.debian.oval:ste:151'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python-regrtest is earlier than 1.5.2-10potato13' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:354' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:213'/>
      <state state_ref='oval:org.debian.oval:ste:151'/>
    </dpkginfo_test>
    <dpkginfo_test comment='idle is earlier than 1.5.2-10potato13' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:355' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:214'/>
      <state state_ref='oval:org.debian.oval:ste:151'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python-examples is earlier than 1.5.2-10potato13' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:356' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:215'/>
      <state state_ref='oval:org.debian.oval:ste:151'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python-tk is earlier than 1.5.2-10potato13' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:357' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:216'/>
      <state state_ref='oval:org.debian.oval:ste:151'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python-base is earlier than 1.5.2-10potato13' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:358' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:217'/>
      <state state_ref='oval:org.debian.oval:ste:151'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python-zlib is earlier than 1.5.2-10potato13' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:359' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:218'/>
      <state state_ref='oval:org.debian.oval:ste:151'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python-mpz is earlier than 1.5.2-10potato13' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:360' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:219'/>
      <state state_ref='oval:org.debian.oval:ste:151'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python-gdbm is earlier than 1.5.2-10potato13' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:361' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:220'/>
      <state state_ref='oval:org.debian.oval:ste:151'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python-dev is earlier than 1.5.2-10potato13' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:362' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:221'/>
      <state state_ref='oval:org.debian.oval:ste:151'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python-tk is earlier than 2.1.3-3.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:363' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:216'/>
      <state state_ref='oval:org.debian.oval:ste:152'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python2.1-doc is earlier than 2.1.3-3.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:364' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:222'/>
      <state state_ref='oval:org.debian.oval:ste:152'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python1.5-examples is earlier than 1.5.2-23.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:365' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:223'/>
      <state state_ref='oval:org.debian.oval:ste:153'/>
    </dpkginfo_test>
    <dpkginfo_test comment='idle-python1.5 is earlier than 1.5.2-23.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:366' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:224'/>
      <state state_ref='oval:org.debian.oval:ste:153'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python is earlier than 2.1.3-3.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:367' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:225'/>
      <state state_ref='oval:org.debian.oval:ste:154'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python-xmlbase is earlier than 2.1.3-3.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:368' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:226'/>
      <state state_ref='oval:org.debian.oval:ste:154'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python-examples is earlier than 2.1.3-3.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:369' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:215'/>
      <state state_ref='oval:org.debian.oval:ste:154'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python2.2-examples is earlier than 2.2.1-4.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:370' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:227'/>
      <state state_ref='oval:org.debian.oval:ste:155'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python2.2-elisp is earlier than 2.2.1-4.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:371' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:228'/>
      <state state_ref='oval:org.debian.oval:ste:155'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python-elisp is earlier than 2.1.3-3.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:372' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:212'/>
      <state state_ref='oval:org.debian.oval:ste:156'/>
    </dpkginfo_test>
    <dpkginfo_test comment='idle is earlier than 2.1.3-3.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:373' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:214'/>
      <state state_ref='oval:org.debian.oval:ste:156'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python2.1-examples is earlier than 2.1.3-3.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:374' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:229'/>
      <state state_ref='oval:org.debian.oval:ste:156'/>
    </dpkginfo_test>
    <dpkginfo_test comment='idle-python2.1 is earlier than 2.1.3-3.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:375' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:230'/>
      <state state_ref='oval:org.debian.oval:ste:156'/>
    </dpkginfo_test>
    <dpkginfo_test comment='idle-python2.2 is earlier than 2.2.1-4.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:376' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:231'/>
      <state state_ref='oval:org.debian.oval:ste:157'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python-mpz is earlier than 2.1.3-3.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:377' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:219'/>
      <state state_ref='oval:org.debian.oval:ste:158'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python-gdbm is earlier than 2.1.3-3.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:378' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:220'/>
      <state state_ref='oval:org.debian.oval:ste:158'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python2.2-doc is earlier than 2.2.1-4.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:379' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:232'/>
      <state state_ref='oval:org.debian.oval:ste:159'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python-doc is earlier than 2.1.3-3.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:380' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:233'/>
      <state state_ref='oval:org.debian.oval:ste:160'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python-dev is earlier than 2.1.3-3.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:381' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:221'/>
      <state state_ref='oval:org.debian.oval:ste:160'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python2.1-elisp is earlier than 2.1.3-3.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:382' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:234'/>
      <state state_ref='oval:org.debian.oval:ste:160'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python1.5 is earlier than 1.5.2-23.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:383' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:235'/>
      <state state_ref='oval:org.debian.oval:ste:161'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python2.1-gdbm is earlier than 2.1.3-3.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:384' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:236'/>
      <state state_ref='oval:org.debian.oval:ste:162'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python1.5-mpz is earlier than 1.5.2-23.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:385' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:237'/>
      <state state_ref='oval:org.debian.oval:ste:163'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python1.5-tk is earlier than 1.5.2-23.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:386' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:238'/>
      <state state_ref='oval:org.debian.oval:ste:163'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python1.5-dev is earlier than 1.5.2-23.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:387' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:239'/>
      <state state_ref='oval:org.debian.oval:ste:163'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python2.2 is earlier than 2.2.1-4.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:388' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:240'/>
      <state state_ref='oval:org.debian.oval:ste:164'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python2.1 is earlier than 2.1.3-3.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:389' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:241'/>
      <state state_ref='oval:org.debian.oval:ste:165'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python2.1-dev is earlier than 2.1.3-3.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:390' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:242'/>
      <state state_ref='oval:org.debian.oval:ste:165'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python2.1-mpz is earlier than 2.1.3-3.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:391' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:243'/>
      <state state_ref='oval:org.debian.oval:ste:165'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python2.1-tk is earlier than 2.1.3-3.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:392' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:244'/>
      <state state_ref='oval:org.debian.oval:ste:165'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python1.5-gdbm is earlier than 1.5.2-23.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:393' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:245'/>
      <state state_ref='oval:org.debian.oval:ste:166'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python2.2-gdbm is earlier than 2.2.1-4.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:394' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:246'/>
      <state state_ref='oval:org.debian.oval:ste:167'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python2.2-xmlbase is earlier than 2.2.1-4.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:395' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:247'/>
      <state state_ref='oval:org.debian.oval:ste:167'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python2.1-xmlbase is earlier than 2.1.3-3.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:396' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:248'/>
      <state state_ref='oval:org.debian.oval:ste:168'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python2.2-mpz is earlier than 2.2.1-4.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:397' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:249'/>
      <state state_ref='oval:org.debian.oval:ste:169'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python2.2-tk is earlier than 2.2.1-4.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:398' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:250'/>
      <state state_ref='oval:org.debian.oval:ste:169'/>
    </dpkginfo_test>
    <dpkginfo_test comment='python2.2-dev is earlier than 2.2.1-4.2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:399' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:251'/>
      <state state_ref='oval:org.debian.oval:ste:169'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libscrollkeeper0 is earlier than 0.3.6-3.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:400' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:252'/>
      <state state_ref='oval:org.debian.oval:ste:170'/>
    </dpkginfo_test>
    <dpkginfo_test comment='libscrollkeeper-dev is earlier than 0.3.6-3.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:401' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:253'/>
      <state state_ref='oval:org.debian.oval:ste:170'/>
    </dpkginfo_test>
    <dpkginfo_test comment='scrollkeeper is earlier than 0.3.6-3.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:402' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:254'/>
      <state state_ref='oval:org.debian.oval:ste:170'/>
    </dpkginfo_test>
    <dpkginfo_test comment='mantis is earlier than 0.17.1-2.5' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:403' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:192'/>
      <state state_ref='oval:org.debian.oval:ste:171'/>
    </dpkginfo_test>
    <dpkginfo_test comment='ethereal is earlier than 0.8.0-4potato.1' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:404' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:134'/>
      <state state_ref='oval:org.debian.oval:ste:172'/>
    </dpkginfo_test>
    <dpkginfo_test comment='ethereal-dev is earlier than 0.9.4-1woody2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:405' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:255'/>
      <state state_ref='oval:org.debian.oval:ste:173'/>
    </dpkginfo_test>
    <dpkginfo_test comment='ethereal-common is earlier than 0.9.4-1woody2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:406' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:256'/>
      <state state_ref='oval:org.debian.oval:ste:173'/>
    </dpkginfo_test>
    <dpkginfo_test comment='tethereal is earlier than 0.9.4-1woody2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:407' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval:obj:257'/>
      <state state_ref='oval:org.debian.oval:ste:173'/>
    </dpkginfo_test>
    <dpkginfo_test comment='ethereal is earlier than 0.9.4-1woody2' xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux' id='oval:org.debian.oval:tst:408' version='1' check='all' check_existence='at_least_one_exists'>
      <object object_ref='oval:org.debian.oval: