<?xml version='1.0' encoding='UTF-8'?>
<oval_definitions xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5' xmlns:unix-def='http://oval.mitre.org/XMLSchema/oval-definitions-5#unix' xmlns:ind-def ='http://oval.mitre.org/XMLSchema/oval-definitions-5#independent' xmlns:oval='http://oval.mitre.org/XMLSchema/oval-common-5' xmlns:oval-def='http://oval.mitre.org/XMLSchema/oval-definitions-5' xmlns:xsi='http://www.w3.org/2001/XMLSchema-instance' xsi:schemaLocation='http://oval.mitre.org/XMLSchema/oval-definitions-5#independent independent-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd' xmlns:linux-def='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux'>
  <generator>
    <oval:product_name>Debian</oval:product_name>
    <oval:schema_version>5.3</oval:schema_version>
    <oval:timestamp>2008-11-19T19:32:46.188-04:00</oval:timestamp>
  </generator>
  <definitions>
    <definition version='1' id='oval:org.debian:def:406' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>lftp</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0963' ref_id='CVE-2003-0963'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-01-05</date>
          <moreinfo>
Ulf Härnhammar discovered a buffer overflow in lftp, a set of
sophisticated command-line FTP/HTTP client programs.  An attacker
could create a carefully crafted directory on a website so that the
execution of an 'ls' or 'rels' command would lead to the execution of
arbitrary code on the client machine.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='lftp DPKG is earlier than 2.4.9-1woody2' test_ref='oval:org.debian.oval:tst:2'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:407' class='vulnerability'>
      <metadata>
        <title>buffer overflows</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>ethereal</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0925' ref_id='CVE-2003-0925'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0926' ref_id='CVE-2003-0926'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0927' ref_id='CVE-2003-0927'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1012' ref_id='CVE-2003-1012'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1013' ref_id='CVE-2003-1013'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-01-05</date>
          <moreinfo>
Several vulnerabilities were discovered upstream in ethereal, a
network traffic analyzer.  The Common Vulnerabilities and Exposures
project identifies the following problems:
A buffer overflow allows remote attackers to cause a denial of
   service and possibly execute arbitrary code via a malformed GTP
   MSISDN string.
Via certain malformed ISAKMP or MEGACO packets remote attackers are
   able to cause a denial of service (crash).
A heap-based buffer overflow allows remote attackers to cause a
   denial of service (crash) and possibly execute arbitrary code via
   the SOCKS dissector.
The SMB dissector allows remote attackers to cause a denial of
   service via a malformed SMB packet that triggers a segmentation
   fault during processing of selected packets.
The Q.931 dissector allows remote attackers to cause a denial of
   service (crash) via a malformed Q.931, which triggers a null
   dereference.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='ethereal-dev DPKG is earlier than 0.9.4-1woody6' test_ref='oval:org.debian.oval:tst:3'/>
            <criterion comment='ethereal-common DPKG is earlier than 0.9.4-1woody6' test_ref='oval:org.debian.oval:tst:4'/>
            <criterion comment='tethereal DPKG is earlier than 0.9.4-1woody6' test_ref='oval:org.debian.oval:tst:5'/>
            <criterion comment='ethereal DPKG is earlier than 0.9.4-1woody6' test_ref='oval:org.debian.oval:tst:6'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:408' class='vulnerability'>
      <metadata>
        <title>integer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>screen</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0972' ref_id='CVE-2003-0972'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-01-05</date>
          <moreinfo>
Timo Sirainen reported a vulnerability in screen, a terminal
multiplexor with VT100/ANSI terminal emulation, that can lead an
attacker to gain group utmp privileges.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='screen DPKG is earlier than 3.9.11-5woody1' test_ref='oval:org.debian.oval:tst:7'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:409' class='vulnerability'>
      <metadata>
        <title>denial of service</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>bind</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0914' ref_id='CVE-2003-0914'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-01-05</date>
          <moreinfo>
A vulnerability was discovered in BIND, a domain name server, whereby
a malicious name server could return authoritative negative responses
with a large TTL (time-to-live) value, thereby rendering a domain name
unreachable.  A successful attack would require that a vulnerable BIND
instance submit a query to a malicious nameserver. 
The bind9 package is not affected by this vulnerability.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='bind-doc DPKG is earlier than 8.3.3-2.0woody2' test_ref='oval:org.debian.oval:tst:9'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='bind DPKG is earlier than 8.3.3-2.0woody2' test_ref='oval:org.debian.oval:tst:10'/>
            <criterion comment='bind-dev DPKG is earlier than 8.3.3-2.0woody2' test_ref='oval:org.debian.oval:tst:11'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:410' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>libnids</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0850' ref_id='CVE-2003-0850'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-01-05</date>
          <moreinfo>
A vulnerability was discovered in libnids, a library used to analyze
IP network traffic, whereby a carefully crafted TCP datagram could
cause memory corruption and potentially execute arbitrary code with
the privileges of the user executing a program which uses libnids
(such as dsniff).</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libnids-dev DPKG is earlier than 1.16-3woody1' test_ref='oval:org.debian.oval:tst:12'/>
            <criterion comment='libnids1 DPKG is earlier than 1.16-3woody1' test_ref='oval:org.debian.oval:tst:13'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:411' class='vulnerability'>
      <metadata>
        <title>format string vulnerability</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>mpg321</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0969' ref_id='CVE-2003-0969'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-01-05</date>
          <moreinfo>
A vulnerability was discovered in mpg321, a command-line mp3 player,
whereby user-supplied strings were passed to printf(3) unsafely.  This
vulnerability could be exploited by a remote attacker to overwrite
memory, and possibly execute arbitrary code.  In order for this
vulnerability to be exploited, mpg321 would need to play a malicious
mp3 file (including via HTTP streaming).</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='mpg321 DPKG is earlier than 0.2.10.2' test_ref='oval:org.debian.oval:tst:14'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:412' class='vulnerability'>
      <metadata>
        <title>buffer overflows</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>nd</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0014' ref_id='CVE-2004-0014'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-01-05</date>
          <moreinfo>
Multiple vulnerabilities were discovered in nd, a command-line WebDAV
interface, whereby long strings received from the remote server could
overflow fixed-length buffers.  This vulnerability could be exploited
by a remote attacker in control of a malicious WebDAV server to
execute arbitrary code if the server was accessed by a vulnerable
version of nd.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='nd DPKG is earlier than 0.5.0-1woody1' test_ref='oval:org.debian.oval:tst:15'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:413' class='vulnerability'>
      <metadata>
        <title>missing boundary check</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>kernel-source-2.4.18, kernel-image-2.4.18-1-i386</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0985' ref_id='CVE-2003-0985'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-01-06</date>
          <moreinfo>
Paul Starzetz &lt;a href="http://isec.pl/vulnerabilities/isec-0013-mremap.txt">discovered&lt;/A> a flaw in bounds checking in mremap() in the
Linux kernel (present in version 2.4.x and 2.6.x) which may allow
a local attacker to gain root privileges.
Version 2.2 is not affected by this bug, since it doesn't support the
MREMAP_FIXED flag (as &lt;a href="http://seclists.org/lists/fulldisclosure/2004/Jan/0095.html">clarified later&lt;/A>).</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-source-2.4.18 DPKG is earlier than 2.4.18-14.1' test_ref='oval:org.debian.oval:tst:16'/>
              <criterion comment='kernel-doc-2.4.18 DPKG is earlier than 2.4.18-14.1' test_ref='oval:org.debian.oval:tst:17'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-image-2.4.18-1-586tsc DPKG is earlier than 2.4.18-12.1' test_ref='oval:org.debian.oval:tst:19'/>
              <criterion comment='kernel-pcmcia-modules-2.4.18-1-586tsc DPKG is earlier than 2.4.18-12.1' test_ref='oval:org.debian.oval:tst:20'/>
              <criterion comment='kernel-image-2.4.18-bf2.4 DPKG is earlier than 2.4.18-5woody6' test_ref='oval:org.debian.oval:tst:21'/>
              <criterion comment='kernel-pcmcia-modules-2.4.18-1-686 DPKG is earlier than 2.4.18-12.1' test_ref='oval:org.debian.oval:tst:22'/>
              <criterion comment='kernel-headers-2.4.18-1-586tsc DPKG is earlier than 2.4.18-12.1' test_ref='oval:org.debian.oval:tst:23'/>
              <criterion comment='kernel-pcmcia-modules-2.4.18-1-k6 DPKG is earlier than 2.4.18-12.1' test_ref='oval:org.debian.oval:tst:24'/>
              <criterion comment='kernel-pcmcia-modules-2.4.18-1-k7 DPKG is earlier than 2.4.18-12.1' test_ref='oval:org.debian.oval:tst:25'/>
              <criterion comment='kernel-pcmcia-modules-2.4.18-1-686-smp DPKG is earlier than 2.4.18-12.1' test_ref='oval:org.debian.oval:tst:26'/>
              <criterion comment='kernel-image-2.4.18-1-686 DPKG is earlier than 2.4.18-12.1' test_ref='oval:org.debian.oval:tst:27'/>
              <criterion comment='kernel-headers-2.4.18-bf2.4 DPKG is earlier than 2.4.18-5woody6' test_ref='oval:org.debian.oval:tst:28'/>
              <criterion comment='kernel-headers-2.4.18-1 DPKG is earlier than 2.4.18-12.1' test_ref='oval:org.debian.oval:tst:29'/>
              <criterion comment='kernel-headers-2.4.18-1-k6 DPKG is earlier than 2.4.18-12.1' test_ref='oval:org.debian.oval:tst:30'/>
              <criterion comment='kernel-headers-2.4.18-1-386 DPKG is earlier than 2.4.18-12.1' test_ref='oval:org.debian.oval:tst:31'/>
              <criterion comment='kernel-image-2.4.18-1-686-smp DPKG is earlier than 2.4.18-12.1' test_ref='oval:org.debian.oval:tst:32'/>
              <criterion comment='kernel-headers-2.4.18-1-686 DPKG is earlier than 2.4.18-12.1' test_ref='oval:org.debian.oval:tst:33'/>
              <criterion comment='kernel-headers-2.4.18-1-k7 DPKG is earlier than 2.4.18-12.1' test_ref='oval:org.debian.oval:tst:34'/>
              <criterion comment='kernel-image-2.4.18-1-k6 DPKG is earlier than 2.4.18-12.1' test_ref='oval:org.debian.oval:tst:35'/>
              <criterion comment='kernel-image-2.4.18-1-386 DPKG is earlier than 2.4.18-12.1' test_ref='oval:org.debian.oval:tst:36'/>
              <criterion comment='kernel-pcmcia-modules-2.4.18-1-386 DPKG is earlier than 2.4.18-12.1' test_ref='oval:org.debian.oval:tst:37'/>
              <criterion comment='kernel-image-2.4.18-1-k7 DPKG is earlier than 2.4.18-12.1' test_ref='oval:org.debian.oval:tst:38'/>
              <criterion comment='kernel-headers-2.4.18-1-686-smp DPKG is earlier than 2.4.18-12.1' test_ref='oval:org.debian.oval:tst:39'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:414' class='vulnerability'>
      <metadata>
        <title>denial of service</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>jabber</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0013' ref_id='CVE-2004-0013'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-01-06</date>
          <moreinfo>
A vulnerability was discovered in jabber, an instant messaging server,
whereby a bug in the handling of SSL connections could cause the
server process to crash, resulting in a denial of service.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='jabber DPKG is earlier than 1.4.2a-1.1woody1' test_ref='oval:org.debian.oval:tst:40'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:415' class='vulnerability'>
      <metadata>
        <title>denial of service</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>zebra</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0795' ref_id='CVE-2003-0795'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0858' ref_id='CVE-2003-0858'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-01-06</date>
          <moreinfo>
Two vulnerabilities were discovered in zebra, an IP routing daemon:</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='zebra-doc DPKG is earlier than 0.92a-5woody2' test_ref='oval:org.debian.oval:tst:41'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='zebra DPKG is earlier than 0.92a-5woody2' test_ref='oval:org.debian.oval:tst:42'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:416' class='vulnerability'>
      <metadata>
        <title>buffer overflow, directory traversal</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>fsp</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1022' ref_id='CVE-2003-1022'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0011' ref_id='CVE-2004-0011'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-01-06</date>
          <moreinfo>
A vulnerability was discovered in fsp, client utilities for File Service Protocol (FSP), whereby a remote user could both
escape from the FSP root directory (&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-1022">CAN-2003-1022&lt;/a>), and also overflow
a fixed-length buffer to execute arbitrary code (&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0011">CAN-2004-0011&lt;/a>).</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='fsp DPKG is earlier than 2.81.b3-3.1woody1' test_ref='oval:org.debian.oval:tst:43'/>
            <criterion comment='fspd DPKG is earlier than 2.81.b3-3.1woody1' test_ref='oval:org.debian.oval:tst:44'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:417' class='vulnerability'>
      <metadata>
        <title>missing boundary check</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>kernel-patch-2.4.18-powerpc, kernel-image-2.4.18-1-alpha</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0961' ref_id='CVE-2003-0961'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0985' ref_id='CVE-2003-0985'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-01-07</date>
          <moreinfo>
Paul Starzetz discovered a flaw in bounds checking in mremap() in the
Linux kernel (present in version 2.4.x and 2.6.x) which may allow a
local attacker to gain root privileges.  Version 2.2 is not affected
by this bug.
Andrew Morton discovered a missing boundary check for the brk system
call which can be used to craft a local root exploit.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-source-2.4.18 DPKG is earlier than 2.4.18-14.1' test_ref='oval:org.debian.oval:tst:45'/>
              <criterion comment='kernel-doc-2.4.18 DPKG is earlier than 2.4.18-14.1' test_ref='oval:org.debian.oval:tst:46'/>
              <criterion comment='kernel-patch-2.4.18-powerpc DPKG is earlier than 2.4.18-1woody3' test_ref='oval:org.debian.oval:tst:47'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:48'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-image-2.4.18-1-generic DPKG is earlier than 2.4.18-11' test_ref='oval:org.debian.oval:tst:49'/>
              <criterion comment='kernel-headers-2.4.18-1 DPKG is earlier than 2.4.18-12' test_ref='oval:org.debian.oval:tst:50'/>
              <criterion comment='kernel-headers-2.4.18-1-smp DPKG is earlier than 2.4.18-12' test_ref='oval:org.debian.oval:tst:51'/>
              <criterion comment='kernel-image-2.4.18-1-smp DPKG is earlier than 2.4.18-11' test_ref='oval:org.debian.oval:tst:52'/>
              <criterion comment='kernel-headers-2.4.18-1-generic DPKG is earlier than 2.4.18-12' test_ref='oval:org.debian.oval:tst:53'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-image-2.4.18-newpmac DPKG is earlier than 2.4.18-1woody3' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='kernel-headers-2.4.18 DPKG is earlier than 2.4.18-1woody3' test_ref='oval:org.debian.oval:tst:56'/>
              <criterion comment='kernel-image-2.4.18-powerpc DPKG is earlier than 2.4.18-1woody3' test_ref='oval:org.debian.oval:tst:57'/>
              <criterion comment='kernel-image-2.4.18-powerpc-smp DPKG is earlier than 2.4.18-1woody3' test_ref='oval:org.debian.oval:tst:58'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:418' class='vulnerability'>
      <metadata>
        <title>privilege leak</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>vbox3</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0015' ref_id='CVE-2004-0015'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-01-07</date>
          <moreinfo>
A bug was discovered in vbox3, a voice response system for isdn4linux,
whereby root privileges were not properly relinquished before
executing a user-supplied tcl script.  By exploiting this
vulnerability, a local user could gain root privileges.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='vbox3 DPKG is earlier than 0.1.7.1' test_ref='oval:org.debian.oval:tst:59'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:419' class='vulnerability'>
      <metadata>
        <title>missing filename sanitising, SQL injection</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>phpgroupware</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0016' ref_id='CVE-2004-0016'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0017' ref_id='CVE-2004-0017'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-01-09</date>
          <moreinfo>
The authors of phpgroupware, a web based groupware system written in
PHP, discovered several vulnerabilities.  The Common Vulnerabilities
and Exposures project identifies the following problems:
In the "calendar" module, "save extension" was not enforced for
  holiday files.  As a result, server-side php scripts may be placed
  in directories that then could be accessed remotely and cause the
  webserver to execute those.  This was resolved by enforcing the
  extension ".txt" for holiday files.
Some SQL injection problems (non-escaping of values used in SQL
  strings) the "calendar" and "infolog" modules.
Additionally, the Debian maintainer adjusted the permissions on world
writable directories that were accidentally created by former postinst
during the installation.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='phpgroupware-admin DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:60'/>
              <criterion comment='phpgroupware-ftp DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:61'/>
              <criterion comment='phpgroupware-wap DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:62'/>
              <criterion comment='phpgroupware-calendar DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:63'/>
              <criterion comment='phpgroupware-tts DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:64'/>
              <criterion comment='phpgroupware-polls DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:65'/>
              <criterion comment='phpgroupware-api-doc DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:66'/>
              <criterion comment='phpgroupware-core-doc DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:67'/>
              <criterion comment='phpgroupware-phpwebhosting DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:68'/>
              <criterion comment='phpgroupware-manual DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:69'/>
              <criterion comment='phpgroupware-addressbook DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:70'/>
              <criterion comment='phpgroupware-img DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:71'/>
              <criterion comment='phpgroupware-projects DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:72'/>
              <criterion comment='phpgroupware-skel DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:73'/>
              <criterion comment='phpgroupware DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:74'/>
              <criterion comment='phpgroupware-email DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:75'/>
              <criterion comment='phpgroupware-stocks DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:76'/>
              <criterion comment='phpgroupware-headlines DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:77'/>
              <criterion comment='phpgroupware-phonelog DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:78'/>
              <criterion comment='phpgroupware-bookkeeping DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:79'/>
              <criterion comment='phpgroupware-todo DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:80'/>
              <criterion comment='phpgroupware-inv DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:81'/>
              <criterion comment='phpgroupware-bookmarks DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:82'/>
              <criterion comment='phpgroupware-developer-tools DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:83'/>
              <criterion comment='phpgroupware-messenger DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:84'/>
              <criterion comment='phpgroupware-infolog DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:85'/>
              <criterion comment='phpgroupware-setup DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:86'/>
              <criterion comment='phpgroupware-registration DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:87'/>
              <criterion comment='phpgroupware-nntp DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:88'/>
              <criterion comment='phpgroupware-chora DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:89'/>
              <criterion comment='phpgroupware-news-admin DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:90'/>
              <criterion comment='phpgroupware-forum DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:91'/>
              <criterion comment='phpgroupware-soap DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:92'/>
              <criterion comment='phpgroupware-chat DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:93'/>
              <criterion comment='phpgroupware-hr DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:94'/>
              <criterion comment='phpgroupware-xmlrpc DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:95'/>
              <criterion comment='phpgroupware-api DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:96'/>
              <criterion comment='phpgroupware-dj DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:97'/>
              <criterion comment='phpgroupware-phpsysinfo DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:98'/>
              <criterion comment='phpgroupware-napster DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:99'/>
              <criterion comment='phpgroupware-brewer DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:100'/>
              <criterion comment='phpgroupware-core DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:101'/>
              <criterion comment='phpgroupware-comic DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:102'/>
              <criterion comment='phpgroupware-filemanager DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:103'/>
              <criterion comment='phpgroupware-preferences DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:104'/>
              <criterion comment='phpgroupware-eldaptir DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:105'/>
              <criterion comment='phpgroupware-notes DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:106'/>
              <criterion comment='phpgroupware-weather DPKG is earlier than 0.9.14-0.RC3.2.woody3' test_ref='oval:org.debian.oval:tst:107'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:420' class='vulnerability'>
      <metadata>
        <title>improperly sanitised input</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>jitterbug</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0028' ref_id='CVE-2004-0028'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-01-12</date>
          <moreinfo>
Steve Kemp discovered a security related problem in jitterbug, a
simple CGI based bug tracking and reporting tool.  Unfortunately the
program executions do not properly sanitize input, which allows an
attacker to execute arbitrary commands on the server hosting the bug
database.  As mitigating factors these attacks are only available to
non-guest users, and accounts for these people must be setup by the
administrator making them "trusted".</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='jitterbug DPKG is earlier than 1.6.2-4.2woody2' test_ref='oval:org.debian.oval:tst:108'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:421' class='vulnerability'>
      <metadata>
        <title>password expiration</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>mod-auth-shadow</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0041' ref_id='CVE-2004-0041'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-01-12</date>
          <moreinfo>
David B Harris discovered a problem with mod-auth-shadow, an Apache
module which authenticates users against the system shadow password
database, where the expiration status of the user's account and
password were not enforced.  This vulnerability would allow an
otherwise authorized user to successfully authenticate, when the
attempt should be rejected due to the expiration parameters.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libapache-mod-auth-shadow DPKG is earlier than 1.3-3.1woody.1' test_ref='oval:org.debian.oval:tst:109'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:422' class='vulnerability'>
      <metadata>
        <title>remote vulnerability</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>cvs</product>
        </affected>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-01-13</date>
          <moreinfo>
The account management of the CVS pserver (which is used to give remote
access to CVS repositories) uses a &lt;kbd>CVSROOT/passwd&lt;/kbd> file in each
repository which contains the accounts and their authentication
information as well as the name of the local unix account to use when a
pserver account is used. Since CVS performed no checking on what unix
account was specified anyone who could modify the &lt;kbd>CVSROOT/passwd&lt;/kbd>
could gain access to all local users on the CVS server, including root.
This has been fixed in upstream version 1.11.11 by preventing pserver
from running as root. For Debian this problem is solved in version
1.11.1p1debian-9 in two different ways:
Additionally, CVS pserver had a bug in parsing module requests which
could be used to create files and directories outside a repository.
This has been fixed upstream in version 1.11.11 and Debian version
1.11.1p1debian-9.
Finally, the umask used for &amp;ldquo;cvs init&amp;rdquo; and
&amp;ldquo;cvs-makerepos&amp;rdquo; has been
changed to prevent repositories from being created with group write
permissions.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='cvs DPKG is earlier than 1.11.1p1debian-9' test_ref='oval:org.debian.oval:tst:110'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:423' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>kernel-image-2.4.17-ia64</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0001' ref_id='CVE-2003-0001'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0018' ref_id='CVE-2003-0018'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0127' ref_id='CVE-2003-0127'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0461' ref_id='CVE-2003-0461'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0462' ref_id='CVE-2003-0462'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0476' ref_id='CVE-2003-0476'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0501' ref_id='CVE-2003-0501'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0550' ref_id='CVE-2003-0550'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0551' ref_id='CVE-2003-0551'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0552' ref_id='CVE-2003-0552'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0961' ref_id='CVE-2003-0961'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0985' ref_id='CVE-2003-0985'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-01-15</date>
          <moreinfo>
The IA-64 maintainers fixed several security related bugs in the Linux
kernel 2.4.17 used for the IA-64 architecture, mostly by backporting
fixes from 2.4.18.  The corrections are listed below with the
identification from the Common Vulnerabilities and Exposures (CVE)
project:
Multiple ethernet network interface card (NIC) device drivers do
    not pad frames with null bytes, which allows remote attackers to
    obtain information from previous packets or kernel memory by using
    malformed packets, as demonstrated by Etherleak.
Linux kernel 2.4.10 through 2.4.21-pre4 does not properly handle
    the O_DIRECT feature, which allows local attackers with write
    privileges to read portions of previously deleted files, or cause
    file system corruption.
The kernel module loader in Linux kernel 2.2.x before 2.2.25, and
    2.4.x before 2.4.21, allows local users to gain root privileges
    by using ptrace to attach to a child process which is spawned by
    the kernel.
The virtual file /proc/tty/driver/serial in Linux 2.4.x reveals
    the exact number of characters used in serial links, which could
    allow local users to obtain potentially sensitive information such
    as the length of passwords.
A race condition in the way env_start and env_end pointers are
    initialized in the execve system call and used in fs/proc/base.c
    on Linux 2.4 allows local users to cause a denial of service
    (crash).
The execve system call in Linux 2.4.x records the file descriptor
    of the executable process in the file table of the calling
    process, which allows local users to gain read access to
    restricted file descriptors.
The /proc filesystem in Linux allows local users to obtain
    sensitive information by opening various entries in /proc/self
    before executing a setuid program, which causes the program to
    fail to change the ownership and permissions of those entries.
The STP protocol, as enabled in Linux 2.4.x, does not provide
    sufficient security by design, which allows attackers to modify
    the bridge topology.
The STP protocol implementation in Linux 2.4.x does not properly
    verify certain lengths, which could allow attackers to cause a
    denial of service.
Linux 2.4.x allows remote attackers to spoof the bridge Forwarding
    table via forged packets whose source addresses are the same as
    the target.
An integer overflow in brk system call (do_brk function) for Linux
    kernel 2.4.22 and earlier allows local users to gain root
    privileges.
The mremap system call (do_mremap) in Linux kernel 2.4 and 2.6
    does not properly perform boundary checks, which allows local
    users to cause a denial of service and possibly gain privileges by
    causing a remapping of a virtual memory area (VMA) to create a
    zero length VMA.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='kernel-source-2.4.17-ia64 DPKG is earlier than 011226.15' test_ref='oval:org.debian.oval:tst:111'/>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:112'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-image-2.4.17-itanium-smp DPKG is earlier than 011226.15' test_ref='oval:org.debian.oval:tst:113'/>
              <criterion comment='kernel-image-2.4.17-mckinley-smp DPKG is earlier than 011226.15' test_ref='oval:org.debian.oval:tst:114'/>
              <criterion comment='kernel-image-2.4.17-mckinley DPKG is earlier than 011226.15' test_ref='oval:org.debian.oval:tst:115'/>
              <criterion comment='kernel-headers-2.4.17-ia64 DPKG is earlier than 011226.15' test_ref='oval:org.debian.oval:tst:116'/>
              <criterion comment='kernel-image-2.4.17-itanium DPKG is earlier than 011226.15' test_ref='oval:org.debian.oval:tst:117'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:424' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>mc</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1023' ref_id='CVE-2003-1023'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-01-16</date>
          <moreinfo>
A vulnerability was discovered in Midnight Commander, a file manager,
whereby a malicious archive (such as a .tar file) could cause
arbitrary code to be executed if opened by Midnight Commander.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:118'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:119'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:120'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:121'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:122'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:112'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:48'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:123'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='gmc DPKG is earlier than 4.5.55-1.2woody2' test_ref='oval:org.debian.oval:tst:124'/>
              <criterion comment='mc DPKG is earlier than 4.5.55-1.2woody2' test_ref='oval:org.debian.oval:tst:125'/>
              <criterion comment='mc-common DPKG is earlier than 4.5.55-1.2woody2' test_ref='oval:org.debian.oval:tst:126'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:425' class='vulnerability'>
      <metadata>
        <title>multiple vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>tcpdump</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1029' ref_id='CVE-2003-1029'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0989' ref_id='CVE-2003-0989'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0055' ref_id='CVE-2004-0055'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0057' ref_id='CVE-2004-0057'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-01-16</date>
          <moreinfo>
Multiple vulnerabilities were discovered in tcpdump, a tool for
inspecting network traffic.  If a vulnerable version of tcpdump
attempted to examine a maliciously constructed packet, a number of
buffer overflows could be exploited to crash tcpdump, or potentially
execute arbitrary code with the privileges of the tcpdump process.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:118'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:119'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:120'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:121'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:122'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:112'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:48'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:123'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='tcpdump DPKG is earlier than 3.6.2-2.7' test_ref='oval:org.debian.oval:tst:127'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:128'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='tcpdump DPKG is earlier than 3.6.2-2.4' test_ref='oval:org.debian.oval:tst:129'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:426' class='vulnerability'>
      <metadata>
        <title>insecure temporary files</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>netpbm-free</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0924' ref_id='CVE-2003-0924'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-01-18</date>
          <moreinfo>
netpbm is a graphics conversion toolkit made up of a large number of
single-purpose programs.  Many of these programs were found to create
temporary files in an insecure manner, which could allow a local
attacker to overwrite files with the privileges of the user invoking a
vulnerable netpbm tool.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:118'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:119'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:120'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:122'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:112'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:48'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:123'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libnetpbm9 DPKG is earlier than 9.20-8.4' test_ref='oval:org.debian.oval:tst:130'/>
              <criterion comment='netpbm DPKG is earlier than 9.20-8.4' test_ref='oval:org.debian.oval:tst:131'/>
              <criterion comment='libnetpbm9-dev DPKG is earlier than 9.20-8.4' test_ref='oval:org.debian.oval:tst:132'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:128'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:121'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libnetpbm9 DPKG is earlier than 9.20-8.3' test_ref='oval:org.debian.oval:tst:133'/>
              <criterion comment='netpbm DPKG is earlier than 9.20-8.3' test_ref='oval:org.debian.oval:tst:134'/>
              <criterion comment='libnetpbm9-dev DPKG is earlier than 9.20-8.3' test_ref='oval:org.debian.oval:tst:135'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:427' class='vulnerability'>
      <metadata>
        <title>missing boundary check</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>kernel-patch-2.4.17-mips</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0985' ref_id='CVE-2003-0985'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-01-19</date>
          <moreinfo>
Paul Starzetz discovered a flaw in bounds checking in mremap() in the
Linux kernel (present in version 2.4.x and 2.6.x) which may allow a
local attacker to gain root privileges.  Version 2.2 is not affected
by this bug.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='kernel-patch-2.4.17-mips DPKG is earlier than 2.4.17-0.020226.2.woody3' test_ref='oval:org.debian.oval:tst:136'/>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:122'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-headers-2.4.17 DPKG is earlier than 2.4.17-0.020226.2.woody3' test_ref='oval:org.debian.oval:tst:137'/>
              <criterion comment='kernel-image-2.4.17-r4k-ip22 DPKG is earlier than 2.4.17-0.020226.2.woody3' test_ref='oval:org.debian.oval:tst:138'/>
              <criterion comment='kernel-image-2.4.17-r5k-ip22 DPKG is earlier than 2.4.17-0.020226.2.woody3' test_ref='oval:org.debian.oval:tst:139'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:128'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='mips-tools DPKG is earlier than 2.4.17-0.020226.2.woody3' test_ref='oval:org.debian.oval:tst:140'/>
              <criterion comment='kernel-headers-2.4.17 DPKG is earlier than 2.4.17-0.020226.2.woody3' test_ref='oval:org.debian.oval:tst:141'/>
              <criterion comment='kernel-image-2.4.17-r4k-kn04 DPKG is earlier than 2.4.17-0.020226.2.woody3' test_ref='oval:org.debian.oval:tst:142'/>
              <criterion comment='kernel-image-2.4.17-r3k-kn02 DPKG is earlier than 2.4.17-0.020226.2.woody3' test_ref='oval:org.debian.oval:tst:143'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:428' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>slocate</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0848' ref_id='CVE-2003-0848'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-01-20</date>
          <moreinfo>
A vulnerability was discovered in slocate, a program to index and
search for files, whereby a specially crafted database could overflow
a heap-based buffer.  This vulnerability could be exploited by a local
attacker to gain the privileges of the "slocate" group, which can
access the global database containing a list of pathnames of all files
on the system, including those which should only be visible to
privileged users.
This problem, and a category of potential similar problems, have been
fixed by modifying slocate to drop privileges before reading a
user-supplied database.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:118'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:119'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:120'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:121'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:122'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:112'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:48'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:123'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='slocate DPKG is earlier than 2.6-1.3.2' test_ref='oval:org.debian.oval:tst:144'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:128'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='slocate DPKG is earlier than 2.6-1.3.1' test_ref='oval:org.debian.oval:tst:145'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:429' class='vulnerability'>
      <metadata>
        <title>cryptographic weakness</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>gnupg</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0971' ref_id='CVE-2003-0971'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-01-26</date>
          <moreinfo>
Phong Nguyen identified a severe bug in the way GnuPG creates and uses
ElGamal keys for signing.  This is a significant security failure
which can lead to a compromise of almost all ElGamal keys used for
signing.
This update disables the use of this type of key.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:118'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:119'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:120'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:121'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:122'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:112'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:48'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:123'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='gnupg DPKG is earlier than 1.0.6-4woody1' test_ref='oval:org.debian.oval:tst:146'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:430' class='vulnerability'>
      <metadata>
        <title>missing privilege release</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>trr19</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0047' ref_id='CVE-2004-0047'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-01-28</date>
          <moreinfo>
Steve Kemp discovered a problem in trr19, a type trainer application
for GNU Emacs, which is written as a pair of setgid() binaries and
wrapper programs which execute commands for GNU Emacs.  However, the
binaries don't drop privileges before executing a command, allowing an
attacker to gain access to the local group games.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:118'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:119'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:120'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:121'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:122'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:112'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:48'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:123'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='trr19 DPKG is earlier than 1.0beta5-15woody1' test_ref='oval:org.debian.oval:tst:147'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:431' class='vulnerability'>
      <metadata>
        <title>information leak</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>perl</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0618' ref_id='CVE-2003-0618'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-02-01</date>
          <moreinfo>
Paul Szabo discovered a number of similar bugs in suidperl, a helper
program to run perl scripts with setuid privileges.  By exploiting
these bugs, an attacker could abuse suidperl to discover information
about files (such as testing for their existence and some of their
permissions) that should not be accessible to unprivileged users.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='perl-modules DPKG is earlier than 5.6.1-8.6' test_ref='oval:org.debian.oval:tst:148'/>
              <criterion comment='perl-doc DPKG is earlier than 5.6.1-8.6' test_ref='oval:org.debian.oval:tst:149'/>
              <criterion comment='libcgi-fast-perl DPKG is earlier than 5.6.1-8.6' test_ref='oval:org.debian.oval:tst:150'/>
            </criteria>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libperl-dev DPKG is earlier than 5.6.1-8.6' test_ref='oval:org.debian.oval:tst:151'/>
            <criterion comment='perl-suid DPKG is earlier than 5.6.1-8.6' test_ref='oval:org.debian.oval:tst:152'/>
            <criterion comment='perl DPKG is earlier than 5.6.1-8.6' test_ref='oval:org.debian.oval:tst:153'/>
            <criterion comment='perl-base DPKG is earlier than 5.6.1-8.6' test_ref='oval:org.debian.oval:tst:154'/>
            <criterion comment='libperl5.6 DPKG is earlier than 5.6.1-8.6' test_ref='oval:org.debian.oval:tst:155'/>
            <criterion comment='perl-debug DPKG is earlier than 5.6.1-8.6' test_ref='oval:org.debian.oval:tst:156'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:432' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>crawl</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0103' ref_id='CVE-2004-0103'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-02-03</date>
          <moreinfo>
Steve Kemp from the Debian Security Audit Project discovered a problem in
crawl, another console based dungeon exploration game, in the vein of
nethack and rogue.  The program uses several environment variables as
inputs but doesn't apply a size check before copying one of them into
a fixed size buffer.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='crawl DPKG is earlier than 4.0.0beta23-2woody1' test_ref='oval:org.debian.oval:tst:157'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:433' class='vulnerability'>
      <metadata>
        <title>integer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>kernel-patch-2.4.17-mips</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0961' ref_id='CVE-2003-0961'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-02-04</date>
          <moreinfo>
Red Hat and SuSE kernel and security teams revealed an integer overflow
in the do_brk() function of the Linux kernel allows local users to
gain root privileges.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='kernel-patch-2.4.17-mips DPKG is earlier than 2.4.17-0.020226.2.woody4' test_ref='oval:org.debian.oval:tst:158'/>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:122'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-headers-2.4.17 DPKG is earlier than 2.4.17-0.020226.2.woody4' test_ref='oval:org.debian.oval:tst:159'/>
              <criterion comment='kernel-image-2.4.17-r4k-ip22 DPKG is earlier than 2.4.17-0.020226.2.woody4' test_ref='oval:org.debian.oval:tst:160'/>
              <criterion comment='kernel-image-2.4.17-r5k-ip22 DPKG is earlier than 2.4.17-0.020226.2.woody4' test_ref='oval:org.debian.oval:tst:161'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:128'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='mips-tools DPKG is earlier than 2.4.17-0.020226.2.woody4' test_ref='oval:org.debian.oval:tst:162'/>
              <criterion comment='kernel-headers-2.4.17 DPKG is earlier than 2.4.17-0.020226.2.woody4' test_ref='oval:org.debian.oval:tst:163'/>
              <criterion comment='kernel-image-2.4.17-r4k-kn04 DPKG is earlier than 2.4.17-0.020226.2.woody4' test_ref='oval:org.debian.oval:tst:164'/>
              <criterion comment='kernel-image-2.4.17-r3k-kn02 DPKG is earlier than 2.4.17-0.020226.2.woody4' test_ref='oval:org.debian.oval:tst:165'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:434' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>gaim</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0005' ref_id='CVE-2004-0005'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0006' ref_id='CVE-2004-0006'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0007' ref_id='CVE-2004-0007'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0008' ref_id='CVE-2004-0008'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-02-05</date>
          <moreinfo>
Stefan Esser discovered several security related problems in Gaim, a
multi-protocol instant messaging client.  Not all of them are
applicable for the version in Debian stable, but affected the version
in the unstable distribution at least.  The problems were grouped for
the Common Vulnerabilities and Exposures as follows:
When the Yahoo Messenger handler decodes an octal value for email
    notification functions two different kinds of overflows can be
    triggered.  When the MIME decoder decoded a quoted printable
    encoded string for email notification two other different kinds of
    overflows can be triggered.  These problems only affect the
    version in the unstable distribution.
When parsing the cookies within the HTTP reply header of a Yahoo
    web connection a buffer overflow can happen.  When parsing the
    Yahoo Login Webpage the YMSG protocol overflows stack buffers if
    the web page returns oversized values.  When splitting a URL into
    its parts a stack overflow can be caused.  These problems only
    affect the version in the unstable distribution.
When an oversized keyname is read from a Yahoo Messenger packet a
    stack overflow can be triggered.  When Gaim is setup to use an HTTP
    proxy for connecting to the server a malicious HTTP proxy can
    exploit it.  These problems affect all versions Debian ships.
    However, the connection to Yahoo doesn't work in the version in
    Debian stable.
Internally data is copied between two tokens into a fixed size
    stack buffer without a size check.  This only affects the version
    of gaim in the unstable distribution.
When allocating memory for AIM/Oscar DirectIM packets an integer
    overflow can happen, resulting in a heap overflow.  This only
    affects the version of gaim in the unstable distribution.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='gaim-common DPKG is earlier than 0.58-2.4' test_ref='oval:org.debian.oval:tst:166'/>
            <criterion comment='gaim-gnome DPKG is earlier than 0.58-2.4' test_ref='oval:org.debian.oval:tst:167'/>
            <criterion comment='gaim DPKG is earlier than 0.58-2.4' test_ref='oval:org.debian.oval:tst:168'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:435' class='vulnerability'>
      <metadata>
        <title>heap overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>mpg123</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0865' ref_id='CVE-2003-0865'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-02-06</date>
          <moreinfo>
A vulnerability was discovered in mpg123, a command-line mp3 player,
whereby a response from a remote HTTP server could overflow a buffer
allocated on the heap, potentially permitting execution of arbitrary
code with the privileges of the user invoking mpg123.  In order for
this vulnerability to be exploited, mpg123 would need to request an
mp3 stream from a malicious remote server via HTTP.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='mpg123 DPKG is earlier than 0.59r-13woody2' test_ref='oval:org.debian.oval:tst:169'/>
              <criterion comment='mpg123-nas DPKG is earlier than 0.59r-13woody2' test_ref='oval:org.debian.oval:tst:170'/>
              <criterion comment='mpg123-oss-i486 DPKG is earlier than 0.59r-13woody2' test_ref='oval:org.debian.oval:tst:171'/>
              <criterion comment='mpg123-oss-3dnow DPKG is earlier than 0.59r-13woody2' test_ref='oval:org.debian.oval:tst:172'/>
              <criterion comment='mpg123-esd DPKG is earlier than 0.59r-13woody2' test_ref='oval:org.debian.oval:tst:173'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:48'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='mpg123 DPKG is earlier than 0.59r-13woody2' test_ref='oval:org.debian.oval:tst:174'/>
              <criterion comment='mpg123-esd DPKG is earlier than 0.59r-13woody2' test_ref='oval:org.debian.oval:tst:175'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported platform section' operator='AND'>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:120'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='mpg123 DPKG is earlier than 0.59r-13woody2' test_ref='oval:org.debian.oval:tst:178'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:436' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>mailman</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0991' ref_id='CVE-2003-0991'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0965' ref_id='CVE-2003-0965'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0038' ref_id='CVE-2003-0038'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-02-08</date>
          <moreinfo>
Several vulnerabilities have been fixed in the mailman package:
The cross-site scripting vulnerabilities could allow an attacker to
perform administrative operations without authorization, by stealing a
session cookie.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='mailman DPKG is earlier than 2.0.11-1woody8' test_ref='oval:org.debian.oval:tst:179'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:437' class='vulnerability'>
      <metadata>
        <title>open mail relay</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>cgiemail</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1575' ref_id='CVE-2002-1575'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-02-11</date>
          <moreinfo>
A vulnerability was discovered in cgiemail, a CGI program used to
email the contents of an HTML form, whereby it could be used to send
email to arbitrary addresses.  This type of vulnerability is commonly
exploited to send unsolicited commercial email (spam).</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='cgiemail DPKG is earlier than 1.6-14woody1' test_ref='oval:org.debian.oval:tst:180'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:438' class='vulnerability'>
      <metadata>
        <title>missing function return value check</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>kernel-source-2.4.18, kernel-image-2.4.18-1-alpha, kernel-image-2.4.18-1-i386, kernel-image-2.4.18-i386bf, kernel-patch-2.4.18-powerpc</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0077' ref_id='CVE-2004-0077'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-02-18</date>
          <moreinfo>
Paul Starzetz and Wojciech Purczynski of isec.pl &lt;a
href="http://isec.pl/vulnerabilities/isec-0014-mremap-unmap.txt">discovered&lt;/a> a critical
security vulnerability in the memory management code of Linux inside
the mremap(2) system call.  Due to missing function return value check
of internal functions a local attacker can gain root privileges.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-source-2.4.18 DPKG is earlier than 2.4.18-14.2' test_ref='oval:org.debian.oval:tst:181'/>
              <criterion comment='kernel-doc-2.4.18 DPKG is earlier than 2.4.18-14.2' test_ref='oval:org.debian.oval:tst:182'/>
              <criterion comment='kernel-patch-2.4.18-powerpc DPKG is earlier than 2.4.18-1woody4' test_ref='oval:org.debian.oval:tst:183'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:48'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-image-2.4.18-1-generic DPKG is earlier than 2.4.18-14' test_ref='oval:org.debian.oval:tst:184'/>
              <criterion comment='kernel-headers-2.4.18-1 DPKG is earlier than 2.4.18-14' test_ref='oval:org.debian.oval:tst:185'/>
              <criterion comment='kernel-headers-2.4.18-1-smp DPKG is earlier than 2.4.18-14' test_ref='oval:org.debian.oval:tst:186'/>
              <criterion comment='kernel-image-2.4.18-1-smp DPKG is earlier than 2.4.18-14' test_ref='oval:org.debian.oval:tst:187'/>
              <criterion comment='kernel-headers-2.4.18-1-generic DPKG is earlier than 2.4.18-14' test_ref='oval:org.debian.oval:tst:188'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-image-2.4.18-1-586tsc DPKG is earlier than 2.4.18-12.2' test_ref='oval:org.debian.oval:tst:189'/>
              <criterion comment='kernel-pcmcia-modules-2.4.18-1-586tsc DPKG is earlier than 2.4.18-12.2' test_ref='oval:org.debian.oval:tst:190'/>
              <criterion comment='kernel-image-2.4.18-bf2.4 DPKG is earlier than 2.4.18-5woody7' test_ref='oval:org.debian.oval:tst:191'/>
              <criterion comment='kernel-pcmcia-modules-2.4.18-1-686 DPKG is earlier than 2.4.18-12.2' test_ref='oval:org.debian.oval:tst:192'/>
              <criterion comment='kernel-headers-2.4.18-1-586tsc DPKG is earlier than 2.4.18-12.2' test_ref='oval:org.debian.oval:tst:193'/>
              <criterion comment='kernel-pcmcia-modules-2.4.18-1-k6 DPKG is earlier than 2.4.18-12.2' test_ref='oval:org.debian.oval:tst:194'/>
              <criterion comment='kernel-pcmcia-modules-2.4.18-1-686-smp DPKG is earlier than 2.4.18-12.2' test_ref='oval:org.debian.oval:tst:195'/>
              <criterion comment='kernel-image-2.4.18-1-686 DPKG is earlier than 2.4.18-12.2' test_ref='oval:org.debian.oval:tst:196'/>
              <criterion comment='kernel-headers-2.4.18-bf2.4 DPKG is earlier than 2.4.18-5woody7' test_ref='oval:org.debian.oval:tst:197'/>
              <criterion comment='kernel-headers-2.4.18-1 DPKG is earlier than 2.4.18-12.2' test_ref='oval:org.debian.oval:tst:198'/>
              <criterion comment='kernel-headers-2.4.18-1-k6 DPKG is earlier than 2.4.18-12.2' test_ref='oval:org.debian.oval:tst:199'/>
              <criterion comment='kernel-headers-2.4.18-1-386 DPKG is earlier than 2.4.18-12.2' test_ref='oval:org.debian.oval:tst:200'/>
              <criterion comment='kernel-image-2.4.18-1-686-smp DPKG is earlier than 2.4.18-12.2' test_ref='oval:org.debian.oval:tst:201'/>
              <criterion comment='kernel-headers-2.4.18-1-686 DPKG is earlier than 2.4.18-12.2' test_ref='oval:org.debian.oval:tst:202'/>
              <criterion comment='kernel-headers-2.4.18-1-k7 DPKG is earlier than 2.4.18-12.2' test_ref='oval:org.debian.oval:tst:203'/>
              <criterion comment='kernel-image-2.4.18-1-k6 DPKG is earlier than 2.4.18-12.2' test_ref='oval:org.debian.oval:tst:204'/>
              <criterion comment='kernel-image-2.4.18-1-386 DPKG is earlier than 2.4.18-12.2' test_ref='oval:org.debian.oval:tst:205'/>
              <criterion comment='kernel-pcmcia-modules-2.4.18-1-386 DPKG is earlier than 2.4.18-12.2' test_ref='oval:org.debian.oval:tst:206'/>
              <criterion comment='kernel-image-2.4.18-1-k7 DPKG is earlier than 2.4.18-12.2' test_ref='oval:org.debian.oval:tst:207'/>
              <criterion comment='kernel-headers-2.4.18-1-686-smp DPKG is earlier than 2.4.18-12.2' test_ref='oval:org.debian.oval:tst:208'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported platform section' operator='AND'>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='kernel-image-2.4.18-newpmac DPKG is earlier than 2.4.18-1woody4' test_ref='oval:org.debian.oval:tst:209'/>
                <criterion comment='kernel-headers-2.4.18 DPKG is earlier than 2.4.18-1woody4' test_ref='oval:org.debian.oval:tst:210'/>
                <criterion comment='kernel-image-2.4.18-powerpc DPKG is earlier than 2.4.18-1woody4' test_ref='oval:org.debian.oval:tst:211'/>
                <criterion comment='kernel-image-2.4.18-powerpc-smp DPKG is earlier than 2.4.18-1woody4' test_ref='oval:org.debian.oval:tst:212'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:439' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>kernel-image-2.4.16-lart, kernel-image-2.4.16-netwinder,  kernel-image-2.4.16-riscpc, kernel-patch-2.4.16-arm</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0961' ref_id='CVE-2003-0961'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0985' ref_id='CVE-2003-0985'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0077' ref_id='CVE-2004-0077'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-02-18</date>
          <moreinfo>
Several local root exploits have been discovered recently in the Linux
kernel.  This security advisory updates the ARM kernel for
Debian GNU/Linux.  The Common Vulnerabilities and Exposures project
identifies the following problems that are fixed with this update:
An integer overflow in brk() system call (do_brk() function) for
   Linux allows a local attacker to gain root privileges.  Fixed
   upstream in Linux 2.4.23.
Paul Starzetz &lt;a href="http://isec.pl/vulnerabilities/isec-0013-mremap.txt">discovered&lt;/a>
   a flaw in bounds checking in mremap() in
   the Linux kernel (present in version 2.4.x and 2.6.x) which may
   allow a local attacker to gain root privileges.  Version 2.2 is not
   affected by this bug.  Fixed upstream in Linux 2.4.24.
Paul Starzetz and Wojciech Purczynski of isec.pl &lt;a
   href="http://isec.pl/vulnerabilities/isec-0014-mremap-unmap.txt">discovered&lt;/a> a
   critical security vulnerability in the memory management code of
   Linux inside the mremap(2) system call.  Due to missing function
   return value check of internal functions a local attacker can gain
   root privileges.  Fixed upstream in Linux 2.4.25 and 2.6.3.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='kernel-patch-2.4.16-arm DPKG is earlier than 20040204' test_ref='oval:org.debian.oval:tst:213'/>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:123'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-image-2.4.16-netwinder DPKG is earlier than 20040204' test_ref='oval:org.debian.oval:tst:214'/>
              <criterion comment='kernel-image-2.4.16-riscpc DPKG is earlier than 20040204' test_ref='oval:org.debian.oval:tst:215'/>
              <criterion comment='kernel-headers-2.4.16 DPKG is earlier than 20040204' test_ref='oval:org.debian.oval:tst:216'/>
              <criterion comment='kernel-image-2.4.16-lart DPKG is earlier than 20040204' test_ref='oval:org.debian.oval:tst:217'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:440' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>kernel-source-2.4.17, kernel-patch-2.4.17-apus</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0961' ref_id='CVE-2003-0961'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0985' ref_id='CVE-2003-0985'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0077' ref_id='CVE-2004-0077'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-02-18</date>
          <moreinfo>
Several local root exploits have been discovered recently in the Linux
kernel.  This security advisory updates the PowerPC/Apus kernel for
Debian GNU/Linux.  The Common Vulnerabilities and Exposures project
identifies the following problems that are fixed with this update:
An integer overflow in brk() system call (do_brk() function) for
   Linux allows a local attacker to gain root privileges.  Fixed
   upstream in Linux 2.4.23.
Paul Starzetz &lt;a href="http://isec.pl/vulnerabilities/isec-0013-mremap.txt">discovered&lt;/a>
   a flaw in bounds checking in mremap() in
   the Linux kernel (present in version 2.4.x and 2.6.x) which may
   allow a local attacker to gain root privileges.  Version 2.2 is not
   affected by this bug.  Fixed upstream in Linux 2.4.24.
Paul Starzetz and Wojciech Purczynski of isec.pl &lt;a
   href="http://isec.pl/vulnerabilities/isec-0014-mremap-unmap.txt">discovered&lt;/a> a
   critical security vulnerability in the memory management code of
   Linux inside the mremap(2) system call.  Due to missing function
   return value check of internal functions a local attacker can gain
   root privileges.  Fixed upstream in Linux 2.4.25 and 2.6.3.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-doc-2.4.17 DPKG is earlier than 2.4.17-1woody2' test_ref='oval:org.debian.oval:tst:218'/>
              <criterion comment='kernel-source-2.4.17 DPKG is earlier than 2.4.17-1woody2' test_ref='oval:org.debian.oval:tst:219'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-headers-2.4.17-apus DPKG is earlier than 2.4.17-4' test_ref='oval:org.debian.oval:tst:220'/>
              <criterion comment='kernel-image-2.4.17-apus DPKG is earlier than 2.4.17-4' test_ref='oval:org.debian.oval:tst:221'/>
              <criterion comment='kernel-patch-2.4.17-apus DPKG is earlier than 2.4.17-4' test_ref='oval:org.debian.oval:tst:222'/>
              <criterion comment='kernel-image-apus DPKG is earlier than 2.4.17-4' test_ref='oval:org.debian.oval:tst:223'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:441' class='vulnerability'>
      <metadata>
        <title>missing function return value check</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>kernel-patch-2.4.17-mips</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0077' ref_id='CVE-2004-0077'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-02-18</date>
          <moreinfo>
Paul Starzetz and Wojciech Purczynski of isec.pl &lt;a
href="http://isec.pl/vulnerabilities/isec-0014-mremap-unmap.txt">discovered&lt;/a> a critical
security vulnerability in the memory management code of Linux inside
the mremap(2) system call.  Due to missing function return value check
of internal functions a local attacker can gain root privileges.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='kernel-patch-2.4.17-mips DPKG is earlier than 2.4.17-0.020226.2.woody5' test_ref='oval:org.debian.oval:tst:224'/>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:122'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-headers-2.4.17 DPKG is earlier than 2.4.17-0.020226.2.woody5' test_ref='oval:org.debian.oval:tst:225'/>
              <criterion comment='kernel-image-2.4.17-r4k-ip22 DPKG is earlier than 2.4.17-0.020226.2.woody5' test_ref='oval:org.debian.oval:tst:226'/>
              <criterion comment='kernel-image-2.4.17-r5k-ip22 DPKG is earlier than 2.4.17-0.020226.2.woody5' test_ref='oval:org.debian.oval:tst:227'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:128'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='mips-tools DPKG is earlier than 2.4.17-0.020226.2.woody5' test_ref='oval:org.debian.oval:tst:228'/>
              <criterion comment='kernel-headers-2.4.17 DPKG is earlier than 2.4.17-0.020226.2.woody5' test_ref='oval:org.debian.oval:tst:229'/>
              <criterion comment='kernel-image-2.4.17-r4k-kn04 DPKG is earlier than 2.4.17-0.020226.2.woody5' test_ref='oval:org.debian.oval:tst:230'/>
              <criterion comment='kernel-image-2.4.17-r3k-kn02 DPKG is earlier than 2.4.17-0.020226.2.woody5' test_ref='oval:org.debian.oval:tst:231'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:442' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>kernel-patch-2.4.17-s390, kernel-image-2.4.17-s390</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0001' ref_id='CVE-2003-0001'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0244' ref_id='CVE-2003-0244'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0246' ref_id='CVE-2003-0246'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0247' ref_id='CVE-2003-0247'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0248' ref_id='CVE-2003-0248'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0364' ref_id='CVE-2003-0364'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0961' ref_id='CVE-2003-0961'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0985' ref_id='CVE-2003-0985'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0077' ref_id='CVE-2004-0077'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0429' ref_id='CVE-2002-0429'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-02-19</date>
          <moreinfo>
Several security related problems have been fixed in the Linux kernel
2.4.17 used for the S/390 architecture, mostly by backporting fixes
from 2.4.18 and incorporating recent security fixes.  The corrections
are listed below with the identification from the Common
Vulnerabilities and Exposures (CVE) project:
The iBCS routines in arch/i386/kernel/traps.c for Linux kernels
   2.4.18 and earlier on x86 systems allow local users to kill
   arbitrary processes via a binary compatibility interface (lcall).
Multiple ethernet network interface card (NIC) device drivers do
   not pad frames with null bytes, which allows remote attackers to
   obtain information from previous packets or kernel memory by using
   malformed packets, as demonstrated by Etherleak.
The route cache implementation in Linux 2.4, and the Netfilter IP
   conntrack module, allows remote attackers to cause a denial of
   service (CPU consumption) via packets with forged source addresses
   that cause a large number of hash table collisions related to the
   PREROUTING chain.
The ioperm system call in Linux kernel 2.4.20 and earlier does not
   properly restrict privileges, which allows local users to gain read
   or write access to certain I/O ports.
A vulnerability in the TTY layer of the Linux kernel 2.4 allows
   attackers to cause a denial of service ("kernel oops").
The mxcsr code in Linux kernel 2.4 allows attackers to modify CPU
   state registers via a malformed address.
The TCP/IP fragment reassembly handling in the Linux kernel 2.4
   allows remote attackers to cause a denial of service (CPU
   consumption) via certain packets that cause a large number of hash
   table collisions.
An integer overflow in brk() system call (do_brk() function) for
   Linux allows a local attacker to gain root privileges.  Fixed
   upstream in Linux 2.4.23.
Paul Starzetz &lt;a href="http://isec.pl/vulnerabilities/isec-0013-mremap.txt">discovered&lt;/a>
   a flaw in bounds checking in mremap() in
   the Linux kernel (present in version 2.4.x and 2.6.x) which may
   allow a local attacker to gain root privileges.  Version 2.2 is not
   affected by this bug.  Fixed upstream in Linux 2.4.24.
Paul Starzetz and Wojciech Purczynski of isec.pl &lt;a
   href="http://isec.pl/vulnerabilities/isec-0014-mremap-unmap.txt">discovered&lt;/a> a
   critical security vulnerability in the memory management code of
   Linux inside the mremap(2) system call.  Due to missing function
   return value check of internal functions a local attacker can gain
   root privileges.  Fixed upstream in Linux 2.4.25 and 2.6.3.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='kernel-patch-2.4.17-s390 DPKG is earlier than 0.0.20020816-0.woody.2' test_ref='oval:org.debian.oval:tst:232'/>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:118'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-image-2.4.17-s390 DPKG is earlier than 2.4.17-2.woody.3' test_ref='oval:org.debian.oval:tst:233'/>
              <criterion comment='kernel-headers-2.4.17 DPKG is earlier than 2.4.17-2.woody.3' test_ref='oval:org.debian.oval:tst:234'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:443' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>xfree86</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0690' ref_id='CVE-2003-0690'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0083' ref_id='CVE-2004-0083'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0084' ref_id='CVE-2004-0084'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0106' ref_id='CVE-2004-0106'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0093' ref_id='CVE-2004-0093'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0094' ref_id='CVE-2004-0094'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-02-19</date>
          <moreinfo>
A number of vulnerabilities have been discovered in XFree86.  The corrections
are listed below with the identification from the Common
Vulnerabilities and Exposures (CVE) project:
Buffer overflow in ReadFontAlias from dirfile.c of
    XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to
    execute arbitrary code via a font alias file (font.alias) with a long
    token, a different vulnerability than CAN-2004-0084.
Buffer overflow in the ReadFontAlias function in XFree86
    4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows
    local or remote authenticated users to execute arbitrary code via a
    malformed entry in the font alias (font.alias) file, a different
    vulnerability than CAN-2004-0083.
Miscellaneous additional flaws in XFree86's handling of
    font files.
xdm does not verify whether the pam_setcred function call
    succeeds, which may allow attackers to gain root privileges by
    triggering error conditions within PAM modules, as demonstrated in
    certain configurations of the MIT pam_krb5 module.
Denial-of-service attacks against the X
    server by clients using the GLX extension and Direct Rendering
    Infrastructure are possible due to unchecked client data (out-of-bounds
    array indexes [CAN-2004-0093] and integer signedness errors
    [CAN-2004-0094]).
Exploitation of CAN-2004-0083, CAN-2004-0084, CAN-2004-0106,
CAN-2004-0093 and CAN-2004-0094 would require a connection to the X
server.  By default, display managers in Debian start the X server
with a configuration which only accepts local connections, but if the
configuration is changed to allow remote connections, or X servers are
started by other means, then these bugs could be exploited remotely.
Since the X server usually runs with root privileges, these bugs could
potentially be exploited to gain root privileges.
No attack vector for CAN-2003-0690 is known at this time.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='xfonts-base-transcoded DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:235'/>
              <criterion comment='xfonts-scalable DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:236'/>
              <criterion comment='x-window-system DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:237'/>
              <criterion comment='xfonts-100dpi DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:238'/>
              <criterion comment='xspecs DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:239'/>
              <criterion comment='xfonts-cyrillic DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:240'/>
              <criterion comment='xfonts-75dpi DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:241'/>
              <criterion comment='xfree86-common DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:242'/>
              <criterion comment='xfonts-base DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:243'/>
              <criterion comment='xlib6g DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:244'/>
              <criterion comment='xfonts-100dpi-transcoded DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:245'/>
              <criterion comment='xfonts-pex DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:246'/>
              <criterion comment='xlib6g-dev DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:247'/>
              <criterion comment='xfonts-75dpi-transcoded DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:248'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:118'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:119'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:120'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:123'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:112'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:48'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:121'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libdps1-dbg DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:249'/>
              <criterion comment='xlibs-pic DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:250'/>
              <criterion comment='xlibmesa3 DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:251'/>
              <criterion comment='xlibs DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:252'/>
              <criterion comment='xlibmesa-dev DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:253'/>
              <criterion comment='xlibs-dbg DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:254'/>
              <criterion comment='libxaw6-dev DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:255'/>
              <criterion comment='proxymngr DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:256'/>
              <criterion comment='libxaw6 DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:257'/>
              <criterion comment='libxaw7 DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:258'/>
              <criterion comment='xfwp DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:259'/>
              <criterion comment='xmh DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:260'/>
              <criterion comment='twm DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:261'/>
              <criterion comment='xutils DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:262'/>
              <criterion comment='xprt DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:263'/>
              <criterion comment='libxaw7-dbg DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:264'/>
              <criterion comment='xserver-common DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:265'/>
              <criterion comment='libdps1 DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:266'/>
              <criterion comment='xbase-clients DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:267'/>
              <criterion comment='xdm DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:268'/>
              <criterion comment='xterm DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:269'/>
              <criterion comment='xvfb DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:270'/>
              <criterion comment='libxaw7-dev DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:271'/>
              <criterion comment='libdps-dev DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:272'/>
              <criterion comment='xfs DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:273'/>
              <criterion comment='libxaw6-dbg DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:274'/>
              <criterion comment='xlibs-dev DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:275'/>
              <criterion comment='xlibmesa3-dbg DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:276'/>
              <criterion comment='xnest DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:277'/>
              <criterion comment='lbxproxy DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:278'/>
              <criterion comment='x-window-system-core DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:279'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:119'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:48'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:112'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='xlibosmesa3-dbg DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:280'/>
              <criterion comment='xlibosmesa3 DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:281'/>
              <criterion comment='xserver-xfree86 DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:282'/>
              <criterion comment='xlibosmesa-dev DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:283'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported platform section' operator='AND'>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:123'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='xserver-xfree86 DPKG is earlier than 4.1.0-16woody3' test_ref='oval:org.debian.oval:tst:350'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:444' class='vulnerability'>
      <metadata>
        <title>missing function return value check</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>kernel-image-2.4.17-ia64</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0077' ref_id='CVE-2004-0077'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-02-20</date>
          <moreinfo>
Paul Starzetz and Wojciech Purczynski of isec.pl &lt;a
href="http://isec.pl/vulnerabilities/isec-0014-mremap-unmap.txt">discovered&lt;/a> a critical
security vulnerability in the memory management code of Linux inside
the mremap(2) system call.  Due to missing function return value check
of internal functions a local attacker can gain root privileges.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='kernel-source-2.4.17-ia64 DPKG is earlier than 011226.16' test_ref='oval:org.debian.oval:tst:351'/>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:112'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-image-2.4.17-itanium-smp DPKG is earlier than 011226.16' test_ref='oval:org.debian.oval:tst:352'/>
              <criterion comment='kernel-image-2.4.17-mckinley-smp DPKG is earlier than 011226.16' test_ref='oval:org.debian.oval:tst:353'/>
              <criterion comment='kernel-image-2.4.17-mckinley DPKG is earlier than 011226.16' test_ref='oval:org.debian.oval:tst:354'/>
              <criterion comment='kernel-headers-2.4.17-ia64 DPKG is earlier than 011226.16' test_ref='oval:org.debian.oval:tst:355'/>
              <criterion comment='kernel-image-2.4.17-itanium DPKG is earlier than 011226.16' test_ref='oval:org.debian.oval:tst:356'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:445' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>lbreakout2</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0158' ref_id='CVE-2004-0158'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-02-21</date>
          <moreinfo>
Ulf Härnhammar from the Debian Security Audit Project 
discovered a vulnerability in
lbreakout2, a game, where proper bounds checking was not performed on
environment variables.  This bug could be exploited by a local
attacker to gain the privileges of group "games".</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:118'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:119'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:120'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:121'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:122'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:112'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:48'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:123'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='lbreakout2 DPKG is earlier than 2.2.2-1woody1' test_ref='oval:org.debian.oval:tst:357'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:446' class='vulnerability'>
      <metadata>
        <title>insecure file creation</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>synaesthesia</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0160' ref_id='CVE-2004-0160'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-02-21</date>
          <moreinfo>
Ulf Härnhammar from the Debian Security Audit Project
discovered a vulnerability in
synaesthesia, a program which represents sounds visually.
synaesthesia created its configuration file while holding root
privileges, allowing a local user to create files owned by root and
writable by the user's primary group.  This type of vulnerability can
usually be easily exploited to execute arbitrary code with root
privileges by various means.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:118'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:119'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:120'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:121'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:122'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:112'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:48'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:123'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='synaesthesia DPKG is earlier than 2.1-2.1woody1' test_ref='oval:org.debian.oval:tst:358'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:447' class='vulnerability'>
      <metadata>
        <title>format string</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>hsftp</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0159' ref_id='CVE-2004-0159'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-02-22</date>
          <moreinfo>
Ulf Härnhammar from the Debian Security Audit Project
discovered a format string
vulnerability in hsftp.  This vulnerability could be exploited by an
attacker able to create files on a remote server with carefully
crafted names, to which a user would connect using hsftp.  When the
user requests a directory listing, particular bytes in memory could be
overwritten, potentially allowing arbitrary code to be executed with
the privileges of the user invoking hsftp.
Note that while hsftp is installed setuid root, it only uses these
privileges to acquire locked memory, and then relinquishes them.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:118'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:119'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:120'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:121'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:122'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:112'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:48'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:123'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='hsftp DPKG is earlier than 1.11-1woody1' test_ref='oval:org.debian.oval:tst:359'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:448' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>pwlib</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0097' ref_id='CVE-2004-0097'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-02-22</date>
          <moreinfo>
Multiple vulnerabilities were discovered in pwlib, a library used to
aid in writing portable applications, whereby a remote attacker could
cause a denial of service or potentially execute arbitrary code.  This
library is most notably used in several applications implementing the
H.323 teleconferencing protocol, including the OpenH323 suite,
gnomemeeting and asterisk.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:118'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:119'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:120'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:121'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:122'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:112'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:48'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:123'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libpt-dev DPKG is earlier than 1.2.5-5woody1' test_ref='oval:org.debian.oval:tst:360'/>
              <criterion comment='libpt-1.2.0 DPKG is earlier than 1.2.5-5woody1' test_ref='oval:org.debian.oval:tst:361'/>
              <criterion comment='libpt-dbg DPKG is earlier than 1.2.5-5woody1' test_ref='oval:org.debian.oval:tst:362'/>
              <criterion comment='asnparser DPKG is earlier than 1.2.5-5woody1' test_ref='oval:org.debian.oval:tst:363'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:449' class='vulnerability'>
      <metadata>
        <title>buffer overflow, format string bugs</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>metamail</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0104' ref_id='CVE-2004-0104'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0105' ref_id='CVE-2004-0105'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-02-24</date>
          <moreinfo>
Ulf Härnhammar discovered two format string bugs (&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0104">CAN-2004-0104&lt;/a>) and
two buffer overflow bugs (&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0105">CAN-2004-0105&lt;/a>) in metamail, an
implementation of MIME.  An attacker could create a carefully-crafted
mail message which will execute arbitrary code as the victim when it
is opened and parsed through metamail.
We have been devoting some effort to trying to avoid shipping metamail
in the future.  It became unmaintainable and these are probably not
the last of the vulnerabilities.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='metamail DPKG is earlier than 2.7-45woody.2' test_ref='oval:org.debian.oval:tst:364'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:450' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>kernel-source-2.4.19, kernel-patch-2.4.19-mips</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0961' ref_id='CVE-2003-0961'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0985' ref_id='CVE-2003-0985'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0077' ref_id='CVE-2004-0077'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-02-27</date>
          <moreinfo>
Several local root exploits have been discovered recently in the Linux
kernel.  This security advisory updates the mips kernel 2.4.19 for
Debian GNU/Linux.  The Common Vulnerabilities and Exposures project
identifies the following problems that are fixed with this update:
An integer overflow in brk() system call (do_brk() function) for
   Linux allows a local attacker to gain root privileges.  Fixed
   upstream in Linux 2.4.23.
Paul Starzetz &lt;a
   href="http://isec.pl/vulnerabilities/isec-0013-mremap.txt">discovered&lt;/a>
   a flaw in bounds checking in mremap() in
   the Linux kernel (present in version 2.4.x and 2.6.x) which may
   allow a local attacker to gain root privileges.  Version 2.2 is not
   affected by this bug.  Fixed upstream in Linux 2.4.24.
Paul Starzetz and Wojciech Purczynski of isec.pl &lt;a
   href="http://isec.pl/vulnerabilities/isec-0014-mremap-unmap.txt">discovered&lt;/a> a
   critical security vulnerability in the memory management code of
   Linux inside the mremap(2) system call.  Due to missing function
   return value check of internal functions a local attacker can gain
   root privileges.  Fixed upstream in Linux 2.4.25 and 2.6.3.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-source-2.4.19 DPKG is earlier than 2.4.19-4.woody1' test_ref='oval:org.debian.oval:tst:365'/>
              <criterion comment='kernel-patch-2.4.19-mips DPKG is earlier than 2.4.19-0.020911.1.woody3' test_ref='oval:org.debian.oval:tst:366'/>
              <criterion comment='kernel-doc-2.4.19 DPKG is earlier than 2.4.19-4.woody1' test_ref='oval:org.debian.oval:tst:367'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:122'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='mips-tools DPKG is earlier than 2.4.19-0.020911.1.woody3' test_ref='oval:org.debian.oval:tst:368'/>
              <criterion comment='kernel-headers-2.4.19 DPKG is earlier than 2.4.19-0.020911.1.woody3' test_ref='oval:org.debian.oval:tst:369'/>
              <criterion comment='kernel-image-2.4.19-r4k-ip22 DPKG is earlier than 2.4.19-0.020911.1.woody3' test_ref='oval:org.debian.oval:tst:370'/>
              <criterion comment='kernel-image-2.4.19-r5k-ip22 DPKG is earlier than 2.4.19-0.020911.1.woody3' test_ref='oval:org.debian.oval:tst:371'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:451' class='vulnerability'>
      <metadata>
        <title>buffer overflows</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>xboing</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0149' ref_id='CVE-2004-0149'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-02-27</date>
          <moreinfo>
Steve Kemp discovered a number of buffer overflow vulnerabilities in
xboing, a game, which could be exploited by a local attacker to gain
gid "games".</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='xboing DPKG is earlier than 2.4-26woody1' test_ref='oval:org.debian.oval:tst:372'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:452' class='vulnerability'>
      <metadata>
        <title>denial of service</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>libapache-mod-python</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0973' ref_id='CVE-2003-0973'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-02-29</date>
          <moreinfo>
The Apache Software Foundation announced that some versions of
mod_python contain a bug which, when processing a request with a
malformed query string, could cause the corresponding Apache child to
crash.  This bug could be exploited by a remote attacker to cause a
denial of service.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libapache-mod-python DPKG is earlier than 2.7.8-0.0woody2' test_ref='oval:org.debian.oval:tst:373'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:453' class='vulnerability'>
      <metadata>
        <title>failing function and TLB flush</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>kernel-source-2.2.20, kernel-image-2.2.20-i386, kernel-image-2.2.20-reiserfs-i386, kernel-image-2.2.20-amiga, kernel-image-2.2.20-atari, kernel-image-2.2.20-bvme6000, kernel-image-2.2.20-mac, kernel-image-2.2.20-mvme147, kernel-image-2.2.20-mvme16x, kernel-patch-2.2.20-powerpc</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0077' ref_id='CVE-2004-0077'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-03-02</date>
          <moreinfo>
Paul Starzetz and Wojciech Purczynski of isec.pl &lt;a
href="http://isec.pl/vulnerabilities/isec-0014-mremap-unmap.txt">discovered&lt;/a> a critical
security vulnerability in the memory management code of Linux inside
the mremap(2) system call.  Due to flushing the TLB (Translation
Lookaside Buffer, an address cache) too early it is possible for an
attacker to trigger a local root exploit.
The attack vectors for 2.4.x and 2.2.x kernels are exclusive for the
respective kernel series, though.  We formerly believed that the
exploitable vulnerability in 2.4.x does not exist in 2.2.x which is
still true.  However, it turned out that a second (sort of)
vulnerability is indeed exploitable in 2.2.x, but not in 2.4.x, with a
different exploit, of course.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-doc-2.2.20 DPKG is earlier than 2.2.20-5woody3' test_ref='oval:org.debian.oval:tst:374'/>
              <criterion comment='kernel-patch-2.2.20-powerpc DPKG is earlier than 2.2.20-3woody1' test_ref='oval:org.debian.oval:tst:375'/>
              <criterion comment='kernel-source-2.2.20 DPKG is earlier than 2.2.20-5woody3' test_ref='oval:org.debian.oval:tst:376'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-headers-2.2.20-idepci DPKG is earlier than 2.2.20-5woody5' test_ref='oval:org.debian.oval:tst:377'/>
              <criterion comment='kernel-headers-2.2.20-compact DPKG is earlier than 2.2.20-5woody5' test_ref='oval:org.debian.oval:tst:378'/>
              <criterion comment='kernel-image-2.2.20-compact DPKG is earlier than 2.2.20-5woody5' test_ref='oval:org.debian.oval:tst:379'/>
              <criterion comment='kernel-headers-2.2.20 DPKG is earlier than 2.2.20-5woody5' test_ref='oval:org.debian.oval:tst:380'/>
              <criterion comment='kernel-image-2.2.20-reiserfs DPKG is earlier than 2.2.20-4woody1' test_ref='oval:org.debian.oval:tst:381'/>
              <criterion comment='kernel-image-2.2.20-idepci DPKG is earlier than 2.2.20-5woody5' test_ref='oval:org.debian.oval:tst:382'/>
              <criterion comment='kernel-headers-2.2.20-reiserfs DPKG is earlier than 2.2.20-4woody1' test_ref='oval:org.debian.oval:tst:383'/>
              <criterion comment='kernel-image-2.2.20 DPKG is earlier than 2.2.20-5woody5' test_ref='oval:org.debian.oval:tst:384'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:120'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-image-2.2.20-bvme6000 DPKG is earlier than 2.2.20-3' test_ref='oval:org.debian.oval:tst:385'/>
              <criterion comment='kernel-image-2.2.20-mvme16x DPKG is earlier than 2.2.20-3' test_ref='oval:org.debian.oval:tst:386'/>
              <criterion comment='kernel-image-2.2.20-mac DPKG is earlier than 2.2.20-3' test_ref='oval:org.debian.oval:tst:387'/>
              <criterion comment='kernel-image-2.2.20-amiga DPKG is earlier than 2.2.20-4' test_ref='oval:org.debian.oval:tst:388'/>
              <criterion comment='kernel-image-2.2.20-mvme147 DPKG is earlier than 2.2.20-3' test_ref='oval:org.debian.oval:tst:389'/>
              <criterion comment='kernel-image-2.2.20-atari DPKG is earlier than 2.2.20-3' test_ref='oval:org.debian.oval:tst:390'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported platform section' operator='AND'>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='kernel-headers-2.2.20 DPKG is earlier than 2.2.20-3woody1' test_ref='oval:org.debian.oval:tst:391'/>
                <criterion comment='kernel-image-2.2.20-chrp DPKG is earlier than 2.2.20-3woody1' test_ref='oval:org.debian.oval:tst:392'/>
                <criterion comment='kernel-image-2.2.20-prep DPKG is earlier than 2.2.20-3woody1' test_ref='oval:org.debian.oval:tst:393'/>
                <criterion comment='kernel-image-2.2.20-pmac DPKG is earlier than 2.2.20-3woody1' test_ref='oval:org.debian.oval:tst:394'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:454' class='vulnerability'>
      <metadata>
        <title>failing function and TLB flush</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>kernel-source-2.2.22, kernel-image-2.2.22-alpha</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0077' ref_id='CVE-2004-0077'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-03-02</date>
          <moreinfo>
Paul Starzetz and Wojciech Purczynski of isec.pl &lt;a
href="http://isec.pl/vulnerabilities/isec-0014-mremap-unmap.txt">discovered&lt;/a> a critical
security vulnerability in the memory management code of Linux inside
the mremap(2) system call.  Due to flushing the TLB (Translation
Lookaside Buffer, an address cache) too early it is possible for an
attacker to trigger a local root exploit.
The attack vectors for 2.4.x and 2.2.x kernels are exclusive for the
respective kernel series, though.  We formerly believed that the
exploitable vulnerability in 2.4.x does not exist in 2.2.x which is
still true.  However, it turned out that a second (sort of)
vulnerability is indeed exploitable in 2.2.x, but not in 2.4.x, with a
different exploit, of course.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-source-2.2.22 DPKG is earlier than 2.2.22-1woody1' test_ref='oval:org.debian.oval:tst:395'/>
              <criterion comment='kernel-doc-2.2.22 DPKG is earlier than 2.2.22-1woody1' test_ref='oval:org.debian.oval:tst:396'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:48'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-image-2.2.22-smp DPKG is earlier than 2.2.22-2' test_ref='oval:org.debian.oval:tst:397'/>
              <criterion comment='kernel-headers-2.2.22 DPKG is earlier than 2.2.22-2' test_ref='oval:org.debian.oval:tst:398'/>
              <criterion comment='kernel-image-2.2.22-jensen DPKG is earlier than 2.2.22-2' test_ref='oval:org.debian.oval:tst:399'/>
              <criterion comment='kernel-image-2.2.22-nautilus DPKG is earlier than 2.2.22-2' test_ref='oval:org.debian.oval:tst:400'/>
              <criterion comment='kernel-image-2.2.22-generic DPKG is earlier than 2.2.22-2' test_ref='oval:org.debian.oval:tst:401'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:455' class='vulnerability'>
      <metadata>
        <title>buffer overflows</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>libxml, libxml2</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0110' ref_id='CVE-2004-0110'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-03-03</date>
          <moreinfo>
libxml2 is a library for manipulating XML files.
Yuuichi Teranishi (&amp;#23546;&amp;#35199; &amp;#35029;&amp;#19968;)
discovered a flaw in libxml, the GNOME XML library.
When fetching a remote resource via FTP or HTTP, the library uses
special parsing routines which can overflow a buffer if passed a very
long URL.  If an attacker is able to find an application using libxml1
or libxml2 that parses remote resources and allows the attacker to
craft the URL, then this flaw could be used to execute arbitrary code.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libxml2 DPKG is earlier than 2.4.19-4woody1' test_ref='oval:org.debian.oval:tst:402'/>
            <criterion comment='libxml1 DPKG is earlier than 1.8.17-2woody1' test_ref='oval:org.debian.oval:tst:403'/>
            <criterion comment='libxml-dev DPKG is earlier than 1.8.17-2woody1' test_ref='oval:org.debian.oval:tst:404'/>
            <criterion comment='libxml2-dev DPKG is earlier than 2.4.19-4woody1' test_ref='oval:org.debian.oval:tst:405'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:456' class='vulnerability'>
      <metadata>
        <title>failing function and TLB flush</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>kernel-source-2.2.19, kernel-patch-2.2.19-arm, kernel-image-2.2.19-netwinder, kernel-image-2.2.19-riscpc</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0077' ref_id='CVE-2004-0077'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-03-06</date>
          <moreinfo>
Paul Starzetz and Wojciech Purczynski of isec.pl &lt;a
href="http://isec.pl/vulnerabilities/isec-0014-mremap-unmap.txt">discovered&lt;/a> a critical
security vulnerability in the memory management code of Linux inside
the mremap(2) system call.  Due to flushing the TLB (Translation
Lookaside Buffer, an address cache) too early it is possible for an
attacker to trigger a local root exploit.
The attack vectors for 2.4.x and 2.2.x kernels are exclusive for the
respective kernel series, though.  We formerly believed that the
exploitable vulnerability in 2.4.x does not exist in 2.2.x which is
still true.  However, it turned out that a second (sort of)
vulnerability is indeed exploitable in 2.2.x, but not in 2.4.x, with a
different exploit, of course.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='kernel-patch-2.2.19-arm DPKG is earlier than 20040303' test_ref='oval:org.debian.oval:tst:406'/>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:123'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-headers-2.2.19 DPKG is earlier than 20040303' test_ref='oval:org.debian.oval:tst:407'/>
              <criterion comment='kernel-image-2.2.19-netwinder DPKG is earlier than 20040303' test_ref='oval:org.debian.oval:tst:408'/>
              <criterion comment='kernel-image-2.2.19-riscpc DPKG is earlier than 20040303' test_ref='oval:org.debian.oval:tst:409'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:457' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>wu-ftpd</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0148' ref_id='CVE-2004-0148'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0185' ref_id='CVE-2004-0185'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-03-08</date>
          <moreinfo>
Two vulnerabilities were discovered in wu-ftpd:
Glenn Stewart discovered that users could bypass the
 directory access restrictions imposed by the restricted-gid option by
 changing the permissions on their home directory.  On a subsequent
 login, when access to the user's home directory was denied, wu-ftpd
 would fall back to the root directory.
A buffer overflow existed in wu-ftpd's code which
 deals with S/key authentication.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='wu-ftpd-academ DPKG is earlier than 2.6.2-3woody4' test_ref='oval:org.debian.oval:tst:410'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='wu-ftpd DPKG is earlier than 2.6.2-3woody4' test_ref='oval:org.debian.oval:tst:411'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:458' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>python2.2</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0150' ref_id='CVE-2004-0150'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-10-10</date>
          <moreinfo>
This security advisory corrects DSA 458-2 which caused a problem in
the gethostbyaddr routine.
The original advisory said:
Sebastian Schmidt discovered a buffer overflow bug in Python's
getaddrinfo function, which could allow an IPv6 address, supplied by a
remote attacker via DNS, to overwrite memory on the stack.
This bug only exists in python 2.2 and 2.2.1, and only when IPv6
support is disabled.  The python2.2 package in Debian woody meets
these conditions (the 'python' package does not).</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='python2.2-doc DPKG is earlier than 2.2.1-4.6' test_ref='oval:org.debian.oval:tst:412'/>
              <criterion comment='python2.2-elisp DPKG is earlier than 2.2.1-4.6' test_ref='oval:org.debian.oval:tst:413'/>
              <criterion comment='python2.2-examples DPKG is earlier than 2.2.1-4.6' test_ref='oval:org.debian.oval:tst:414'/>
              <criterion comment='idle-python2.2 DPKG is earlier than 2.2.1-4.6' test_ref='oval:org.debian.oval:tst:415'/>
            </criteria>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='python2.2 DPKG is earlier than 2.2.1-4.6' test_ref='oval:org.debian.oval:tst:416'/>
            <criterion comment='python2.2-gdbm DPKG is earlier than 2.2.1-4.6' test_ref='oval:org.debian.oval:tst:417'/>
            <criterion comment='python2.2-xmlbase DPKG is earlier than 2.2.1-4.6' test_ref='oval:org.debian.oval:tst:418'/>
            <criterion comment='python2.2-mpz DPKG is earlier than 2.2.1-4.6' test_ref='oval:org.debian.oval:tst:419'/>
            <criterion comment='python2.2-tk DPKG is earlier than 2.2.1-4.6' test_ref='oval:org.debian.oval:tst:420'/>
            <criterion comment='python2.2-dev DPKG is earlier than 2.2.1-4.6' test_ref='oval:org.debian.oval:tst:421'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:459' class='vulnerability'>
      <metadata>
        <title>cookie path traversal</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>kdelibs, kdelibs-crypto</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0592' ref_id='CVE-2003-0592'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-03-10</date>
          <moreinfo>
A vulnerability was discovered in KDE where the path restrictions on
cookies could be bypassed using encoded relative path components
(e.g., "/../").  This means that a cookie which should only be sent by
the browser to an application running at /app1, the browser could
inadvertently include it with a request sent to /app2 on the same
server.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='kdelibs3-doc DPKG is earlier than 2.2.2-13.woody.9' test_ref='oval:org.debian.oval:tst:422'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libarts DPKG is earlier than 2.2.2-13.woody.9' test_ref='oval:org.debian.oval:tst:423'/>
            <criterion comment='libkmid-alsa DPKG is earlier than 2.2.2-13.woody.9' test_ref='oval:org.debian.oval:tst:424'/>
            <criterion comment='kdelibs3-bin DPKG is earlier than 2.2.2-13.woody.9' test_ref='oval:org.debian.oval:tst:425'/>
            <criterion comment='kdelibs3-crypto DPKG is earlier than 2.2.2-6woody3' test_ref='oval:org.debian.oval:tst:426'/>
            <criterion comment='libarts-alsa DPKG is earlier than 2.2.2-13.woody.9' test_ref='oval:org.debian.oval:tst:427'/>
            <criterion comment='kdelibs3 DPKG is earlier than 2.2.2-13.woody.9' test_ref='oval:org.debian.oval:tst:428'/>
            <criterion comment='kdelibs3-cups DPKG is earlier than 2.2.2-13.woody.9' test_ref='oval:org.debian.oval:tst:429'/>
            <criterion comment='libkmid-dev DPKG is earlier than 2.2.2-13.woody.9' test_ref='oval:org.debian.oval:tst:430'/>
            <criterion comment='libkmid DPKG is earlier than 2.2.2-13.woody.9' test_ref='oval:org.debian.oval:tst:431'/>
            <criterion comment='libarts-dev DPKG is earlier than 2.2.2-13.woody.9' test_ref='oval:org.debian.oval:tst:432'/>
            <criterion comment='kdelibs-dev DPKG is earlier than 2.2.2-13.woody.9' test_ref='oval:org.debian.oval:tst:433'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:460' class='vulnerability'>
      <metadata>
        <title>insecure temporary file</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>sysstat</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0108' ref_id='CVE-2004-0108'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-03-10</date>
          <moreinfo>
Alan Cox discovered that the isag utility (which graphically displays
data collected by the sysstat tools), creates a temporary file without
taking proper precautions.  This vulnerability could allow a local
attacker to overwrite files with the privileges of the user invoking
isag.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='isag DPKG is earlier than 4.0.4-1woody1' test_ref='oval:org.debian.oval:tst:434'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='sysstat DPKG is earlier than 4.0.4-1woody1' test_ref='oval:org.debian.oval:tst:435'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:461' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>calife</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0188' ref_id='CVE-2004-0188'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-03-11</date>
          <moreinfo>
Leon Juranic discovered a buffer overflow related to the
getpass(3) library function in
calife, a program which provides super user privileges to specific
users.  A local attacker could potentially
exploit this vulnerability, given knowledge of a local user's password
and the presence of at least one entry in /etc/calife.auth, to execute
arbitrary code with root privileges.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='calife DPKG is earlier than 2.8.4c-1woody1' test_ref='oval:org.debian.oval:tst:436'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:462' class='vulnerability'>
      <metadata>
        <title>missing privilege release</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>xitalk</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0151' ref_id='CVE-2004-0151'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-03-12</date>
          <moreinfo>
Steve Kemp from the Debian Security Audit Project discovered a problem in
xitalk, a talk intercept utility for the X Window System.  A local
user can exploit this problem and execute arbitrary commands under the
GID utmp.  This could be used by an attacker to remove traces from the
utmp file.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='xitalk DPKG is earlier than 1.1.11-9.1woody1' test_ref='oval:org.debian.oval:tst:437'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:463' class='vulnerability'>
      <metadata>
        <title>privilege escalation</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>samba</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0186' ref_id='CVE-2004-0186'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-03-12</date>
          <moreinfo>
Samba, a LanManager-like file and printer server for Unix, was found
to contain a vulnerability whereby a local user could use the "smbmnt"
utility, which is setuid root, to mount a file share from a remote
server which contained setuid programs under the control of the user.
These programs could then be executed to gain privileges on the local
system.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='samba-doc DPKG is earlier than 2.2.3a-13' test_ref='oval:org.debian.oval:tst:438'/>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:118'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:119'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:120'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:123'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:122'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:112'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:48'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:121'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='smbfs DPKG is earlier than 2.2.3a-13' test_ref='oval:org.debian.oval:tst:439'/>
              <criterion comment='samba DPKG is earlier than 2.2.3a-13' test_ref='oval:org.debian.oval:tst:440'/>
              <criterion comment='swat DPKG is earlier than 2.2.3a-13' test_ref='oval:org.debian.oval:tst:441'/>
              <criterion comment='libsmbclient DPKG is earlier than 2.2.3a-13' test_ref='oval:org.debian.oval:tst:442'/>
              <criterion comment='smbclient DPKG is earlier than 2.2.3a-13' test_ref='oval:org.debian.oval:tst:443'/>
              <criterion comment='winbind DPKG is earlier than 2.2.3a-13' test_ref='oval:org.debian.oval:tst:444'/>
              <criterion comment='libpam-smbpass DPKG is earlier than 2.2.3a-13' test_ref='oval:org.debian.oval:tst:445'/>
              <criterion comment='libsmbclient-dev DPKG is earlier than 2.2.3a-13' test_ref='oval:org.debian.oval:tst:446'/>
              <criterion comment='samba-common DPKG is earlier than 2.2.3a-13' test_ref='oval:org.debian.oval:tst:447'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:128'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='smbfs DPKG is earlier than 2.2.3a-12.3' test_ref='oval:org.debian.oval:tst:448'/>
              <criterion comment='samba DPKG is earlier than 2.2.3a-12.3' test_ref='oval:org.debian.oval:tst:449'/>
              <criterion comment='swat DPKG is earlier than 2.2.3a-12.3' test_ref='oval:org.debian.oval:tst:450'/>
              <criterion comment='libsmbclient DPKG is earlier than 2.2.3a-12.3' test_ref='oval:org.debian.oval:tst:451'/>
              <criterion comment='smbclient DPKG is earlier than 2.2.3a-12.3' test_ref='oval:org.debian.oval:tst:452'/>
              <criterion comment='winbind DPKG is earlier than 2.2.3a-12.3' test_ref='oval:org.debian.oval:tst:453'/>
              <criterion comment='libpam-smbpass DPKG is earlier than 2.2.3a-12.3' test_ref='oval:org.debian.oval:tst:454'/>
              <criterion comment='libsmbclient-dev DPKG is earlier than 2.2.3a-12.3' test_ref='oval:org.debian.oval:tst:455'/>
              <criterion comment='samba-common DPKG is earlier than 2.2.3a-12.3' test_ref='oval:org.debian.oval:tst:456'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:464' class='vulnerability'>
      <metadata>
        <title>broken image handling</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>gdk-pixbuf</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0111' ref_id='CVE-2004-0111'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-03-16</date>
          <moreinfo>
Thomas Kristensen discovered a vulnerability in gdk-pixbuf (binary
package libgdk-pixbuf2), the GdkPixBuf image library for Gtk, that can
cause the surrounding application to crash.  To exploit this problem,
a remote attacker could send a carefully-crafted BMP file via mail,
which would cause e.g. Evolution to crash but is probably not limited
to Evolution.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libgdk-pixbuf-dev DPKG is earlier than 0.17.0-2woody1' test_ref='oval:org.debian.oval:tst:457'/>
            <criterion comment='libgdk-pixbuf2 DPKG is earlier than 0.17.0-2woody1' test_ref='oval:org.debian.oval:tst:458'/>
            <criterion comment='libgdk-pixbuf-gnome-dev DPKG is earlier than 0.17.0-2woody1' test_ref='oval:org.debian.oval:tst:459'/>
            <criterion comment='libgdk-pixbuf-gnome2 DPKG is earlier than 0.17.0-2woody1' test_ref='oval:org.debian.oval:tst:460'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:465' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>openssl,openssl094,openssl095</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0079' ref_id='CVE-2004-0079'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0081' ref_id='CVE-2004-0081'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-03-17</date>
          <moreinfo>
Two vulnerabilities were discovered in openssl, an implementation of
the SSL protocol, using the Codenomicon TLS Test Tool.  More
information can be found in the following &lt;a
href="http://www.uniras.gov.uk/vuls/2004/224012/index.htm">NISCC
Vulnerability Advisory&lt;/a> and this &lt;a
href="http://www.openssl.org/news/secadv_20040317.txt">OpenSSL
advisory&lt;/a>.  The Common Vulnerabilities and Exposures project
identified the following vulnerabilities:
Null-pointer assignment in the
   do_change_cipher_spec() function.  A remote attacker could perform
   a carefully crafted SSL/TLS handshake against a server that used
   the OpenSSL library in such a way as to cause OpenSSL to crash.
   Depending on the application this could lead to a denial of
   service.
A bug in older versions of OpenSSL 0.9.6 that
   can lead to a Denial of Service attack (infinite loop).</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='ssleay DPKG is earlier than 0.9.6c-2.woody.6' test_ref='oval:org.debian.oval:tst:461'/>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:118'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:119'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:120'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:123'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:122'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:112'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:48'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:121'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libssl-dev DPKG is earlier than 0.9.6c-2.woody.6' test_ref='oval:org.debian.oval:tst:462'/>
              <criterion comment='libssl0.9.6 DPKG is earlier than 0.9.6c-2.woody.6' test_ref='oval:org.debian.oval:tst:463'/>
              <criterion comment='openssl DPKG is earlier than 0.9.6c-2.woody.6' test_ref='oval:org.debian.oval:tst:464'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libssl09 DPKG is earlier than 0.9.4-6.woody.3' test_ref='oval:org.debian.oval:tst:465'/>
              <criterion comment='libssl095a DPKG is earlier than 0.9.5a-6.woody.5' test_ref='oval:org.debian.oval:tst:466'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported platform section' operator='AND'>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:123'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='libssl095a DPKG is earlier than 0.9.5a-6.woody.5' test_ref='oval:org.debian.oval:tst:476'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:466' class='vulnerability'>
      <metadata>
        <title>failing function and TLB flush</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>kernel-source-2.2.10, kernel-image-2.2.10-powerpc-apus</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0077' ref_id='CVE-2004-0077'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-03-18</date>
          <moreinfo>
Paul Starzetz and Wojciech Purczynski of isec.pl 
&lt;a href="http://isec.pl/vulnerabilities/isec-0014-mremap-unmap.txt">\
discovered&lt;/a> a critical
security vulnerability in the memory management code of Linux inside
the mremap(2) system call.  Due to flushing the TLB (Translation
Lookaside Buffer, an address cache) too early it is possible for an
attacker to trigger a local root exploit.
The attack vectors for 2.4.x and 2.2.x kernels are exclusive for the
respective kernel series, though.  We formerly believed that the
exploitable vulnerability in 2.4.x does not exist in 2.2.x which is
still true.  However, it turned out that a second (sort of)
vulnerability is indeed exploitable in 2.2.x, but not in 2.4.x, with a
different exploit, of course.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-doc-2.2.10 DPKG is earlier than 2.2.10-2' test_ref='oval:org.debian.oval:tst:477'/>
              <criterion comment='kernel-source-2.2.10 DPKG is earlier than 2.2.10-2' test_ref='oval:org.debian.oval:tst:478'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-image-2.2.10-apus DPKG is earlier than 2.2.10-13woody1' test_ref='oval:org.debian.oval:tst:479'/>
              <criterion comment='kernel-headers-2.2.10-apus DPKG is earlier than 2.2.10-13woody1' test_ref='oval:org.debian.oval:tst:480'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:467' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>ecartis</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0781' ref_id='CVE-2003-0781'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0782' ref_id='CVE-2003-0782'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-03-23</date>
          <moreinfo>
Timo Sirainen discovered two vulnerabilities in ecartis, a mailing
list manager.
Failure to validate user input could lead to
   disclosure of mailing list passwords
Multiple buffer overflows</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:118'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:119'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:120'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:121'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:122'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:112'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:48'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:123'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='ecartis DPKG is earlier than 0.129a+1.0.0-snap20020514-1.2' test_ref='oval:org.debian.oval:tst:481'/>
              <criterion comment='ecartis-cgi DPKG is earlier than 0.129a+1.0.0-snap20020514-1.2' test_ref='oval:org.debian.oval:tst:482'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:128'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='ecartis DPKG is earlier than 0.129a+1.0.0-snap20020514-1.1' test_ref='oval:org.debian.oval:tst:483'/>
              <criterion comment='ecartis-cgi DPKG is earlier than 0.129a+1.0.0-snap20020514-1.1' test_ref='oval:org.debian.oval:tst:484'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:468' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>emil</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0152' ref_id='CVE-2004-0152'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0153' ref_id='CVE-2004-0153'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-03-24</date>
          <moreinfo>
Ulf Härnhammar discovered a number of vulnerabilities in emil, a
filter for converting Internet mail messages.  The vulnerabilities
fall into two categories:
Buffer overflows in (1) the encode_mime function,
   (2) the encode_uuencode function, (3) the decode_uuencode
   function.  These bugs could allow a carefully crafted email message
   to cause the execution of arbitrary code supplied with the message
   when it is acted upon by emil.
Format string bugs in statements which print
   various error messages.  The exploit potential of these bugs has
   not been established, and is probably configuration-dependent.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='emil DPKG is earlier than 2.1.0-beta9-11woody1' test_ref='oval:org.debian.oval:tst:485'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:469' class='vulnerability'>
      <metadata>
        <title>missing input sanitising</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>pam-pgsql</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0366' ref_id='CVE-2004-0366'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-03-29</date>
          <moreinfo>
Primoz Bratanic discovered a bug in libpam-pgsql, a PAM module to
authenticate using a PostgreSQL database.  The library does not escape
all user-supplied data that are sent to the database.  An attacker
could exploit this bug to insert SQL statements.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libpam-pgsql DPKG is earlier than 0.5.2-3woody2' test_ref='oval:org.debian.oval:tst:486'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:470' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>kernel-image-2.4.17-hppa</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0961' ref_id='CVE-2003-0961'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0985' ref_id='CVE-2003-0985'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0077' ref_id='CVE-2004-0077'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-04-01</date>
          <moreinfo>
Several local root exploits have been discovered recently in the Linux
kernel.  This security advisory updates the hppa kernel 2.4.17 for
Debian GNU/Linux.  The Common Vulnerabilities and Exposures project
identifies the following problems that are fixed with this update:
An integer overflow in brk() system call (do_brk() function) for
   Linux allows a local attacker to gain root privileges.  Fixed
   upstream in Linux 2.4.23.
Paul Starzetz discovered a flaw in bounds checking in mremap() in
   the Linux kernel (present in version 2.4.x and 2.6.x) which may
   allow a local attacker to gain root privileges.  Version 2.2 is not
   affected by this bug.  Fixed upstream in Linux 2.4.24.
Paul Starzetz and Wojciech Purczynski of isec.pl discovered a
   critical security vulnerability in the memory management code of
   Linux inside the mremap(2) system call.  Due to missing function
   return value check of internal functions a local attacker can gain
   root privileges.  Fixed upstream in Linux 2.4.25 and 2.6.3.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='kernel-source-2.4.17-hppa DPKG is earlier than 32.3' test_ref='oval:org.debian.oval:tst:487'/>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:121'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-image-2.4.17-64-smp DPKG is earlier than 32.3' test_ref='oval:org.debian.oval:tst:488'/>
              <criterion comment='kernel-image-2.4.17-32 DPKG is earlier than 32.3' test_ref='oval:org.debian.oval:tst:489'/>
              <criterion comment='kernel-image-2.4.17-64 DPKG is earlier than 32.3' test_ref='oval:org.debian.oval:tst:490'/>
              <criterion comment='kernel-headers-2.4.17-hppa DPKG is earlier than 32.3' test_ref='oval:org.debian.oval:tst:491'/>
              <criterion comment='kernel-image-2.4.17-32-smp DPKG is earlier than 32.3' test_ref='oval:org.debian.oval:tst:492'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:471' class='vulnerability'>
      <metadata>
        <title>missing input sanitising</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>interchange</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0374' ref_id='CVE-2004-0374'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-04-02</date>
          <moreinfo>
A vulnerability was discovered recently in Interchange, an e-commerce
and general HTTP database display system.  This vulnerability can be
exploited by an attacker to expose the content of arbitrary variables.
An attacker may learn SQL access information for your Interchange
application and use this information to read and manipulate sensitive
data.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='interchange-ui DPKG is earlier than 4.8.3.20020306-1.woody.2' test_ref='oval:org.debian.oval:tst:493'/>
              <criterion comment='interchange-cat-foundation DPKG is earlier than 4.8.3.20020306-1.woody.2' test_ref='oval:org.debian.oval:tst:494'/>
            </criteria>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libapache-mod-interchange DPKG is earlier than 4.8.3.20020306-1.woody.2' test_ref='oval:org.debian.oval:tst:495'/>
            <criterion comment='interchange DPKG is earlier than 4.8.3.20020306-1.woody.2' test_ref='oval:org.debian.oval:tst:496'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:472' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>fte</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0648' ref_id='CVE-2003-0648'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-04-03</date>
          <moreinfo>
Steve Kemp and Jaguar discovered a number of buffer overflow
vulnerabilities in vfte, a version of the fte editor which runs on the
Linux console, found in the package fte-console.  This program is
setuid root in order to perform certain types of low-level operations
on the console.
Due to these bugs, setuid privilege has been removed from vfte, making
it only usable by root.  We recommend using the terminal version (in
the fte-terminal package) instead, which runs on any capable terminal
including the Linux console.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='fte-console DPKG is earlier than 0.49.13-15woody1' test_ref='oval:org.debian.oval:tst:497'/>
            <criterion comment='fte-terminal DPKG is earlier than 0.49.13-15woody1' test_ref='oval:org.debian.oval:tst:498'/>
            <criterion comment='fte DPKG is earlier than 0.49.13-15woody1' test_ref='oval:org.debian.oval:tst:499'/>
            <criterion comment='fte-docs DPKG is earlier than 0.49.13-15woody1' test_ref='oval:org.debian.oval:tst:500'/>
            <criterion comment='fte-xwindow DPKG is earlier than 0.49.13-15woody1' test_ref='oval:org.debian.oval:tst:501'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:473' class='vulnerability'>
      <metadata>
        <title>denial of service</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>oftpd</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0376' ref_id='CVE-2004-0376'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-04-03</date>
          <moreinfo>
A vulnerability was discovered in oftpd, an anonymous FTP server,
whereby a remote attacker could cause the oftpd process to crash by
specifying a large value in a PORT command.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:118'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:119'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:121'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:122'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:112'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:48'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:128'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:123'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='oftpd DPKG is earlier than 0.3.6-6' test_ref='oval:org.debian.oval:tst:502'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:474' class='vulnerability'>
      <metadata>
        <title>ACL bypass</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>squid</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0189' ref_id='CVE-2004-0189'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-04-03</date>
          <moreinfo>
A vulnerability was discovered in squid, an Internet object cache,
whereby access control lists based on URLs could be bypassed
(&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0189">CAN-2004-0189&lt;/a>).  Two other bugs were also fixed with patches
squid-2.4.STABLE7-url_escape.patch (a buffer overrun which does not
appear to be exploitable) and squid-2.4.STABLE7-url_port.patch (a
potential denial of service).</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:118'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:119'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:120'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:121'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:122'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:112'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:48'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:123'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='squidclient DPKG is earlier than 2.4.6-2woody2' test_ref='oval:org.debian.oval:tst:503'/>
              <criterion comment='squid DPKG is earlier than 2.4.6-2woody2' test_ref='oval:org.debian.oval:tst:504'/>
              <criterion comment='squid-cgi DPKG is earlier than 2.4.6-2woody2' test_ref='oval:org.debian.oval:tst:505'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:128'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='squidclient DPKG is earlier than 2.4.6-2woody1' test_ref='oval:org.debian.oval:tst:506'/>
              <criterion comment='squid DPKG is earlier than 2.4.6-2woody1' test_ref='oval:org.debian.oval:tst:507'/>
              <criterion comment='squid-cgi DPKG is earlier than 2.4.6-2woody1' test_ref='oval:org.debian.oval:tst:508'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:475' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>kernel-image-2.4.18-hppa</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0961' ref_id='CVE-2003-0961'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0985' ref_id='CVE-2003-0985'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0077' ref_id='CVE-2004-0077'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-04-05</date>
          <moreinfo>
Several local root exploits have been discovered recently in the Linux
kernel.  This security advisory updates the PA-RISC kernel 2.4.18 for
Debian GNU/Linux.  The Common Vulnerabilities and Exposures project
identifies the following problems that are fixed with this update:
An integer overflow in brk() system call (do_brk() function) for
   Linux allows a local attacker to gain root privileges.  Fixed
   upstream in Linux 2.4.23.
Paul Starzetz discovered a flaw in bounds checking in mremap() in
   the Linux kernel (present in version 2.4.x and 2.6.x) which may
   allow a local attacker to gain root privileges.  Version 2.2 is not
   affected by this bug.  Fixed upstream in Linux 2.4.24.
Paul Starzetz and Wojciech Purczynski of isec.pl discovered a
   critical security vulnerability in the memory management code of
   Linux inside the mremap(2) system call.  Due to missing function
   return value check of internal functions a local attacker can gain
   root privileges.  Fixed upstream in Linux 2.4.25 and 2.6.3.
Please note that the source package has to include a lot of updates in
order to compile the package, which wasn't possible with the old
source package.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='kernel-source-2.4.18-hppa DPKG is earlier than 62.1' test_ref='oval:org.debian.oval:tst:509'/>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:121'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-image-2.4.18-32-smp DPKG is earlier than 62.1' test_ref='oval:org.debian.oval:tst:510'/>
              <criterion comment='kernel-image-2.4.18-64 DPKG is earlier than 62.1' test_ref='oval:org.debian.oval:tst:511'/>
              <criterion comment='kernel-image-2.4.18-32 DPKG is earlier than 62.1' test_ref='oval:org.debian.oval:tst:512'/>
              <criterion comment='kernel-headers-2.4.18-hppa DPKG is earlier than 62.1' test_ref='oval:org.debian.oval:tst:513'/>
              <criterion comment='kernel-image-2.4.18-64-smp DPKG is earlier than 62.1' test_ref='oval:org.debian.oval:tst:514'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:476' class='vulnerability'>
      <metadata>
        <title>cross-realm</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>heimdal</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0371' ref_id='CVE-2004-0371'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-04-06</date>
          <moreinfo>
According to a &lt;a href="http://www.pdc.kth.se/heimdal/advisory/2004-04-01/">\
security advisory&lt;/a> from the heimdal project,
heimdal, a suite of software implementing the Kerberos protocol, has
"a cross-realm vulnerability allowing someone with control over a
realm to impersonate anyone in the cross-realm trust path."</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='heimdal-lib DPKG is earlier than 0.4e-7.woody.8.1' test_ref='oval:org.debian.oval:tst:515'/>
              <criterion comment='heimdal-docs DPKG is earlier than 0.4e-7.woody.8.1' test_ref='oval:org.debian.oval:tst:516'/>
            </criteria>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libroken9-heimdal DPKG is earlier than 0.4e-7.woody.8.1' test_ref='oval:org.debian.oval:tst:517'/>
            <criterion comment='heimdal-clients DPKG is earlier than 0.4e-7.woody.8.1' test_ref='oval:org.debian.oval:tst:518'/>
            <criterion comment='libotp0-heimdal DPKG is earlier than 0.4e-7.woody.8.1' test_ref='oval:org.debian.oval:tst:519'/>
            <criterion comment='heimdal-servers-x DPKG is earlier than 0.4e-7.woody.8.1' test_ref='oval:org.debian.oval:tst:520'/>
            <criterion comment='libkadm5clnt4-heimdal DPKG is earlier than 0.4e-7.woody.8.1' test_ref='oval:org.debian.oval:tst:521'/>
            <criterion comment='heimdal-dev DPKG is earlier than 0.4e-7.woody.8.1' test_ref='oval:org.debian.oval:tst:522'/>
            <criterion comment='libkafs0-heimdal DPKG is earlier than 0.4e-7.woody.8.1' test_ref='oval:org.debian.oval:tst:523'/>
            <criterion comment='libkadm5srv7-heimdal DPKG is earlier than 0.4e-7.woody.8.1' test_ref='oval:org.debian.oval:tst:524'/>
            <criterion comment='heimdal-servers DPKG is earlier than 0.4e-7.woody.8.1' test_ref='oval:org.debian.oval:tst:525'/>
            <criterion comment='heimdal-clients-x DPKG is earlier than 0.4e-7.woody.8.1' test_ref='oval:org.debian.oval:tst:526'/>
            <criterion comment='libgssapi1-heimdal DPKG is earlier than 0.4e-7.woody.8.1' test_ref='oval:org.debian.oval:tst:527'/>
            <criterion comment='libss0-heimdal DPKG is earlier than 0.4e-7.woody.8.1' test_ref='oval:org.debian.oval:tst:528'/>
            <criterion comment='libhdb7-heimdal DPKG is earlier than 0.4e-7.woody.8.1' test_ref='oval:org.debian.oval:tst:529'/>
            <criterion comment='libsl0-heimdal DPKG is earlier than 0.4e-7.woody.8.1' test_ref='oval:org.debian.oval:tst:530'/>
            <criterion comment='libasn1-5-heimdal DPKG is earlier than 0.4e-7.woody.8.1' test_ref='oval:org.debian.oval:tst:531'/>
            <criterion comment='libkrb5-17-heimdal DPKG is earlier than 0.4e-7.woody.8.1' test_ref='oval:org.debian.oval:tst:532'/>
            <criterion comment='heimdal-kdc DPKG is earlier than 0.4e-7.woody.8.1' test_ref='oval:org.debian.oval:tst:533'/>
            <criterion comment='libcomerr1-heimdal DPKG is earlier than 0.4e-7.woody.8.1' test_ref='oval:org.debian.oval:tst:534'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:477' class='vulnerability'>
      <metadata>
        <title>insecure temporary file creation</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>xine-ui</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0372' ref_id='CVE-2004-0372'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-04-06</date>
          <moreinfo>
Shaun Colley discovered a problem in xine-ui, the xine video player
user interface.  A script contained in the package to possibly remedy
a problem or report a bug does not create temporary files in a secure
fashion.  This could allow a local attacker to overwrite files with
the privileges of the user invoking xine.
This update also removes the bug reporting facility since bug reports
can't be processed upstream anymore.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='xine-ui DPKG is earlier than 0.9.8-5.1' test_ref='oval:org.debian.oval:tst:535'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:478' class='vulnerability'>
      <metadata>
        <title>denial of service</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>tcpdump</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0183' ref_id='CVE-2004-0183'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0184' ref_id='CVE-2004-0184'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-04-06</date>
          <moreinfo>
tcpdump, a tool for network monitoring and data acquisition, was found
to contain two vulnerabilities whereby tcpdump could be caused to
crash through attempts to read from invalid memory locations.  This
bug is triggered by certain invalid ISAKMP packets.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='tcpdump DPKG is earlier than 3.6.2-2.8' test_ref='oval:org.debian.oval:tst:536'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:479' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>kernel-source-2.4.18 kernel-image-2.4.18-1-alpha kernel-image-2.4.18-1-i386 kernel-image-2.4.18-i386bf kernel-patch-2.4.18-powerpc</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0003' ref_id='CVE-2004-0003'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0010' ref_id='CVE-2004-0010'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0109' ref_id='CVE-2004-0109'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0177' ref_id='CVE-2004-0177'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0178' ref_id='CVE-2004-0178'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-04-14</date>
          <moreinfo>
Several serious problems have been discovered in the Linux kernel.
This update takes care of Linux 2.4.18 for the alpha, i386 and powerpc
architectures.  The Common Vulnerabilities and Exposures project
identifies the following problems that will be fixed with this update:
A vulnerability has been discovered in the R128 DRI driver in the Linux
    kernel which could potentially lead an attacker to gain
    unauthorised privileges.  Alan Cox and Thomas Biege developed a
    correction for this.
Arjan van de Ven discovered a stack-based buffer overflow in the
    ncp_lookup function for ncpfs in the Linux kernel, which could
    lead an attacker to gain unauthorised privileges.  Petr Vandrovec
    developed a correction for this.
zen-parse discovered a buffer overflow vulnerability in the
    ISO9660 filesystem component of Linux kernel which could be abused
    by an attacker to gain unauthorised root access.  Sebastian
    Krahmer and Ernie Petrides developed a correction for this.
Solar Designer discovered an information leak in the ext3 code of
    Linux.  In a worst case an attacker could read sensitive data such
    as cryptographic keys which would otherwise never hit disk media.
    Theodore Ts'o developed a correction for this.
Andreas Kies discovered a denial of service condition in the Sound
    Blaster driver in Linux.  He also developed a correction for this.
These problems are also fixed by upstream in Linux 2.4.26 and will be
fixed in Linux 2.6.6.
The following security matrix explains which kernel versions for which
architectures are already fixed.  Kernel images in the unstable Debian
distribution (sid) will be fixed soon.
We recommend that you upgrade your kernel packages immediately, either
with a Debian provided kernel or with a self compiled one.
&lt;a href="CAN-2004-0109">Vulnerability matrix&lt;/a> for CAN-2004-0109</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-source-2.4.18 DPKG is earlier than 2.4.18-14.3' test_ref='oval:org.debian.oval:tst:537'/>
              <criterion comment='kernel-doc-2.4.18 DPKG is earlier than 2.4.18-14.3' test_ref='oval:org.debian.oval:tst:538'/>
              <criterion comment='kernel-patch-2.4.18-powerpc DPKG is earlier than 2.4.18-1woody5' test_ref='oval:org.debian.oval:tst:539'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:48'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-image-2.4.18-1-generic DPKG is earlier than 2.4.18-15' test_ref='oval:org.debian.oval:tst:540'/>
              <criterion comment='kernel-headers-2.4.18-1 DPKG is earlier than 2.4.18-15' test_ref='oval:org.debian.oval:tst:541'/>
              <criterion comment='kernel-headers-2.4.18-1-smp DPKG is earlier than 2.4.18-15' test_ref='oval:org.debian.oval:tst:542'/>
              <criterion comment='kernel-image-2.4.18-1-smp DPKG is earlier than 2.4.18-15' test_ref='oval:org.debian.oval:tst:543'/>
              <criterion comment='kernel-headers-2.4.18-1-generic DPKG is earlier than 2.4.18-15' test_ref='oval:org.debian.oval:tst:544'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-image-2.4.18-1-586tsc DPKG is earlier than 2.4.18-13' test_ref='oval:org.debian.oval:tst:545'/>
              <criterion comment='kernel-pcmcia-modules-2.4.18-1-586tsc DPKG is earlier than 2.4.18-13' test_ref='oval:org.debian.oval:tst:546'/>
              <criterion comment='kernel-image-2.4.18-bf2.4 DPKG is earlier than 2.4.18-5woody8' test_ref='oval:org.debian.oval:tst:547'/>
              <criterion comment='kernel-pcmcia-modules-2.4.18-1-686 DPKG is earlier than 2.4.18-13' test_ref='oval:org.debian.oval:tst:548'/>
              <criterion comment='kernel-headers-2.4.18-1-586tsc DPKG is earlier than 2.4.18-13' test_ref='oval:org.debian.oval:tst:549'/>
              <criterion comment='kernel-pcmcia-modules-2.4.18-1-k6 DPKG is earlier than 2.4.18-13' test_ref='oval:org.debian.oval:tst:550'/>
              <criterion comment='kernel-pcmcia-modules-2.4.18-1-k7 DPKG is earlier than 2.4.18-13' test_ref='oval:org.debian.oval:tst:551'/>
              <criterion comment='kernel-pcmcia-modules-2.4.18-1-686-smp DPKG is earlier than 2.4.18-13' test_ref='oval:org.debian.oval:tst:552'/>
              <criterion comment='kernel-image-2.4.18-1-686 DPKG is earlier than 2.4.18-13' test_ref='oval:org.debian.oval:tst:553'/>
              <criterion comment='kernel-headers-2.4.18-bf2.4 DPKG is earlier than 2.4.18-5woody8' test_ref='oval:org.debian.oval:tst:554'/>
              <criterion comment='kernel-headers-2.4.18-1 DPKG is earlier than 2.4.18-13' test_ref='oval:org.debian.oval:tst:555'/>
              <criterion comment='kernel-headers-2.4.18-1-k6 DPKG is earlier than 2.4.18-13' test_ref='oval:org.debian.oval:tst:556'/>
              <criterion comment='kernel-headers-2.4.18-1-386 DPKG is earlier than 2.4.18-13' test_ref='oval:org.debian.oval:tst:557'/>
              <criterion comment='kernel-image-2.4.18-1-686-smp DPKG is earlier than 2.4.18-13' test_ref='oval:org.debian.oval:tst:558'/>
              <criterion comment='kernel-headers-2.4.18-1-686 DPKG is earlier than 2.4.18-13' test_ref='oval:org.debian.oval:tst:559'/>
              <criterion comment='kernel-headers-2.4.18-1-k7 DPKG is earlier than 2.4.18-13' test_ref='oval:org.debian.oval:tst:560'/>
              <criterion comment='kernel-image-2.4.18-1-k6 DPKG is earlier than 2.4.18-13' test_ref='oval:org.debian.oval:tst:561'/>
              <criterion comment='kernel-image-2.4.18-1-386 DPKG is earlier than 2.4.18-13' test_ref='oval:org.debian.oval:tst:562'/>
              <criterion comment='kernel-pcmcia-modules-2.4.18-1-386 DPKG is earlier than 2.4.18-13' test_ref='oval:org.debian.oval:tst:563'/>
              <criterion comment='kernel-image-2.4.18-1-k7 DPKG is earlier than 2.4.18-13' test_ref='oval:org.debian.oval:tst:564'/>
              <criterion comment='kernel-headers-2.4.18-1-686-smp DPKG is earlier than 2.4.18-13' test_ref='oval:org.debian.oval:tst:565'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported platform section' operator='AND'>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='kernel-image-2.4.18-newpmac DPKG is earlier than 2.4.18-1woody5' test_ref='oval:org.debian.oval:tst:566'/>
                <criterion comment='kernel-headers-2.4.18 DPKG is earlier than 2.4.18-1woody5' test_ref='oval:org.debian.oval:tst:567'/>
                <criterion comment='kernel-image-2.4.18-powerpc DPKG is earlier than 2.4.18-1woody5' test_ref='oval:org.debian.oval:tst:568'/>
                <criterion comment='kernel-image-2.4.18-powerpc-smp DPKG is earlier than 2.4.18-1woody5' test_ref='oval:org.debian.oval:tst:569'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:480' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>kernel-image-2.4.17-hppa kernel-image-2.4.18-hppa</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0003' ref_id='CVE-2004-0003'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0010' ref_id='CVE-2004-0010'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0109' ref_id='CVE-2004-0109'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0177' ref_id='CVE-2004-0177'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0178' ref_id='CVE-2004-0178'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-04-14</date>
          <moreinfo>
Several serious problems have been discovered in the Linux kernel.
This update takes care of Linux 2.4.17 and 2.4.18 for the hppa
(PA-RISC) architecture.  The Common Vulnerabilities and Exposures
project identifies the following problems that will be fixed with this
update:
A vulnerability has been discovered in the R128 DRI driver in the Linux
    kernel which could potentially lead an attacker to gain
    unauthorised privileges.  Alan Cox and Thomas Biege developed a
    correction for this.
Arjan van de Ven discovered a stack-based buffer overflow in the
    ncp_lookup function for ncpfs in the Linux kernel, which could
    lead an attacker to gain unauthorised privileges.  Petr Vandrovec
    developed a correction for this.
zen-parse discovered a buffer overflow vulnerability in the
    ISO9660 filesystem component of Linux kernel which could be abused
    by an attacker to gain unauthorised root access.  Sebastian
    Krahmer and Ernie Petrides developed a correction for this.
Solar Designer discovered an information leak in the ext3 code of
    Linux.  In a worst case an attacker could read sensitive data such
    as cryptographic keys which would otherwise never hit disk media.
    Theodore Ts'o developed a correction for this.
Andreas Kies discovered a denial of service condition in the Sound
    Blaster driver in Linux.  He also developed a correction for this.
These problems are also fixed by upstream in Linux 2.4.26 and will be
fixed in Linux 2.6.6.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-source-2.4.18-hppa DPKG is earlier than 62.3' test_ref='oval:org.debian.oval:tst:570'/>
              <criterion comment='kernel-source-2.4.17-hppa DPKG is earlier than 32.4' test_ref='oval:org.debian.oval:tst:571'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:121'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-image-2.4.17-32 DPKG is earlier than 32.4' test_ref='oval:org.debian.oval:tst:572'/>
              <criterion comment='kernel-image-2.4.18-64-smp DPKG is earlier than 62.3' test_ref='oval:org.debian.oval:tst:573'/>
              <criterion comment='kernel-image-2.4.18-64 DPKG is earlier than 62.3' test_ref='oval:org.debian.oval:tst:574'/>
              <criterion comment='kernel-headers-2.4.17-hppa DPKG is earlier than 32.4' test_ref='oval:org.debian.oval:tst:575'/>
              <criterion comment='kernel-image-2.4.17-32-smp DPKG is earlier than 32.4' test_ref='oval:org.debian.oval:tst:576'/>
              <criterion comment='kernel-image-2.4.18-32 DPKG is earlier than 62.3' test_ref='oval:org.debian.oval:tst:577'/>
              <criterion comment='kernel-headers-2.4.18-hppa DPKG is earlier than 62.3' test_ref='oval:org.debian.oval:tst:578'/>
              <criterion comment='kernel-image-2.4.17-64 DPKG is earlier than 32.4' test_ref='oval:org.debian.oval:tst:579'/>
              <criterion comment='kernel-image-2.4.17-64-smp DPKG is earlier than 32.4' test_ref='oval:org.debian.oval:tst:580'/>
              <criterion comment='kernel-image-2.4.18-32-smp DPKG is earlier than 62.3' test_ref='oval:org.debian.oval:tst:581'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:481' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>kernel-image-2.4.17-ia64</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0003' ref_id='CVE-2004-0003'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0010' ref_id='CVE-2004-0010'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0109' ref_id='CVE-2004-0109'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0177' ref_id='CVE-2004-0177'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0178' ref_id='CVE-2004-0178'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-04-14</date>
          <moreinfo>
Several serious problems have been discovered in the Linux kernel.
This update takes care of Linux 2.4.17 for the IA-64 architecture.
The Common Vulnerabilities and Exposures project identifies the
following problems that will be fixed with this update:
A vulnerability has been discovered in the R128 DRI driver in the Linux
    kernel which could potentially lead an attacker to gain
    unauthorised privileges.  Alan Cox and Thomas Biege developed a
    correction for this.
Arjan van de Ven discovered a stack-based buffer overflow in the
    ncp_lookup function for ncpfs in the Linux kernel, which could
    lead an attacker to gain unauthorised privileges.  Petr Vandrovec
    developed a correction for this.
zen-parse discovered a buffer overflow vulnerability in the
    ISO9660 filesystem component of Linux kernel which could be abused
    by an attacker to gain unauthorised root access.  Sebastian
    Krahmer and Ernie Petrides developed a correction for this.
Solar Designer discovered an information leak in the ext3 code of
    Linux.  In a worst case an attacker could read sensitive data such
    as cryptographic keys which would otherwise never hit disk media.
    Theodore Ts'o developed a correction for this.
Andreas Kies discovered a denial of service condition in the Sound
    Blaster driver in Linux.  He also developed a correction for this.
These problems are also fixed by upstream in Linux 2.4.26 and will be
fixed in Linux 2.6.6.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='kernel-source-2.4.17-ia64 DPKG is earlier than 011226.17' test_ref='oval:org.debian.oval:tst:582'/>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:112'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-image-2.4.17-itanium-smp DPKG is earlier than 011226.17' test_ref='oval:org.debian.oval:tst:583'/>
              <criterion comment='kernel-image-2.4.17-mckinley-smp DPKG is earlier than 011226.17' test_ref='oval:org.debian.oval:tst:584'/>
              <criterion comment='kernel-image-2.4.17-mckinley DPKG is earlier than 011226.17' test_ref='oval:org.debian.oval:tst:585'/>
              <criterion comment='kernel-headers-2.4.17-ia64 DPKG is earlier than 011226.17' test_ref='oval:org.debian.oval:tst:586'/>
              <criterion comment='kernel-image-2.4.17-itanium DPKG is earlier than 011226.17' test_ref='oval:org.debian.oval:tst:587'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:482' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>kernel-source-2.4.17 kernel-patch-2.4.17-apus kernel-patch-2.4.17-s390 kernel-image-2.4.17-s390</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0003' ref_id='CVE-2004-0003'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0010' ref_id='CVE-2004-0010'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0109' ref_id='CVE-2004-0109'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0177' ref_id='CVE-2004-0177'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0178' ref_id='CVE-2004-0178'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-04-14</date>
          <moreinfo>
Several serious problems have been discovered in the Linux kernel.
This update takes care of Linux 2.4.17 for the PowerPC/apus and S/390
architectures.  The Common Vulnerabilities and Exposures project
identifies the following problems that will be fixed with this update:
A vulnerability has been discovered in the R128 DRI driver in the Linux
    kernel which could potentially lead an attacker to gain
    unauthorised privileges.  Alan Cox and Thomas Biege developed a
    correction for this.
Arjan van de Ven discovered a stack-based buffer overflow in the
    ncp_lookup function for ncpfs in the Linux kernel, which could
    lead an attacker to gain unauthorised privileges.  Petr Vandrovec
    developed a correction for this.
zen-parse discovered a buffer overflow vulnerability in the
    ISO9660 filesystem component of Linux kernel which could be abused
    by an attacker to gain unauthorised root access.  Sebastian
    Krahmer and Ernie Petrides developed a correction for this.
Solar Designer discovered an information leak in the ext3 code of
    Linux.  In a worst case an attacker could read sensitive data such
    as cryptographic keys which would otherwise never hit disk media.
    Theodore Ts'o developed a correction for this.
Andreas Kies discovered a denial of service condition in the Sound
    Blaster driver in Linux.  He also developed a correction for this.
These problems are also fixed by upstream in Linux 2.4.26 and will be
fixed in Linux 2.6.6.
The following security matrix explains which kernel versions for which
architectures are already fixed.
We recommend that you upgrade your kernel packages immediately, either
with a Debian provided kernel or with a self compiled one.
&lt;a href="CAN-2004-0109">Vulnerability matrix&lt;/a> for CAN-2004-0109</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-doc-2.4.17 DPKG is earlier than 2.4.17-1woody3' test_ref='oval:org.debian.oval:tst:588'/>
              <criterion comment='kernel-source-2.4.17 DPKG is earlier than 2.4.17-1woody3' test_ref='oval:org.debian.oval:tst:589'/>
              <criterion comment='kernel-patch-2.4.17-s390 DPKG is earlier than 0.0.20020816-0.woody.3' test_ref='oval:org.debian.oval:tst:590'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:118'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-image-2.4.17-s390 DPKG is earlier than 2.4.17-2.woody.4' test_ref='oval:org.debian.oval:tst:591'/>
              <criterion comment='kernel-headers-2.4.17 DPKG is earlier than 2.4.17-2.woody.4' test_ref='oval:org.debian.oval:tst:592'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-headers-2.4.17-apus DPKG is earlier than 2.4.17-5' test_ref='oval:org.debian.oval:tst:593'/>
              <criterion comment='kernel-image-2.4.17-apus DPKG is earlier than 2.4.17-5' test_ref='oval:org.debian.oval:tst:594'/>
              <criterion comment='kernel-patch-2.4.17-apus DPKG is earlier than 2.4.17-5' test_ref='oval:org.debian.oval:tst:595'/>
              <criterion comment='kernel-image-apus DPKG is earlier than 2.4.17-5' test_ref='oval:org.debian.oval:tst:596'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:483' class='vulnerability'>
      <metadata>
        <title>insecure temporary file creation</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>mysql</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0381' ref_id='CVE-2004-0381'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0388' ref_id='CVE-2004-0388'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-04-14</date>
          <moreinfo>
Two vulnerabilities have been discovered in mysql, a common database
system.  Two scripts contained in the package don't create temporary
files in a secure fashion.  This could allow a local attacker to
overwrite files with the privileges of the user invoking the MySQL
server, which is often the root user.  The Common Vulnerabilities and
Exposures identifies the following problems:
The script mysqlbug in MySQL allows local users to overwrite
    arbitrary files via a symlink attack.
The script mysqld_multi in MySQL allows local users to overwrite
    arbitrary files via a symlink attack.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='mysql-common DPKG is earlier than 3.23.49-8.6' test_ref='oval:org.debian.oval:tst:597'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='mysql-client DPKG is earlier than 3.23.49-8.6' test_ref='oval:org.debian.oval:tst:598'/>
            <criterion comment='libmysqlclient10 DPKG is earlier than 3.23.49-8.6' test_ref='oval:org.debian.oval:tst:599'/>
            <criterion comment='libmysqlclient10-dev DPKG is earlier than 3.23.49-8.6' test_ref='oval:org.debian.oval:tst:600'/>
            <criterion comment='mysql-server DPKG is earlier than 3.23.49-8.6' test_ref='oval:org.debian.oval:tst:601'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:484' class='vulnerability'>
      <metadata>
        <title>failure to drop privileges</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>xonix</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0157' ref_id='CVE-2004-0157'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-04-14</date>
          <moreinfo>
Steve Kemp discovered a vulnerability in xonix, a game, where an
external program was invoked while retaining setgid privileges.  A
local attacker could exploit this vulnerability to gain gid "games".</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='xonix DPKG is earlier than 1.4-19woody1' test_ref='oval:org.debian.oval:tst:602'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:485' class='vulnerability'>
      <metadata>
        <title>format string</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>ssmtp</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0156' ref_id='CVE-2004-0156'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-04-14</date>
          <moreinfo>
Max Vozeler discovered two format string vulnerabilities in ssmtp, a
simple mail transport agent.  Untrusted values in the functions die()
and log_event() were passed to printf-like functions as format
strings.  These vulnerabilities could potentially be exploited by a
remote mail relay to gain the privileges of the ssmtp process
(including potentially root).</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='ssmtp DPKG is earlier than 2.50.6.1' test_ref='oval:org.debian.oval:tst:603'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:486' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>cvs</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0180' ref_id='CVE-2004-0180'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0405' ref_id='CVE-2004-0405'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-04-16</date>
          <moreinfo>
Two vulnerabilities have been discovered and fixed in CVS:
Sebastian Krahmer discovered a vulnerability whereby
 a malicious CVS pserver could create arbitrary files on the client
 system during an update or checkout operation, by supplying absolute
 pathnames in RCS diffs.
Derek Robert Price discovered a vulnerability whereby
 a CVS pserver could be abused by a malicious client to view the
 contents of certain files outside of the CVS root directory using
 relative pathnames containing "../".</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='cvs DPKG is earlier than 1.11.1p1debian-9woody2' test_ref='oval:org.debian.oval:tst:604'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:487' class='vulnerability'>
      <metadata>
        <title>format string</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>neon</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0179' ref_id='CVE-2004-0179'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-04-16</date>
          <moreinfo>
Multiple format string vulnerabilities were discovered in neon, an
HTTP and WebDAV client library.  These vulnerabilities could
potentially be exploited by a malicious WebDAV server to execute
arbitrary code with the privileges of the process using libneon.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libneon-dev DPKG is earlier than 0.19.3-2woody3' test_ref='oval:org.debian.oval:tst:605'/>
            <criterion comment='libneon19 DPKG is earlier than 0.19.3-2woody3' test_ref='oval:org.debian.oval:tst:606'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:488' class='vulnerability'>
      <metadata>
        <title>insecure temporary directory</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>logcheck</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0404' ref_id='CVE-2004-0404'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-04-16</date>
          <moreinfo>
Christian Jaeger reported a bug in logcheck which could potentially be
exploited by a local user to overwrite files with root privileges.
logcheck utilized a temporary directory under /var/tmp without taking
security precautions.  While this directory is created when logcheck
is installed, and while it exists there is no vulnerability, if at
any time this directory is removed, the potential for exploitation exists.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='logcheck-database DPKG is earlier than 1.1.1-13.1woody1' test_ref='oval:org.debian.oval:tst:607'/>
              <criterion comment='logtail DPKG is earlier than 1.1.1-13.1woody1' test_ref='oval:org.debian.oval:tst:608'/>
              <criterion comment='logcheck DPKG is earlier than 1.1.1-13.1woody1' test_ref='oval:org.debian.oval:tst:609'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:489' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>kernel-source-2.4.17 kernel-patch-2.4.17-mips</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0003' ref_id='CVE-2004-0003'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0010' ref_id='CVE-2004-0010'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0109' ref_id='CVE-2004-0109'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0177' ref_id='CVE-2004-0177'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0178' ref_id='CVE-2004-0178'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-04-17</date>
          <moreinfo>
Several serious problems have been discovered in the Linux kernel.
This update takes care of Linux 2.4.17 for the MIPS and MIPSel
architectures.  The Common Vulnerabilities and Exposures project
identifies the following problems that will be fixed with this update:
A vulnerability has been discovered in the R128 DRI driver in the Linux
    kernel which could potentially lead an attacker to gain
    unauthorised privileges.  Alan Cox and Thomas Biege developed a
    correction for this.
Arjan van de Ven discovered a stack-based buffer overflow in the
    ncp_lookup function for ncpfs in the Linux kernel, which could
    lead an attacker to gain unauthorised privileges.  Petr Vandrovec
    developed a correction for this.
zen-parse discovered a buffer overflow vulnerability in the
    ISO9660 filesystem component of Linux kernel which could be abused
    by an attacker to gain unauthorised root access.  Sebastian
    Krahmer and Ernie Petrides developed a correction for this.
Solar Designer discovered an information leak in the ext3 code of
    Linux.  In a worst case an attacker could read sensitive data such
    as cryptographic keys which would otherwise never hit disk media.
    Theodore Ts'o developed a correction for this.
Andreas Kies discovered a denial of service condition in the Sound
    Blaster driver in Linux.  He also developed a correction for this.
These problems are also fixed by upstream in Linux 2.4.26 and will be
fixed in Linux 2.6.6.
The following security matrix explains which kernel versions for which
architectures are already fixed and which will be removed instead.
We recommend that you upgrade your kernel packages immediately, either
with a Debian provided kernel or with a self compiled one.
&lt;a href="CAN-2004-0109">Vulnerability matrix&lt;/a> for CAN-2004-0109</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-patch-2.4.17-mips DPKG is earlier than 2.4.17-0.020226.2.woody6' test_ref='oval:org.debian.oval:tst:610'/>
              <criterion comment='kernel-doc-2.4.17 DPKG is earlier than 2.4.17-1woody3' test_ref='oval:org.debian.oval:tst:611'/>
              <criterion comment='kernel-source-2.4.17 DPKG is earlier than 2.4.17-1woody3' test_ref='oval:org.debian.oval:tst:612'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:122'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-headers-2.4.17 DPKG is earlier than 2.4.17-0.020226.2.woody6' test_ref='oval:org.debian.oval:tst:613'/>
              <criterion comment='kernel-image-2.4.17-r4k-ip22 DPKG is earlier than 2.4.17-0.020226.2.woody6' test_ref='oval:org.debian.oval:tst:614'/>
              <criterion comment='kernel-image-2.4.17-r5k-ip22 DPKG is earlier than 2.4.17-0.020226.2.woody6' test_ref='oval:org.debian.oval:tst:615'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:128'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='mips-tools DPKG is earlier than 2.4.17-0.020226.2.woody6' test_ref='oval:org.debian.oval:tst:616'/>
              <criterion comment='kernel-headers-2.4.17 DPKG is earlier than 2.4.17-0.020226.2.woody6' test_ref='oval:org.debian.oval:tst:617'/>
              <criterion comment='kernel-image-2.4.17-r4k-kn04 DPKG is earlier than 2.4.17-0.020226.2.woody6' test_ref='oval:org.debian.oval:tst:618'/>
              <criterion comment='kernel-image-2.4.17-r3k-kn02 DPKG is earlier than 2.4.17-0.020226.2.woody6' test_ref='oval:org.debian.oval:tst:619'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:490' class='vulnerability'>
      <metadata>
        <title>arbitrary code execution</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>zope</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0688' ref_id='CVE-2002-0688'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-04-17</date>
          <moreinfo>
A vulnerability has been discovered in the index support of the
ZCatalog plug-in in Zope, an open source web application server.  A
flaw in the security settings of ZCatalog allows anonymous users to
call arbitrary methods of catalog indexes.  The vulnerability also
allows untrusted code to do the same.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='zope DPKG is earlier than 2.5.1-1woody1' test_ref='oval:org.debian.oval:tst:620'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:491' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>kernel-source-2.4.19 kernel-patch-2.4.19-mips</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0003' ref_id='CVE-2004-0003'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0010' ref_id='CVE-2004-0010'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0109' ref_id='CVE-2004-0109'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0177' ref_id='CVE-2004-0177'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0178' ref_id='CVE-2004-0178'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-04-17</date>
          <moreinfo>
Several serious problems have been discovered in the Linux kernel.
This update takes care of Linux 2.4.19 for the MIPS architecture.  The
Common Vulnerabilities and Exposures project identifies the following
problems that will be fixed with this update:
A vulnerability has been discovered in the R128 DRI driver in the Linux
    kernel which could potentially lead an attacker to gain
    unauthorised privileges.  Alan Cox and Thomas Biege developed a
    correction for this.
Arjan van de Ven discovered a stack-based buffer overflow in the
    ncp_lookup function for ncpfs in the Linux kernel, which could
    lead an attacker to gain unauthorised privileges.  Petr Vandrovec
    developed a correction for this.
zen-parse discovered a buffer overflow vulnerability in the
    ISO9660 filesystem component of Linux kernel which could be abused
    by an attacker to gain unauthorised root access.  Sebastian
    Krahmer and Ernie Petrides developed a correction for this.
Solar Designer discovered an information leak in the ext3 code of
    Linux.  In a worst case an attacker could read sensitive data such
    as cryptographic keys which would otherwise never hit disk media.
    Theodore Ts'o developed a correction for this.
Andreas Kies discovered a denial of service condition in the Sound
    Blaster driver in Linux.  He also developed a correction for this.
These problems are also fixed by upstream in Linux 2.4.26 and will be
fixed in Linux 2.6.6.
The following security matrix explains which kernel versions for which
architectures are already fixed and which will be removed instead.
We recommend that you upgrade your kernel packages immediately, either
with a Debian provided kernel or with a self compiled one.
&lt;a href="CAN-2004-0109">Vulnerability matrix&lt;/a> for CAN-2004-0109</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-source-2.4.19 DPKG is earlier than 2.4.19-4.woody2' test_ref='oval:org.debian.oval:tst:621'/>
              <criterion comment='kernel-patch-2.4.19-mips DPKG is earlier than 2.4.19-0.020911.1.woody4' test_ref='oval:org.debian.oval:tst:622'/>
              <criterion comment='kernel-doc-2.4.19 DPKG is earlier than 2.4.19-4.woody2' test_ref='oval:org.debian.oval:tst:623'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:122'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='mips-tools DPKG is earlier than 2.4.19-0.020911.1.woody4' test_ref='oval:org.debian.oval:tst:624'/>
              <criterion comment='kernel-headers-2.4.19 DPKG is earlier than 2.4.19-0.020911.1.woody4' test_ref='oval:org.debian.oval:tst:625'/>
              <criterion comment='kernel-image-2.4.19-r4k-ip22 DPKG is earlier than 2.4.19-0.020911.1.woody4' test_ref='oval:org.debian.oval:tst:626'/>
              <criterion comment='kernel-image-2.4.19-r5k-ip22 DPKG is earlier than 2.4.19-0.020911.1.woody4' test_ref='oval:org.debian.oval:tst:627'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:492' class='vulnerability'>
      <metadata>
        <title>denial of service</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>iproute</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0856' ref_id='CVE-2003-0856'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-04-18</date>
          <moreinfo>
Herbert Xu reported that local users could cause a denial of service
against iproute, a set of tools for controlling networking in Linux
kernels.  iproute uses the netlink interface to communicate with the
kernel, but failed to verify that the messages it received came from
the kernel (rather than from other user processes).</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='iproute DPKG is earlier than 20010824-8woody1' test_ref='oval:org.debian.oval:tst:628'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:493' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>xchat</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0409' ref_id='CVE-2004-0409'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-04-21</date>
          <moreinfo>
A buffer overflow has been discovered in the Socks-5 proxy code of
XChat, an IRC client for X similar to AmIRC.  This allows an attacker
to execute arbitrary code on the users' machine.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='xchat-common DPKG is earlier than 1.8.9-0woody3' test_ref='oval:org.debian.oval:tst:629'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='xchat-gnome DPKG is earlier than 1.8.9-0woody3' test_ref='oval:org.debian.oval:tst:630'/>
            <criterion comment='xchat-text DPKG is earlier than 1.8.9-0woody3' test_ref='oval:org.debian.oval:tst:631'/>
            <criterion comment='xchat DPKG is earlier than 1.8.9-0woody3' test_ref='oval:org.debian.oval:tst:632'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:494' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>ident2</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0408' ref_id='CVE-2004-0408'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-04-21</date>
          <moreinfo>
Jack &amp;lt;&lt;email "jack@rapturesecurity.org">&amp;gt; discovered a buffer overflow in
ident2, an implementation of the ident protocol (RFC1413), where a
buffer in the child_service function was slightly too small to hold
all of the data which could be written into it.  This vulnerability
could be exploited by a remote attacker to execute arbitrary code with
the privileges of the ident2 daemon (by default, the "identd" user).</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='ident2 DPKG is earlier than 1.03-3woody1' test_ref='oval:org.debian.oval:tst:633'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:495' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>kernel-source-2.4.16 kernel-patch-2.4.16-arm kernel-image-2.4.16-lart kernel-image-2.4.16-netwinder kernel-image-2.4.16-riscpc</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0127' ref_id='CVE-2003-0127'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0003' ref_id='CVE-2004-0003'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0010' ref_id='CVE-2004-0010'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0109' ref_id='CVE-2004-0109'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0177' ref_id='CVE-2004-0177'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0178' ref_id='CVE-2004-0178'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-04-26</date>
          <moreinfo>
Several serious problems have been discovered in the Linux kernel.
This update takes care of Linux 2.4.16 for the ARM architecture.  The
Common Vulnerabilities and Exposures project identifies the following
problems that will be fixed with this update:
The kernel module loader allows local users to gain root
    privileges by using ptrace to attach to a child process that is
    spawned by the kernel.
A vulnerability has been discovered in the R128 DRI driver in the Linux
    kernel which could potentially lead an attacker to gain
    unauthorised privileges.  Alan Cox and Thomas Biege developed a
    correction for this.
Arjan van de Ven discovered a stack-based buffer overflow in the
    ncp_lookup function for ncpfs in the Linux kernel, which could
    lead an attacker to gain unauthorised privileges.  Petr Vandrovec
    developed a correction for this.
zen-parse discovered a buffer overflow vulnerability in the
    ISO9660 filesystem component of Linux kernel which could be abused
    by an attacker to gain unauthorised root access.  Sebastian
    Krahmer and Ernie Petrides developed a correction for this.
Solar Designer discovered an information leak in the ext3 code of
    Linux.  In a worst case a local attacker could obtain sensitive
    information (such as cryptographic keys in another worst case)
    which would otherwise never hit disk media.  Theodore Ts'o
    developed a correction for this.
Andreas Kies discovered a denial of service condition in the Sound
    Blaster driver in Linux.  He also developed a correction for this.
These problems are also fixed by upstream in Linux 2.4.26 and will be
fixed in Linux 2.6.6.
The following security matrix explains which kernel versions for which
architectures are already fixed and which will be removed instead.
We recommend that you upgrade your kernel packages immediately, either
with a Debian provided kernel or with a self compiled one.
&lt;a href="CAN-2004-0109">Vulnerability matrix&lt;/a> for CAN-2004-0109</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-doc-2.4.16 DPKG is earlier than 2.4.16-1woody2' test_ref='oval:org.debian.oval:tst:634'/>
              <criterion comment='kernel-patch-2.4.16-arm DPKG is earlier than 20040419' test_ref='oval:org.debian.oval:tst:635'/>
              <criterion comment='kernel-source-2.4.16 DPKG is earlier than 2.4.16-1woody2' test_ref='oval:org.debian.oval:tst:636'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:123'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-image-2.4.16-netwinder DPKG is earlier than 20040419' test_ref='oval:org.debian.oval:tst:637'/>
              <criterion comment='kernel-image-2.4.16-riscpc DPKG is earlier than 20040419' test_ref='oval:org.debian.oval:tst:638'/>
              <criterion comment='kernel-headers-2.4.16 DPKG is earlier than 20040419' test_ref='oval:org.debian.oval:tst:639'/>
              <criterion comment='kernel-image-2.4.16-lart DPKG is earlier than 20040419' test_ref='oval:org.debian.oval:tst:640'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:496' class='vulnerability'>
      <metadata>
        <title>missing input sanitising</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>eterm</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0068' ref_id='CVE-2003-0068'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-04-29</date>
          <moreinfo>
H.D. Moore discovered several terminal emulator security issues.  One
of them covers escape codes that are interpreted by the terminal
emulator.  This could be exploited by an attacker to insert malicious
commands hidden for the user, who has to hit enter to continue, which
would also execute the hidden commands.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='eterm DPKG is earlier than 0.9.2-0pre2002042903.3' test_ref='oval:org.debian.oval:tst:641'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:497' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>mc</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0226' ref_id='CVE-2004-0226'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0231' ref_id='CVE-2004-0231'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0232' ref_id='CVE-2004-0232'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-04-29</date>
          <moreinfo>
Jacub Jelinek discovered several vulnerabilities in the Midnight
Commander, a powerful file manager for GNU/Linux systems.  The
problems were classified as follows:
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0226">CAN-2004-0226&lt;/a> Buffer overflows
&lt;br>&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0231">CAN-2004-0231&lt;/a> Insecure temporary file and directory creations
&lt;br>&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0232">CAN-2004-0232&lt;/a> Format string problems</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='gmc DPKG is earlier than 4.5.55-1.2woody3' test_ref='oval:org.debian.oval:tst:642'/>
            <criterion comment='mc DPKG is earlier than 4.5.55-1.2woody3' test_ref='oval:org.debian.oval:tst:643'/>
            <criterion comment='mc-common DPKG is earlier than 4.5.55-1.2woody3' test_ref='oval:org.debian.oval:tst:644'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:498' class='vulnerability'>
      <metadata>
        <title>out of bound access</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>libpng, libpng3</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0421' ref_id='CVE-2004-0421'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-04-30</date>
          <moreinfo>
Steve Grubb discovered a problem in the Portable Network Graphics
library libpng which is utilised in several applications.  When
processing a broken PNG image, the error handling routine will access
memory that is out of bounds when creating an error message.
Depending on machine architecture, bounds checking and other
protective measures, this problem could cause the program to crash if
a defective or intentionally prepared PNG image file is handled by
libpng.
This could be used as a denial of service attack against various
programs that link against this library.  The following commands will
show you which packages utilise this library and whose programs should
probably restarted after an upgrade:
The following security matrix explains which package versions will
contain a correction.
We recommend that you upgrade your libpng and related packages.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libpng2-dev DPKG is earlier than 1.0.12-3.woody.5' test_ref='oval:org.debian.oval:tst:645'/>
            <criterion comment='libpng3 DPKG is earlier than 1.2.1-1.1.woody.5' test_ref='oval:org.debian.oval:tst:646'/>
            <criterion comment='libpng-dev DPKG is earlier than 1.2.1-1.1.woody.5' test_ref='oval:org.debian.oval:tst:647'/>
            <criterion comment='libpng2 DPKG is earlier than 1.0.12-3.woody.5' test_ref='oval:org.debian.oval:tst:648'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:499' class='vulnerability'>
      <metadata>
        <title>directory traversal</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>rsync</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0426' ref_id='CVE-2004-0426'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-06-02</date>
          <moreinfo>
A vulnerability was discovered in rsync, a file transfer program,
whereby a remote user could cause an rsync daemon to write files
outside of the intended directory tree.  This vulnerability is not
exploitable when the daemon is configured with the 'chroot' option.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='rsync DPKG is earlier than 2.5.5-0.5' test_ref='oval:org.debian.oval:tst:649'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:500' class='vulnerability'>
      <metadata>
        <title>insecure temporary file</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>flim</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0422' ref_id='CVE-2004-0422'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-05-01</date>
          <moreinfo>
Tatsuya Kinoshita discovered a vulnerability in flim, an emacs library
for working with internet messages, where temporary files were created
without taking appropriate precautions.  This vulnerability could
potentially be exploited by a local user to overwrite files with the
privileges of the user running emacs.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='flim DPKG is earlier than 1.14.3-9woody1' test_ref='oval:org.debian.oval:tst:650'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:501' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>exim</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0399' ref_id='CVE-2004-0399'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0400' ref_id='CVE-2004-0400'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-05-07</date>
          <moreinfo>
Georgi Guninski discovered two stack-based buffer overflows.  They can
not be exploited with the default configuration from the Debian
system, though.  The Common Vulnerabilities and Exposures project
identifies the following problems that are fixed with this update:
When "sender_verify = true" is configured in exim.conf a buffer
    overflow can happen during verification of the sender.  This
    problem is fixed in exim 4.
When headers_check_syntax is configured in exim.conf a buffer
    overflow can happen during the header check.  This problem does
    also exist in exim 4.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='eximon DPKG is earlier than 3.35-1woody3' test_ref='oval:org.debian.oval:tst:651'/>
            <criterion comment='exim DPKG is earlier than 3.35-1woody3' test_ref='oval:org.debian.oval:tst:652'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:502' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>exim-tls</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0399' ref_id='CVE-2004-0399'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0400' ref_id='CVE-2004-0400'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-05-11</date>
          <moreinfo>
Georgi Guninski discovered two stack-based buffer overflows in exim
and exim-tls.  They cannot be exploited with the default
configuration from the Debian system, though.  The Common
Vulnerabilities and Exposures project identifies the following
problems that are fixed with this update:
When "sender_verify = true" is configured in exim.conf a buffer
    overflow can happen during verification of the sender.  This
    problem is fixed in exim 4.

&lt;li>&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0400">CAN-2004-0400&lt;/a>

    &lt;p>When headers_check_syntax is configured in exim.conf a buffer
    overflow can happen during the header check.  This problem does
    also exist in exim 4.

&lt;/ul>

&lt;p>For the stable distribution (woody) these problems have been fixed in
version 3.35-3woody2.
The unstable distribution (sid) does not contain exim-tls anymore.
The functionality has been incorporated in the main exim versions
which have these problems fixed in version 3.36-11 for exim 3 and in
version 4.33-1 for exim 4.
We recommend that you upgrade your exim-tls package.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='exim-tls DPKG is earlier than 3.35-3woody2' test_ref='oval:org.debian.oval:tst:653'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:503' class='vulnerability'>
      <metadata>
        <title>missing argument check</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>mah-jong</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0458' ref_id='CVE-2004-0458'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-05-13</date>
          <moreinfo>
A problem has been discovered in mah-jong, a variant of the original
Mah-Jong game, that can be utilised to crash the game server after
dereferencing a NULL pointer.  This bug be exploited by any client
that connects to the mah-jong server.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='mah-jong DPKG is earlier than 1.4-3' test_ref='oval:org.debian.oval:tst:654'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:504' class='vulnerability'>
      <metadata>
        <title>missing input sanitising</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>heimdal</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0434' ref_id='CVE-2004-0434'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-05-18</date>
          <moreinfo>
Evgeny Demidov discovered a potential buffer overflow in a Kerberos 4
component of heimdal, a free implementation of Kerberos 5.  The
problem is present in kadmind, a server for administrative access to
the Kerberos database.  This problem could perhaps be exploited to
cause the daemon to read a negative amount of data which could lead to
unexpected behaviour.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='heimdal-lib DPKG is earlier than 0.4e-7.woody.9' test_ref='oval:org.debian.oval:tst:655'/>
              <criterion comment='heimdal-docs DPKG is earlier than 0.4e-7.woody.9' test_ref='oval:org.debian.oval:tst:656'/>
            </criteria>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libroken9-heimdal DPKG is earlier than 0.4e-7.woody.9' test_ref='oval:org.debian.oval:tst:657'/>
            <criterion comment='heimdal-clients DPKG is earlier than 0.4e-7.woody.9' test_ref='oval:org.debian.oval:tst:658'/>
            <criterion comment='libotp0-heimdal DPKG is earlier than 0.4e-7.woody.9' test_ref='oval:org.debian.oval:tst:659'/>
            <criterion comment='heimdal-servers-x DPKG is earlier than 0.4e-7.woody.9' test_ref='oval:org.debian.oval:tst:660'/>
            <criterion comment='libkadm5clnt4-heimdal DPKG is earlier than 0.4e-7.woody.9' test_ref='oval:org.debian.oval:tst:661'/>
            <criterion comment='heimdal-dev DPKG is earlier than 0.4e-7.woody.9' test_ref='oval:org.debian.oval:tst:662'/>
            <criterion comment='libkafs0-heimdal DPKG is earlier than 0.4e-7.woody.9' test_ref='oval:org.debian.oval:tst:663'/>
            <criterion comment='libkadm5srv7-heimdal DPKG is earlier than 0.4e-7.woody.9' test_ref='oval:org.debian.oval:tst:664'/>
            <criterion comment='heimdal-servers DPKG is earlier than 0.4e-7.woody.9' test_ref='oval:org.debian.oval:tst:665'/>
            <criterion comment='heimdal-clients-x DPKG is earlier than 0.4e-7.woody.9' test_ref='oval:org.debian.oval:tst:666'/>
            <criterion comment='libgssapi1-heimdal DPKG is earlier than 0.4e-7.woody.9' test_ref='oval:org.debian.oval:tst:667'/>
            <criterion comment='libss0-heimdal DPKG is earlier than 0.4e-7.woody.9' test_ref='oval:org.debian.oval:tst:668'/>
            <criterion comment='libhdb7-heimdal DPKG is earlier than 0.4e-7.woody.9' test_ref='oval:org.debian.oval:tst:669'/>
            <criterion comment='libsl0-heimdal DPKG is earlier than 0.4e-7.woody.9' test_ref='oval:org.debian.oval:tst:670'/>
            <criterion comment='libasn1-5-heimdal DPKG is earlier than 0.4e-7.woody.9' test_ref='oval:org.debian.oval:tst:671'/>
            <criterion comment='libkrb5-17-heimdal DPKG is earlier than 0.4e-7.woody.9' test_ref='oval:org.debian.oval:tst:672'/>
            <criterion comment='heimdal-kdc DPKG is earlier than 0.4e-7.woody.9' test_ref='oval:org.debian.oval:tst:673'/>
            <criterion comment='libcomerr1-heimdal DPKG is earlier than 0.4e-7.woody.9' test_ref='oval:org.debian.oval:tst:674'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:505' class='vulnerability'>
      <metadata>
        <title>heap overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>cvs</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0396' ref_id='CVE-2004-0396'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-05-19</date>
          <moreinfo>
Stefan Esser discovered a heap overflow in the CVS server, which
serves the popular Concurrent Versions System.  Malformed "Entry"
Lines in combination with Is-modified and Unchanged can be used to
overflow malloc()ed memory.  This was proven to be exploitable.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='cvs DPKG is earlier than 1.11.1p1debian-9woody4' test_ref='oval:org.debian.oval:tst:675'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:506' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>neon</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0398' ref_id='CVE-2004-0398'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-05-19</date>
          <moreinfo>
Stefan Esser discovered a problem in neon, an HTTP and WebDAV client
library.  User input is copied into variables not large enough for all
cases.  This can lead to an overflow of a static heap variable.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libneon-dev DPKG is earlier than 0.19.3-2woody5' test_ref='oval:org.debian.oval:tst:676'/>
            <criterion comment='libneon19 DPKG is earlier than 0.19.3-2woody5' test_ref='oval:org.debian.oval:tst:677'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:507' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>cadaver</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0398' ref_id='CVE-2004-0398'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-05-19</date>
          <moreinfo>
Stefan Esser discovered a problem in neon, an HTTP and WebDAV client
library, which is also present in cadaver, a command-line client for
WebDAV server.  User input is copied into variables not large enough
for all cases.  This can lead to an overflow of a static heap
variable.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='cadaver DPKG is earlier than 0.18.0-1woody3' test_ref='oval:org.debian.oval:tst:678'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:508' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>xpcd</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0402' ref_id='CVE-2004-0402'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-05-22</date>
          <moreinfo>
Jaguar discovered a vulnerability in one component of xpcd, a PhotoCD
viewer.  xpcd-svga, part of xpcd which uses svgalib to display
graphics on the console, would copy user-supplied data of arbitrary
length into a fixed-size buffer in the pcd_open function.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:118'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:119'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:120'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:122'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:112'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:128'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='xpcd-gimp DPKG is earlier than 2.08-8woody1' test_ref='oval:org.debian.oval:tst:679'/>
              <criterion comment='xpcd DPKG is earlier than 2.08-8woody1' test_ref='oval:org.debian.oval:tst:680'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:48'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:121'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:123'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='xpcd-gimp DPKG is earlier than 2.08-8woody2' test_ref='oval:org.debian.oval:tst:681'/>
              <criterion comment='xpcd DPKG is earlier than 2.08-8woody2' test_ref='oval:org.debian.oval:tst:682'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported platform section' operator='AND'>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='xpcd-svga DPKG is earlier than 2.08-8woody1' test_ref='oval:org.debian.oval:tst:683'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:509' class='vulnerability'>
      <metadata>
        <title>privilege escalation</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>gatos</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0395' ref_id='CVE-2004-0395'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-05-29</date>
          <moreinfo>
Steve Kemp discovered a vulnerability in xatitv, one of the programs
in the gatos package, which is used to display video with certain
ATI video cards.
xatitv is installed setuid root in order to gain direct access to the
video hardware.  It normally drops root privileges after successfully
initializing itself.  However, if initialization fails due to a
missing configuration file, root privileges are not dropped, and
xatitv executes the system(3) function to launch its configuration
program without sanitizing user-supplied environment variables.
By exploiting this vulnerability, a local user could gain root
privileges if the configuration file does not exist.  However, a
default configuration file is supplied with the package, and so this
vulnerability is not exploitable unless this file is removed by the
administrator.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='gatos DPKG is earlier than 0.0.5-6woody1' test_ref='oval:org.debian.oval:tst:684'/>
              <criterion comment='libgatos0 DPKG is earlier than 0.0.5-6woody1' test_ref='oval:org.debian.oval:tst:685'/>
              <criterion comment='libgatos-dev DPKG is earlier than 0.0.5-6woody1' test_ref='oval:org.debian.oval:tst:686'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:510' class='vulnerability'>
      <metadata>
        <title>format string</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>jftpgw</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0448' ref_id='CVE-2004-0448'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-05-29</date>
          <moreinfo>
jaguar@felinemenace.org discovered a vulnerability in jftpgw, an FTP
proxy program, whereby a remote user could potentially cause arbitrary
code to be executed with the privileges of the jftpgw server process.
By default, the server runs as user "nobody".
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0448">CAN-2004-0448&lt;/a>: format string vulnerability via syslog(3) in log()
function</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='jftpgw DPKG is earlier than 0.13.1-1woody1' test_ref='oval:org.debian.oval:tst:687'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:511' class='vulnerability'>
      <metadata>
        <title>buffer overflows</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>ethereal</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0176' ref_id='CVE-2004-0176'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-05-30</date>
          <moreinfo>
Several buffer overflow vulnerabilities were discovered in ethereal, a
network traffic analyzer.  These vulnerabilities are described in the
ethereal advisory "enpa-sa-00013".  Of these, only some parts of
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0176">CAN-2004-0176&lt;/a> affect the version of ethereal in Debian woody.
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0367">CAN-2004-0367&lt;/a> and &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0365">CAN-2004-0365&lt;/a> are not applicable to this version.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='ethereal-dev DPKG is earlier than 0.9.4-1woody7' test_ref='oval:org.debian.oval:tst:688'/>
            <criterion comment='ethereal-common DPKG is earlier than 0.9.4-1woody7' test_ref='oval:org.debian.oval:tst:689'/>
            <criterion comment='tethereal DPKG is earlier than 0.9.4-1woody7' test_ref='oval:org.debian.oval:tst:690'/>
            <criterion comment='ethereal DPKG is earlier than 0.9.4-1woody7' test_ref='oval:org.debian.oval:tst:691'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:512' class='vulnerability'>
      <metadata>
        <title>unauthenticated access</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>gallery</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0522' ref_id='CVE-2004-0522'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-06-02</date>
          <moreinfo>
A vulnerability was discovered in gallery, a web-based photo album
written in php, whereby a remote attacker could gain access to the
gallery "admin" user without proper authentication.  No CVE candidate
was available for this vulnerability at the time of release.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='gallery DPKG is earlier than 1.2.5-8woody2' test_ref='oval:org.debian.oval:tst:692'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:513' class='vulnerability'>
      <metadata>
        <title>format string</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>log2mail</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0450' ref_id='CVE-2004-0450'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-06-03</date>
          <moreinfo>
jaguar@felinemenace.org discovered a format string vulnerability in
log2mail, whereby a user able to log a specially crafted message to a
logfile monitored by log2mail (for example, via syslog) could cause
arbitrary code to be executed with the privileges of the log2mail
process.  By default, this process runs as user 'log2mail', which is a
member of group 'adm' (which has access to read system logfiles).
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0450">CAN-2004-0450&lt;/a>: log2mail format string vulnerability via syslog(3) in
printlog()</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='log2mail DPKG is earlier than 0.2.5.2' test_ref='oval:org.debian.oval:tst:693'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:514' class='vulnerability'>
      <metadata>
        <title>failing function and TLB flush</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>kernel-source-2.2.20, kernel-image-sparc-2.2</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0077' ref_id='CVE-2004-0077'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-06-04</date>
          <moreinfo>
Paul Starzetz and Wojciech Purczynski of isec.pl discovered a critical
security vulnerability in the memory management code of Linux inside
the mremap(2) system call.  Due to flushing the TLB (Translation
Lookaside Buffer, an address cache) too early it is possible for an
attacker to trigger a local root exploit.
The attack vectors for 2.4.x and 2.2.x kernels are exclusive for the
respective kernel series, though.  We formerly believed that the
exploitable vulnerability in 2.4.x does not exist in 2.2.x which is
still true.  However, it turned out that a second (sort of)
vulnerability is indeed exploitable in 2.2.x, but not in 2.4.x, with a
different exploit, of course.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-doc-2.2.20 DPKG is earlier than 2.2.20-5woody3' test_ref='oval:org.debian.oval:tst:694'/>
              <criterion comment='kernel-source-2.2.20 DPKG is earlier than 2.2.20-5woody3' test_ref='oval:org.debian.oval:tst:695'/>
              <criterion comment='kernel-headers-2.2.20-sparc DPKG is earlier than 9woody1' test_ref='oval:org.debian.oval:tst:696'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:119'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-image-2.2.20-sun4dm-smp DPKG is earlier than 9woody1' test_ref='oval:org.debian.oval:tst:697'/>
              <criterion comment='kernel-image-2.2.20-sun4u DPKG is earlier than 9woody1' test_ref='oval:org.debian.oval:tst:698'/>
              <criterion comment='kernel-image-2.2.20-sun4u-smp DPKG is earlier than 9woody1' test_ref='oval:org.debian.oval:tst:699'/>
              <criterion comment='kernel-image-2.2.20-sun4cdm DPKG is earlier than 9woody1' test_ref='oval:org.debian.oval:tst:700'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:515' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>lha</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0234' ref_id='CVE-2004-0234'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0235' ref_id='CVE-2004-0235'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-06-05</date>
          <moreinfo>
Two vulnerabilities were discovered in lha:</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:118'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:119'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:120'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:112'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:48'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:123'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='lha DPKG is earlier than 1.14i-2woody1' test_ref='oval:org.debian.oval:tst:701'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:516' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>postgresql</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0547' ref_id='CVE-2004-0547'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-06-07</date>
          <moreinfo>
A buffer overflow has been discovered in the ODBC driver of PostgreSQL,
an object-relational SQL database, descended from POSTGRES.  It is possible
to exploit this problem and crash the surrounding application.  Hence, a
PHP script using php4-odbc can be utilised to crash the surrounding
Apache webserver.  Other parts of postgresql are not affected.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='postgresql-doc DPKG is earlier than 7.2.1-2woody5' test_ref='oval:org.debian.oval:tst:702'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libpgsql2 DPKG is earlier than 7.2.1-2woody5' test_ref='oval:org.debian.oval:tst:703'/>
            <criterion comment='libpgtcl DPKG is earlier than 7.2.1-2woody5' test_ref='oval:org.debian.oval:tst:704'/>
            <criterion comment='postgresql DPKG is earlier than 7.2.1-2woody5' test_ref='oval:org.debian.oval:tst:705'/>
            <criterion comment='pgaccess DPKG is earlier than 7.2.1-2woody5' test_ref='oval:org.debian.oval:tst:706'/>
            <criterion comment='libpgperl DPKG is earlier than 7.2.1-2woody5' test_ref='oval:org.debian.oval:tst:707'/>
            <criterion comment='postgresql-contrib DPKG is earlier than 7.2.1-2woody5' test_ref='oval:org.debian.oval:tst:708'/>
            <criterion comment='odbc-postgresql DPKG is earlier than 7.2.1-2woody5' test_ref='oval:org.debian.oval:tst:709'/>
            <criterion comment='libecpg3 DPKG is earlier than 7.2.1-2woody5' test_ref='oval:org.debian.oval:tst:710'/>
            <criterion comment='python-pygresql DPKG is earlier than 7.2.1-2woody5' test_ref='oval:org.debian.oval:tst:711'/>
            <criterion comment='postgresql-dev DPKG is earlier than 7.2.1-2woody5' test_ref='oval:org.debian.oval:tst:712'/>
            <criterion comment='postgresql-client DPKG is earlier than 7.2.1-2woody5' test_ref='oval:org.debian.oval:tst:713'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:517' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>cvs</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0414' ref_id='CVE-2004-0414'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-06-10</date>
          <moreinfo>
Derek Robert Price discovered a potential buffer overflow
vulnerability in the CVS server, based on a malformed Entry, which
serves the popular Concurrent Versions System.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='cvs DPKG is earlier than 1.11.1p1debian-9woody6' test_ref='oval:org.debian.oval:tst:714'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:518' class='vulnerability'>
      <metadata>
        <title>unsanitised input</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>kdelibs</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0411' ref_id='CVE-2004-0411'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-06-14</date>
          <moreinfo>
iDEFENSE identified a vulnerability in the Opera web browser that
could be used by remote attackers to create or truncate arbitrary
files on the victims machine.  The KDE team discovered that a similar
&lt;a href="http://www.kde.org/info/security/advisory-20040517-1.txt">\
vulnerability&lt;/a> exists in KDE.
A remote attacker could entice a user to open a carefully crafted
telnet URI which may either create or truncate a file in the victims
home directory.  In KDE 3.2 and later versions the user is first
explicitly asked to confirm the opening of the telnet URI.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='kdelibs3-doc DPKG is earlier than 2.2.2-13.woody.10' test_ref='oval:org.debian.oval:tst:715'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libarts DPKG is earlier than 2.2.2-13.woody.10' test_ref='oval:org.debian.oval:tst:716'/>
            <criterion comment='libkmid-alsa DPKG is earlier than 2.2.2-13.woody.10' test_ref='oval:org.debian.oval:tst:717'/>
            <criterion comment='kdelibs3-bin DPKG is earlier than 2.2.2-13.woody.10' test_ref='oval:org.debian.oval:tst:718'/>
            <criterion comment='libarts-alsa DPKG is earlier than 2.2.2-13.woody.10' test_ref='oval:org.debian.oval:tst:719'/>
            <criterion comment='kdelibs3 DPKG is earlier than 2.2.2-13.woody.10' test_ref='oval:org.debian.oval:tst:720'/>
            <criterion comment='kdelibs3-cups DPKG is earlier than 2.2.2-13.woody.10' test_ref='oval:org.debian.oval:tst:721'/>
            <criterion comment='libkmid-dev DPKG is earlier than 2.2.2-13.woody.10' test_ref='oval:org.debian.oval:tst:722'/>
            <criterion comment='libkmid DPKG is earlier than 2.2.2-13.woody.10' test_ref='oval:org.debian.oval:tst:723'/>
            <criterion comment='libarts-dev DPKG is earlier than 2.2.2-13.woody.10' test_ref='oval:org.debian.oval:tst:724'/>
            <criterion comment='kdelibs-dev DPKG is earlier than 2.2.2-13.woody.10' test_ref='oval:org.debian.oval:tst:725'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:519' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>cvs</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0416' ref_id='CVE-2004-0416'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0417' ref_id='CVE-2004-0417'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0418' ref_id='CVE-2004-0418'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0778' ref_id='CVE-2004-0778'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-06-15</date>
          <moreinfo>
Sebastian Krahmer and Stefan Esser discovered several vulnerabilities
in the CVS server, which serves the popular Concurrent Versions
System.  The Common Vulnerabilities and Exposures project identifies the
following problems:</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='cvs DPKG is earlier than 1.11.1p1debian-9woody7' test_ref='oval:org.debian.oval:tst:726'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:520' class='vulnerability'>
      <metadata>
        <title>buffer overflows</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>krb5</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0523' ref_id='CVE-2004-0523'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-06-16</date>
          <moreinfo>
In their advisory MITKRB5-SA-2004-001, the MIT Kerberos announced the
existence of buffer overflow vulnerabilities in the
krb5_aname_to_localname function.  This function is only used if
aname_to_localname is enabled in the configuration (this is not
enabled by default).</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='krb5-doc DPKG is earlier than 1.2.4-5woody5' test_ref='oval:org.debian.oval:tst:727'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='krb5-rsh-server DPKG is earlier than 1.2.4-5woody5' test_ref='oval:org.debian.oval:tst:728'/>
            <criterion comment='krb5-telnetd DPKG is earlier than 1.2.4-5woody5' test_ref='oval:org.debian.oval:tst:729'/>
            <criterion comment='libkrb53 DPKG is earlier than 1.2.4-5woody5' test_ref='oval:org.debian.oval:tst:730'/>
            <criterion comment='libkrb5-dev DPKG is earlier than 1.2.4-5woody5' test_ref='oval:org.debian.oval:tst:731'/>
            <criterion comment='krb5-ftpd DPKG is earlier than 1.2.4-5woody5' test_ref='oval:org.debian.oval:tst:732'/>
            <criterion comment='krb5-admin-server DPKG is earlier than 1.2.4-5woody5' test_ref='oval:org.debian.oval:tst:733'/>
            <criterion comment='libkadm55 DPKG is earlier than 1.2.4-5woody5' test_ref='oval:org.debian.oval:tst:734'/>
            <criterion comment='krb5-user DPKG is earlier than 1.2.4-5woody5' test_ref='oval:org.debian.oval:tst:735'/>
            <criterion comment='krb5-clients DPKG is earlier than 1.2.4-5woody5' test_ref='oval:org.debian.oval:tst:736'/>
            <criterion comment='krb5-kdc DPKG is earlier than 1.2.4-5woody5' test_ref='oval:org.debian.oval:tst:737'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:521' class='vulnerability'>
      <metadata>
        <title>format string vulnerability</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>sup</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0451' ref_id='CVE-2004-0451'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-06-18</date>
          <moreinfo>
&lt;email jaguar@felinemenace.org> discovered a format string vulnerability in
sup, a set of programs to synchronize collections of files across a
number of machines, whereby a remote attacker could potentially cause
arbitrary code to be executed with the privileges of the supfilesrv
process (this process does not run automatically by default).
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0451">\
CAN-2004-0451&lt;/a>: format string vulnerabilities in sup via syslog(3) in
logquit, logerr, loginfo functions</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='sup DPKG is earlier than 1.8-8woody2' test_ref='oval:org.debian.oval:tst:738'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:522' class='vulnerability'>
      <metadata>
        <title>format string vulnerability</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>super</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0579' ref_id='CVE-2004-0579'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-06-19</date>
          <moreinfo>
Max Vozeler discovered a format string vulnerability in super, a
program to allow specified users to execute commands with root
privileges.  This vulnerability could potentially be exploited by a
local user to execute arbitrary code with root privileges.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='super DPKG is earlier than 3.16.1-1.2' test_ref='oval:org.debian.oval:tst:739'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:523' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>www-sql</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0455' ref_id='CVE-2004-0455'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-06-19</date>
          <moreinfo>
Ulf Härnhammar discovered a buffer overflow vulnerability in www-sql,
a CGI program which enables the creation of dynamic web pages by
embedding SQL statements in HTML.  By exploiting this
vulnerability, a local user could cause the execution of arbitrary
code by creating a web page and processing it with www-sql.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='www-mysql DPKG is earlier than 0.5.7-17woody1' test_ref='oval:org.debian.oval:tst:740'/>
            <criterion comment='www-pgsql DPKG is earlier than 0.5.7-17woody1' test_ref='oval:org.debian.oval:tst:741'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:524' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>rlpr</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0393' ref_id='CVE-2004-0393'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0454' ref_id='CVE-2004-0454'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-06-19</date>
          <moreinfo>
&lt;email jaguar@felinemenace.org> discovered a format string vulnerability in
rlpr, a utility for lpd printing without using /etc/printcap.  While
investigating this vulnerability, a buffer overflow was also
discovered in related code.  By exploiting one of these
vulnerabilities, a local or remote user could potentially cause
arbitrary code to be executed with the privileges of 1) the rlprd
process (remote), or 2) root (local).
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0393">\
CAN-2004-0393&lt;/a>: format string vulnerability via syslog(3) in msg()
function in rlpr
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0454">\
CAN-2004-0454&lt;/a>: buffer overflow in msg() function in rlpr</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='rlpr DPKG is earlier than 2.02-7woody1' test_ref='oval:org.debian.oval:tst:742'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:525' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>apache</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0492' ref_id='CVE-2004-0492'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-06-24</date>
          <moreinfo>
Georgi Guninski discovered a buffer overflow bug in Apache's mod_proxy
module, whereby a remote user could potentially cause arbitrary code
to be executed with the privileges of an Apache httpd child process
(by default, user www-data).  Note that this bug is only exploitable
if the mod_proxy module is in use.
Note that this bug exists in a module in the apache-common package,
shared by apache, apache-ssl and apache-perl, so this update is
sufficient to correct the bug for all three builds of Apache httpd.
However, on systems using apache-ssl or apache-perl, httpd will not
automatically be restarted.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='apache-doc DPKG is earlier than 1.3.26-0woody5' test_ref='oval:org.debian.oval:tst:743'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='apache DPKG is earlier than 1.3.26-0woody5' test_ref='oval:org.debian.oval:tst:744'/>
            <criterion comment='apache-common DPKG is earlier than 1.3.26-0woody5' test_ref='oval:org.debian.oval:tst:745'/>
            <criterion comment='apache-dev DPKG is earlier than 1.3.26-0woody5' test_ref='oval:org.debian.oval:tst:746'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:526' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>webmin</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0582' ref_id='CVE-2004-0582'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0583' ref_id='CVE-2004-0583'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-07-03</date>
          <moreinfo>
Two vulnerabilities were discovered in webmin:
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0582">CAN-2004-0582&lt;/a>: Unknown vulnerability in Webmin 1.140 allows remote
 attackers to bypass access control rules and gain read access to
 configuration information for a module.
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0583">CAN-2004-0583&lt;/a>: The account lockout functionality in (1) Webmin 1.140
 and (2) Usermin 1.070 does not parse certain character strings, which
 allows remote attackers to conduct a brute force attack to guess user
 IDs and passwords.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='webmin-ssl DPKG is earlier than 0.94-7woody2' test_ref='oval:org.debian.oval:tst:747'/>
              <criterion comment='webmin-status DPKG is earlier than 0.94-7woody2' test_ref='oval:org.debian.oval:tst:748'/>
              <criterion comment='webmin-sshd DPKG is earlier than 0.94-7woody2' test_ref='oval:org.debian.oval:tst:749'/>
              <criterion comment='webmin-mysql DPKG is earlier than 0.94-7woody2' test_ref='oval:org.debian.oval:tst:750'/>
              <criterion comment='webmin-samba DPKG is earlier than 0.94-7woody2' test_ref='oval:org.debian.oval:tst:751'/>
              <criterion comment='webmin-burner DPKG is earlier than 0.94-7woody2' test_ref='oval:org.debian.oval:tst:752'/>
              <criterion comment='webmin-exports DPKG is earlier than 0.94-7woody2' test_ref='oval:org.debian.oval:tst:753'/>
              <criterion comment='webmin-cluster-software DPKG is earlier than 0.94-7woody2' test_ref='oval:org.debian.oval:tst:754'/>
              <criterion comment='webmin-core DPKG is earlier than 0.94-7woody2' test_ref='oval:org.debian.oval:tst:755'/>
              <criterion comment='webmin-fetchmail DPKG is earlier than 0.94-7woody2' test_ref='oval:org.debian.oval:tst:756'/>
              <criterion comment='webmin-quota DPKG is earlier than 0.94-7woody2' test_ref='oval:org.debian.oval:tst:757'/>
              <criterion comment='webmin-inetd DPKG is earlier than 0.94-7woody2' test_ref='oval:org.debian.oval:tst:758'/>
              <criterion comment='webmin-postfix DPKG is earlier than 0.94-7woody2' test_ref='oval:org.debian.oval:tst:759'/>
              <criterion comment='webmin-cpan DPKG is earlier than 0.94-7woody2' test_ref='oval:org.debian.oval:tst:760'/>
              <criterion comment='webmin-mon DPKG is earlier than 0.94-7woody2' test_ref='oval:org.debian.oval:tst:761'/>
              <criterion comment='webmin-xinetd DPKG is earlier than 0.94-7woody2' test_ref='oval:org.debian.oval:tst:762'/>
              <criterion comment='webmin-bind8 DPKG is earlier than 0.94-7woody2' test_ref='oval:org.debian.oval:tst:763'/>
              <criterion comment='webmin-sendmail DPKG is earlier than 0.94-7woody2' test_ref='oval:org.debian.oval:tst:764'/>
              <criterion comment='webmin-dhcpd DPKG is earlier than 0.94-7woody2' test_ref='oval:org.debian.oval:tst:765'/>
              <criterion comment='webmin-apache DPKG is earlier than 0.94-7woody2' test_ref='oval:org.debian.oval:tst:766'/>
              <criterion comment='webmin-heartbeat DPKG is earlier than 0.94-7woody2' test_ref='oval:org.debian.oval:tst:767'/>
              <criterion comment='webmin-lpadmin DPKG is earlier than 0.94-7woody2' test_ref='oval:org.debian.oval:tst:768'/>
              <criterion comment='webmin-squid DPKG is earlier than 0.94-7woody2' test_ref='oval:org.debian.oval:tst:769'/>
              <criterion comment='webmin-postgresql DPKG is earlier than 0.94-7woody2' test_ref='oval:org.debian.oval:tst:770'/>
              <criterion comment='webmin-wuftpd DPKG is earlier than 0.94-7woody2' test_ref='oval:org.debian.oval:tst:771'/>
              <criterion comment='webmin-stunnel DPKG is earlier than 0.94-7woody2' test_ref='oval:org.debian.oval:tst:772'/>
              <criterion comment='webmin-cluster-useradmin DPKG is earlier than 0.94-7woody2' test_ref='oval:org.debian.oval:tst:773'/>
              <criterion comment='webmin-ppp DPKG is earlier than 0.94-7woody2' test_ref='oval:org.debian.oval:tst:774'/>
              <criterion comment='webmin-raid DPKG is earlier than 0.94-7woody2' test_ref='oval:org.debian.oval:tst:775'/>
              <criterion comment='webmin-nis DPKG is earlier than 0.94-7woody2' test_ref='oval:org.debian.oval:tst:776'/>
              <criterion comment='webmin-software DPKG is earlier than 0.94-7woody2' test_ref='oval:org.debian.oval:tst:777'/>
              <criterion comment='webmin-qmailadmin DPKG is earlier than 0.94-7woody2' test_ref='oval:org.debian.oval:tst:778'/>
              <criterion comment='webmin DPKG is earlier than 0.94-7woody2' test_ref='oval:org.debian.oval:tst:779'/>
              <criterion comment='webmin-jabber DPKG is earlier than 0.94-7woody2' test_ref='oval:org.debian.oval:tst:780'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='webmin-grub DPKG is earlier than 0.94-7woody2' test_ref='oval:org.debian.oval:tst:781'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:527' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>pavuk</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0456' ref_id='CVE-2004-0456'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-07-03</date>
          <moreinfo>
Ulf Härnhammar discovered a vulnerability in pavuk, a file retrieval
program, whereby an oversized HTTP 305 response sent by a malicious
server could cause arbitrary code to be executed with the privileges
of the pavuk process.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='pavuk DPKG is earlier than 0.9pl28-1woody1' test_ref='oval:org.debian.oval:tst:782'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:528' class='vulnerability'>
      <metadata>
        <title>denial of service</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>ethereal</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0635' ref_id='CVE-2004-0635'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-07-17</date>
          <moreinfo>
Several denial of service vulnerabilities were discovered in ethereal,
a network traffic analyzer.  These vulnerabilities are described in the
ethereal advisory "enpa-sa-00015".  Of these, only one (&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0635">CAN-2004-0635&lt;/a>)
affects the version of ethereal in Debian woody.  This vulnerability
could be exploited by a remote attacker to crash ethereal with an
invalid SNMP packet.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:118'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:119'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:120'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:121'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:122'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:112'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:128'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:123'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='ethereal-dev DPKG is earlier than 0.9.4-1woody8' test_ref='oval:org.debian.oval:tst:783'/>
              <criterion comment='ethereal-common DPKG is earlier than 0.9.4-1woody8' test_ref='oval:org.debian.oval:tst:784'/>
              <criterion comment='tethereal DPKG is earlier than 0.9.4-1woody8' test_ref='oval:org.debian.oval:tst:785'/>
              <criterion comment='ethereal DPKG is earlier than 0.9.4-1woody8' test_ref='oval:org.debian.oval:tst:786'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:48'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='ethereal-dev DPKG is earlier than 0.9.4-1woody7' test_ref='oval:org.debian.oval:tst:787'/>
              <criterion comment='ethereal-common DPKG is earlier than 0.9.4-1woody7' test_ref='oval:org.debian.oval:tst:788'/>
              <criterion comment='tethereal DPKG is earlier than 0.9.4-1woody7' test_ref='oval:org.debian.oval:tst:789'/>
              <criterion comment='ethereal DPKG is earlier than 0.9.4-1woody7' test_ref='oval:org.debian.oval:tst:790'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:529' class='vulnerability'>
      <metadata>
        <title>format string</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>netkit-telnet-ssl</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0640' ref_id='CVE-2004-0640'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-07-17</date>
          <moreinfo>
"b0f" discovered a format string vulnerability in netkit-telnet-ssl
which could potentially allow a remote attacker to cause the execution
of arbitrary code with the privileges of the telnet daemon (the
'telnetd' user by default).</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:118'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:119'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:120'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:121'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:112'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:122'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:128'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:123'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='telnet-ssl DPKG is earlier than 0.17.17+0.1-2woody1' test_ref='oval:org.debian.oval:tst:791'/>
              <criterion comment='telnetd-ssl DPKG is earlier than 0.17.17+0.1-2woody1' test_ref='oval:org.debian.oval:tst:792'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:530' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>l2tpd</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0649' ref_id='CVE-2004-0649'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-07-17</date>
          <moreinfo>
Thomas Walpuski reported a buffer overflow in l2tpd, an implementation
of the layer 2 tunneling protocol, whereby a remote attacker could
potentially cause arbitrary code to be executed by transmitting a
specially crafted packet.  The exploitability of this vulnerability
has not been verified.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:118'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:119'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:120'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:121'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:122'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:112'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:128'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:123'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='l2tpd DPKG is earlier than 0.67-1.2' test_ref='oval:org.debian.oval:tst:793'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:48'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='l2tpd DPKG is earlier than 0.67-1.1' test_ref='oval:org.debian.oval:tst:794'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:531' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>php4</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0594' ref_id='CVE-2004-0594'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0595' ref_id='CVE-2004-0595'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-07-20</date>
          <moreinfo>
Two vulnerabilities were discovered in php4:
The memory_limit functionality in PHP 4.x up to
   4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as
   when register_globals is enabled, allows remote attackers to
   execute arbitrary code by triggering a memory_limit abort during
   execution of the zend_hash_init function and overwriting a
   HashTable destructor pointer before the initialization of key data
   structures is complete.
The strip_tags function in PHP 4.x up to 4.3.7, and
   5.x up to 5.0.0RC3, does not filter null (\0) characters within tag
   names when restricting input to allowed tags, which allows
   dangerous tags to be processed by web browsers such as Internet
   Explorer and Safari, which ignore null characters and facilitate
   the exploitation of cross-site scripting (XSS) vulnerabilities.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='php4-pear DPKG is earlier than 4.1.2-7' test_ref='oval:org.debian.oval:tst:795'/>
              <criterion comment='php4-dev DPKG is earlier than 4.1.2-7' test_ref='oval:org.debian.oval:tst:796'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:118'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:119'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:120'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:123'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:122'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:112'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:48'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:128'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:121'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='php4-mcal DPKG is earlier than 4.1.2-7' test_ref='oval:org.debian.oval:tst:797'/>
              <criterion comment='php4-sybase DPKG is earlier than 4.1.2-7' test_ref='oval:org.debian.oval:tst:798'/>
              <criterion comment='caudium-php4 DPKG is earlier than 4.1.2-7' test_ref='oval:org.debian.oval:tst:799'/>
              <criterion comment='php4-odbc DPKG is earlier than 4.1.2-7' test_ref='oval:org.debian.oval:tst:800'/>
              <criterion comment='php4-recode DPKG is earlier than 4.1.2-7' test_ref='oval:org.debian.oval:tst:801'/>
              <criterion comment='php4-gd DPKG is earlier than 4.1.2-7' test_ref='oval:org.debian.oval:tst:802'/>
              <criterion comment='php4-xslt DPKG is earlier than 4.1.2-7' test_ref='oval:org.debian.oval:tst:803'/>
              <criterion comment='php4-ldap DPKG is earlier than 4.1.2-7' test_ref='oval:org.debian.oval:tst:804'/>
              <criterion comment='php4 DPKG is earlier than 4.1.2-7' test_ref='oval:org.debian.oval:tst:805'/>
              <criterion comment='php4-mysql DPKG is earlier than 4.1.2-7' test_ref='oval:org.debian.oval:tst:806'/>
              <criterion comment='php4-domxml DPKG is earlier than 4.1.2-7' test_ref='oval:org.debian.oval:tst:807'/>
              <criterion comment='php4-imap DPKG is earlier than 4.1.2-7' test_ref='oval:org.debian.oval:tst:808'/>
              <criterion comment='php4-mhash DPKG is earlier than 4.1.2-7' test_ref='oval:org.debian.oval:tst:809'/>
              <criterion comment='php4-snmp DPKG is earlier than 4.1.2-7' test_ref='oval:org.debian.oval:tst:810'/>
              <criterion comment='php4-curl DPKG is earlier than 4.1.2-7' test_ref='oval:org.debian.oval:tst:811'/>
              <criterion comment='php4-cgi DPKG is earlier than 4.1.2-7' test_ref='oval:org.debian.oval:tst:812'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='php4-sybase DPKG is earlier than 4.1.2-7.0.1' test_ref='oval:org.debian.oval:tst:813'/>
              <criterion comment='php4-xslt DPKG is earlier than 4.1.2-7.0.1' test_ref='oval:org.debian.oval:tst:814'/>
              <criterion comment='php4-odbc DPKG is earlier than 4.1.2-7.0.1' test_ref='oval:org.debian.oval:tst:815'/>
              <criterion comment='php4-recode DPKG is earlier than 4.1.2-7.0.1' test_ref='oval:org.debian.oval:tst:816'/>
              <criterion comment='php4-gd DPKG is earlier than 4.1.2-7.0.1' test_ref='oval:org.debian.oval:tst:817'/>
              <criterion comment='caudium-php4 DPKG is earlier than 4.1.2-7.0.1' test_ref='oval:org.debian.oval:tst:818'/>
              <criterion comment='php4-mhash DPKG is earlier than 4.1.2-7.0.1' test_ref='oval:org.debian.oval:tst:819'/>
              <criterion comment='php4-ldap DPKG is earlier than 4.1.2-7.0.1' test_ref='oval:org.debian.oval:tst:820'/>
              <criterion comment='php4-snmp DPKG is earlier than 4.1.2-7.0.1' test_ref='oval:org.debian.oval:tst:821'/>
              <criterion comment='php4-mysql DPKG is earlier than 4.1.2-7.0.1' test_ref='oval:org.debian.oval:tst:822'/>
              <criterion comment='php4-mcal DPKG is earlier than 4.1.2-7.0.1' test_ref='oval:org.debian.oval:tst:823'/>
              <criterion comment='php4-domxml DPKG is earlier than 4.1.2-7.0.1' test_ref='oval:org.debian.oval:tst:824'/>
              <criterion comment='php4 DPKG is earlier than 4.1.2-7.0.1' test_ref='oval:org.debian.oval:tst:825'/>
              <criterion comment='php4-imap DPKG is earlier than 4.1.2-7.0.1' test_ref='oval:org.debian.oval:tst:826'/>
              <criterion comment='php4-curl DPKG is earlier than 4.1.2-7.0.1' test_ref='oval:org.debian.oval:tst:827'/>
              <criterion comment='php4-cgi DPKG is earlier than 4.1.2-7.0.1' test_ref='oval:org.debian.oval:tst:828'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:532' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>libapache-mod-ssl</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0488' ref_id='CVE-2004-0488'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0700' ref_id='CVE-2004-0700'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-07-27</date>
          <moreinfo>
Two vulnerabilities were discovered in libapache-mod-ssl:
Stack-based buffer overflow in the
  ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl,
  when mod_ssl is configured to trust the issuing CA, may allow remote
  attackers to execute arbitrary code via a client certificate with a
  long subject DN.
Format string vulnerability in the ssl_log function
  in ssl_engine_log.c in mod_ssl 2.8.19 for Apache 1.3.31 may allow
  remote attackers to execute arbitrary messages via format string
  specifiers in certain log messages for HTTPS.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='libapache-mod-ssl-doc DPKG is earlier than 2.8.9-2.4' test_ref='oval:org.debian.oval:tst:829'/>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:118'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:119'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:120'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:123'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:112'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:122'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:128'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:121'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libapache-mod-ssl DPKG is earlier than 2.8.9-2.4' test_ref='oval:org.debian.oval:tst:830'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:533' class='vulnerability'>
      <metadata>
        <title>cross-site scripting</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>courier</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0591' ref_id='CVE-2004-0591'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-07-22</date>
          <moreinfo>
A cross-site scripting vulnerability was discovered in sqwebmail, a
web mail application provided by the courier mail suite, whereby an
attacker could cause web script to be executed within the security
context of the sqwebmail application by injecting it via an email
message.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='courier-doc DPKG is earlier than 0.37.3-2.5' test_ref='oval:org.debian.oval:tst:831'/>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:118'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:119'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:120'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:123'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:112'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:122'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:128'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:121'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='courier-maildrop DPKG is earlier than 0.37.3-2.5' test_ref='oval:org.debian.oval:tst:832'/>
              <criterion comment='courier-base DPKG is earlier than 0.37.3-2.5' test_ref='oval:org.debian.oval:tst:833'/>
              <criterion comment='courier-debug DPKG is earlier than 0.37.3-2.5' test_ref='oval:org.debian.oval:tst:834'/>
              <criterion comment='courier-authdaemon DPKG is earlier than 0.37.3-2.5' test_ref='oval:org.debian.oval:tst:835'/>
              <criterion comment='courier-webadmin DPKG is earlier than 0.37.3-2.5' test_ref='oval:org.debian.oval:tst:836'/>
              <criterion comment='courier-mta DPKG is earlier than 0.37.3-2.5' test_ref='oval:org.debian.oval:tst:837'/>
              <criterion comment='courier-mlm DPKG is earlier than 0.37.3-2.5' test_ref='oval:org.debian.oval:tst:838'/>
              <criterion comment='courier-authmysql DPKG is earlier than 0.37.3-2.5' test_ref='oval:org.debian.oval:tst:839'/>
              <criterion comment='courier-ldap DPKG is earlier than 0.37.3-2.5' test_ref='oval:org.debian.oval:tst:840'/>
              <criterion comment='sqwebmail DPKG is earlier than 0.37.3-2.5' test_ref='oval:org.debian.oval:tst:841'/>
              <criterion comment='courier-pop DPKG is earlier than 0.37.3-2.5' test_ref='oval:org.debian.oval:tst:842'/>
              <criterion comment='courier-imap DPKG is earlier than 1.4.3-2.5' test_ref='oval:org.debian.oval:tst:843'/>
              <criterion comment='courier-pcp DPKG is earlier than 0.37.3-2.5' test_ref='oval:org.debian.oval:tst:844'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:534' class='vulnerability'>
      <metadata>
        <title>directory traversal</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>mailreader</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1581' ref_id='CVE-2002-1581'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-07-22</date>
          <moreinfo>
A directory traversal vulnerability was discovered in mailreader
whereby remote attackers could view arbitrary files with the
privileges of the nph-mr.cgi process (by default, www-data) via
relative paths and a null byte in the configLanguage parameter.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='mailreader DPKG is earlier than 2.3.29-5woody1' test_ref='oval:org.debian.oval:tst:845'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:535' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>squirrelmail</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0519' ref_id='CVE-2004-0519'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0520' ref_id='CVE-2004-0520'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0521' ref_id='CVE-2004-0521'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0639' ref_id='CVE-2004-0639'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-08-02</date>
          <moreinfo>
Four vulnerabilities were discovered in squirrelmail:
Multiple cross-site scripting (XSS) vulnerabilities
 in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary
 script as other users and possibly steal authentication information
 via multiple attack vectors, including the mailbox parameter in
 compose.php.
Cross-site scripting (XSS) vulnerability in mime.php
 for SquirrelMail before 1.4.3 allows remote attackers to insert
 arbitrary HTML and script via the content-type mail header, as
 demonstrated using read_body.php.
SQL injection vulnerability in SquirrelMail before
 1.4.3 RC1 allows remote attackers to execute unauthorized SQL
 statements, with unknown impact, probably via abook_database.php.
Multiple cross-site scripting (XSS) vulnerabilities
 in Squirrelmail 1.2.10 and earlier allow remote attackers to inject
 arbitrary HTML or script via (1) the $mailer variable in
 read_body.php, (2) the $senderNames_part variable in
 mailbox_display.php, and possibly other vectors including (3) the
 $event_title variable or (4) the $event_text variable.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='squirrelmail DPKG is earlier than 1.2.6-1.4' test_ref='oval:org.debian.oval:tst:846'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:536' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>libpng</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0597' ref_id='CVE-2004-0597'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0598' ref_id='CVE-2004-0598'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0599' ref_id='CVE-2004-0599'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0768' ref_id='CVE-2004-0768'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-08-04</date>
          <moreinfo>
Chris Evans discovered several vulnerabilities in libpng:
Multiple buffer overflows exist, including when
 handling transparency chunk data, which could be exploited to cause
 arbitrary code to be executed when a specially crafted PNG image is
 processed
Multiple NULL pointer dereferences in
 png_handle_iCPP() and elsewhere could be exploited to cause an
 application to crash when a specially crafted PNG image is processed
Multiple integer overflows in the png_handle_sPLT(),
 png_read_png() functions and elsewhere could be exploited to cause an
 application to crash, or potentially arbitrary code to be executed,
 when a specially crafted PNG image is processed
In addition, a bug related to &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-1363">CAN-2002-1363&lt;/a> was fixed:
A buffer overflow could be caused by incorrect
 calculation of buffer offsets, possibly leading to the execution of
 arbitrary code</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:118'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:119'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:120'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:121'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:112'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:122'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:128'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:123'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libpng2-dev DPKG is earlier than 1.0.12-3.woody.7' test_ref='oval:org.debian.oval:tst:847'/>
              <criterion comment='libpng-dev DPKG is earlier than 1.2.1-1.1.woody.7' test_ref='oval:org.debian.oval:tst:848'/>
              <criterion comment='libpng3 DPKG is earlier than 1.2.1-1.1.woody.7' test_ref='oval:org.debian.oval:tst:849'/>
              <criterion comment='libpng2 DPKG is earlier than 1.0.12-3.woody.7' test_ref='oval:org.debian.oval:tst:850'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:537' class='vulnerability'>
      <metadata>
        <title>insecure file permissions</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>ruby</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0755' ref_id='CVE-2004-0755'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-08-16</date>
          <moreinfo>
Andres Salomon noticed a problem in the CGI session management of
Ruby, an object-oriented scripting language.  CGI::Session's FileStore
(and presumably PStore, but not in Debian woody) implementations store
session information insecurely.  They simply create files, ignoring
permission issues.  This can lead an attacker who has also shell
access to the webserver to take over a session.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='ruby-elisp DPKG is earlier than 1.6.7-3woody3' test_ref='oval:org.debian.oval:tst:851'/>
              <criterion comment='ruby-examples DPKG is earlier than 1.6.7-3woody3' test_ref='oval:org.debian.oval:tst:852'/>
              <criterion comment='irb DPKG is earlier than 1.6.7-3woody3' test_ref='oval:org.debian.oval:tst:853'/>
            </criteria>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libpty-ruby DPKG is earlier than 1.6.7-3woody3' test_ref='oval:org.debian.oval:tst:854'/>
            <criterion comment='libdbm-ruby DPKG is earlier than 1.6.7-3woody3' test_ref='oval:org.debian.oval:tst:855'/>
            <criterion comment='libreadline-ruby DPKG is earlier than 1.6.7-3woody3' test_ref='oval:org.debian.oval:tst:856'/>
            <criterion comment='ruby-dev DPKG is earlier than 1.6.7-3woody3' test_ref='oval:org.debian.oval:tst:857'/>
            <criterion comment='libcurses-ruby DPKG is earlier than 1.6.7-3woody3' test_ref='oval:org.debian.oval:tst:858'/>
            <criterion comment='libsdbm-ruby DPKG is earlier than 1.6.7-3woody3' test_ref='oval:org.debian.oval:tst:859'/>
            <criterion comment='libruby DPKG is earlier than 1.6.7-3woody3' test_ref='oval:org.debian.oval:tst:860'/>
            <criterion comment='libgdbm-ruby DPKG is earlier than 1.6.7-3woody3' test_ref='oval:org.debian.oval:tst:861'/>
            <criterion comment='libtk-ruby DPKG is earlier than 1.6.7-3woody3' test_ref='oval:org.debian.oval:tst:862'/>
            <criterion comment='libnkf-ruby DPKG is earlier than 1.6.7-3woody3' test_ref='oval:org.debian.oval:tst:863'/>
            <criterion comment='ruby DPKG is earlier than 1.6.7-3woody3' test_ref='oval:org.debian.oval:tst:864'/>
            <criterion comment='libsyslog-ruby DPKG is earlier than 1.6.7-3woody3' test_ref='oval:org.debian.oval:tst:865'/>
            <criterion comment='libtcltk-ruby DPKG is earlier than 1.6.7-3woody3' test_ref='oval:org.debian.oval:tst:866'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:538' class='vulnerability'>
      <metadata>
        <title>unsanitised input processing</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>rsync</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0792' ref_id='CVE-2004-0792'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-08-17</date>
          <moreinfo>
The rsync developers have discovered a security related problem in
rsync, a fast remote file copy program, which offers an attacker to
access files outside of the defined directory.  To exploit this
path-sanitizing bug, rsync has to run in daemon mode with the chroot
option being disabled.  It does not affect the normal send/receive
filenames that specify what files should be transferred.  It does
affect certain option paths that cause auxiliary files to be read or
written.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='rsync DPKG is earlier than 2.5.5-0.6' test_ref='oval:org.debian.oval:tst:867'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:539' class='vulnerability'>
      <metadata>
        <title>temporary directory vulnerability</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>kdelibs</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0689' ref_id='CVE-2004-0689'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-08-17</date>
          <moreinfo>
The SUSE security team was alerted that in some cases the integrity of
symlinks used by KDE are not ensured and that these symlinks can be
pointing to stale locations.  This can be abused by a local attacker
to create or truncate arbitrary files or to prevent KDE applications
from functioning correctly.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='kdelibs3-doc DPKG is earlier than 2.2.2-13.woody.12' test_ref='oval:org.debian.oval:tst:868'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libarts DPKG is earlier than 2.2.2-13.woody.12' test_ref='oval:org.debian.oval:tst:869'/>
            <criterion comment='libkmid-alsa DPKG is earlier than 2.2.2-13.woody.12' test_ref='oval:org.debian.oval:tst:870'/>
            <criterion comment='kdelibs3-bin DPKG is earlier than 2.2.2-13.woody.12' test_ref='oval:org.debian.oval:tst:871'/>
            <criterion comment='libarts-alsa DPKG is earlier than 2.2.2-13.woody.12' test_ref='oval:org.debian.oval:tst:872'/>
            <criterion comment='kdelibs3 DPKG is earlier than 2.2.2-13.woody.12' test_ref='oval:org.debian.oval:tst:873'/>
            <criterion comment='kdelibs3-cups DPKG is earlier than 2.2.2-13.woody.12' test_ref='oval:org.debian.oval:tst:874'/>
            <criterion comment='libkmid-dev DPKG is earlier than 2.2.2-13.woody.12' test_ref='oval:org.debian.oval:tst:875'/>
            <criterion comment='libkmid DPKG is earlier than 2.2.2-13.woody.12' test_ref='oval:org.debian.oval:tst:876'/>
            <criterion comment='libarts-dev DPKG is earlier than 2.2.2-13.woody.12' test_ref='oval:org.debian.oval:tst:877'/>
            <criterion comment='kdelibs-dev DPKG is earlier than 2.2.2-13.woody.12' test_ref='oval:org.debian.oval:tst:878'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:540' class='vulnerability'>
      <metadata>
        <title>insecure file creation</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>mysql</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0457' ref_id='CVE-2004-0457'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-08-18</date>
          <moreinfo>
Jeroen van Wolffelaar discovered an insecure
temporary file vulnerability in the mysqlhotcopy script when using the
scp method which is part of the mysql-server package.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='mysql-doc DPKG is earlier than 3.23.49-8.5' test_ref='oval:org.debian.oval:tst:879'/>
              <criterion comment='mysql-common DPKG is earlier than 3.23.49-8.7' test_ref='oval:org.debian.oval:tst:880'/>
            </criteria>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='mysql-client DPKG is earlier than 3.23.49-8.7' test_ref='oval:org.debian.oval:tst:881'/>
            <criterion comment='libmysqlclient10 DPKG is earlier than 3.23.49-8.7' test_ref='oval:org.debian.oval:tst:882'/>
            <criterion comment='libmysqlclient10-dev DPKG is earlier than 3.23.49-8.7' test_ref='oval:org.debian.oval:tst:883'/>
            <criterion comment='mysql-server DPKG is earlier than 3.23.49-8.7' test_ref='oval:org.debian.oval:tst:884'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:541' class='vulnerability'>
      <metadata>
        <title>missing escape</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>icecast-server</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0781' ref_id='CVE-2004-0781'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-08-24</date>
          <moreinfo>
Markus Wörle discovered a cross site scripting problem in
status-display (list.cgi) of the icecast internal webserver, an MPEG
layer III streaming server.  The UserAgent variable is not properly
html_escaped so that an attacker could cause the client to execute
arbitrary Java script commands.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='icecast-server DPKG is earlier than 1.3.11-4.2' test_ref='oval:org.debian.oval:tst:885'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:542' class='vulnerability'>
      <metadata>
        <title>unsanitised input</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>qt-copy</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0691' ref_id='CVE-2004-0691'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0692' ref_id='CVE-2004-0692'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0693' ref_id='CVE-2004-0693'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-08-30</date>
          <moreinfo>
Several vulnerabilities were discovered in recent versions of Qt, a
commonly used graphic widget set, used in KDE for example.  The first
problem allows an attacker to execute arbitrary code, while the other
two only seem to pose a denial of service danger.  The Common
Vulnerabilities and Exposures project identifies the following
vulnerabilities:
Chris Evans has discovered a heap-based overflow when handling
    8-bit RLE encoded BMP files.
Marcus Meissner has discovered a crash condition in the XPM
    handling code, which is not yet fixed in Qt 3.3.
Marcus Meissner has discovered a crash condition in the GIF
    handling code, which is not yet fixed in Qt 3.3.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='qt3-doc DPKG is earlier than 3.0.3-20020329-1woody2' test_ref='oval:org.debian.oval:tst:886'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libqt3-mt DPKG is earlier than 3.0.3-20020329-1woody2' test_ref='oval:org.debian.oval:tst:887'/>
            <criterion comment='libqxt0 DPKG is earlier than 3.0.3-20020329-1woody2' test_ref='oval:org.debian.oval:tst:888'/>
            <criterion comment='libqt3-mysql DPKG is earlier than 3.0.3-20020329-1woody2' test_ref='oval:org.debian.oval:tst:889'/>
            <criterion comment='qt3-tools DPKG is earlier than 3.0.3-20020329-1woody2' test_ref='oval:org.debian.oval:tst:890'/>
            <criterion comment='libqt3-dev DPKG is earlier than 3.0.3-20020329-1woody2' test_ref='oval:org.debian.oval:tst:891'/>
            <criterion comment='libqt3-mt-odbc DPKG is earlier than 3.0.3-20020329-1woody2' test_ref='oval:org.debian.oval:tst:892'/>
            <criterion comment='libqt3-mt-mysql DPKG is earlier than 3.0.3-20020329-1woody2' test_ref='oval:org.debian.oval:tst:893'/>
            <criterion comment='libqt3-odbc DPKG is earlier than 3.0.3-20020329-1woody2' test_ref='oval:org.debian.oval:tst:894'/>
            <criterion comment='libqt3-mt-dev DPKG is earlier than 3.0.3-20020329-1woody2' test_ref='oval:org.debian.oval:tst:895'/>
            <criterion comment='libqt3 DPKG is earlier than 3.0.3-20020329-1woody2' test_ref='oval:org.debian.oval:tst:896'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:543' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>krb5</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0642' ref_id='CVE-2004-0642'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0643' ref_id='CVE-2004-0643'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0644' ref_id='CVE-2004-0644'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0772' ref_id='CVE-2004-0772'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-08-31</date>
          <moreinfo>
The MIT Kerberos Development Team has discovered a number of
vulnerabilities in the MIT Kerberos Version 5 software.  The Common
Vulnerabilities and Exposures project identifies the following
vulnerabilities:
A double-free error may allow unauthenticated remote attackers to
    execute arbitrary code on KDC or clients.
Several double-free errors may allow authenticated attackers to
    execute arbitrary code on Kerberos application servers.
A remotely exploitable denial of service vulnerability has been
    found in the KDC and libraries.
Several double-free errors may allow remote attackers to execute
    arbitrary code on the server.  This does not affect the version in
    woody.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='krb5-doc DPKG is earlier than 1.2.4-5woody6' test_ref='oval:org.debian.oval:tst:897'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='krb5-rsh-server DPKG is earlier than 1.2.4-5woody6' test_ref='oval:org.debian.oval:tst:898'/>
            <criterion comment='krb5-telnetd DPKG is earlier than 1.2.4-5woody6' test_ref='oval:org.debian.oval:tst:899'/>
            <criterion comment='libkrb53 DPKG is earlier than 1.2.4-5woody6' test_ref='oval:org.debian.oval:tst:900'/>
            <criterion comment='libkrb5-dev DPKG is earlier than 1.2.4-5woody6' test_ref='oval:org.debian.oval:tst:901'/>
            <criterion comment='krb5-ftpd DPKG is earlier than 1.2.4-5woody6' test_ref='oval:org.debian.oval:tst:902'/>
            <criterion comment='krb5-admin-server DPKG is earlier than 1.2.4-5woody6' test_ref='oval:org.debian.oval:tst:903'/>
            <criterion comment='libkadm55 DPKG is earlier than 1.2.4-5woody6' test_ref='oval:org.debian.oval:tst:904'/>
            <criterion comment='krb5-user DPKG is earlier than 1.2.4-5woody6' test_ref='oval:org.debian.oval:tst:905'/>
            <criterion comment='krb5-clients DPKG is earlier than 1.2.4-5woody6' test_ref='oval:org.debian.oval:tst:906'/>
            <criterion comment='krb5-kdc DPKG is earlier than 1.2.4-5woody6' test_ref='oval:org.debian.oval:tst:907'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:544' class='vulnerability'>
      <metadata>
        <title>insecure temporary directory</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>webmin</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0559' ref_id='CVE-2004-0559'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-09-14</date>
          <moreinfo>
Ludwig Nussel discovered a problem in webmin, a web-based
administration toolkit.  A temporary directory was used but without
checking for the previous owner.  This could allow an attacker to
create the directory and place dangerous symbolic links inside.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='webmin-ssl DPKG is earlier than 0.94-7woody3' test_ref='oval:org.debian.oval:tst:908'/>
              <criterion comment='webmin-status DPKG is earlier than 0.94-7woody3' test_ref='oval:org.debian.oval:tst:909'/>
              <criterion comment='webmin-sshd DPKG is earlier than 0.94-7woody3' test_ref='oval:org.debian.oval:tst:910'/>
              <criterion comment='webmin-mysql DPKG is earlier than 0.94-7woody3' test_ref='oval:org.debian.oval:tst:911'/>
              <criterion comment='webmin-samba DPKG is earlier than 0.94-7woody3' test_ref='oval:org.debian.oval:tst:912'/>
              <criterion comment='webmin-burner DPKG is earlier than 0.94-7woody3' test_ref='oval:org.debian.oval:tst:913'/>
              <criterion comment='webmin-exports DPKG is earlier than 0.94-7woody3' test_ref='oval:org.debian.oval:tst:914'/>
              <criterion comment='webmin-cluster-software DPKG is earlier than 0.94-7woody3' test_ref='oval:org.debian.oval:tst:915'/>
              <criterion comment='webmin-core DPKG is earlier than 0.94-7woody3' test_ref='oval:org.debian.oval:tst:916'/>
              <criterion comment='webmin-fetchmail DPKG is earlier than 0.94-7woody3' test_ref='oval:org.debian.oval:tst:917'/>
              <criterion comment='webmin-quota DPKG is earlier than 0.94-7woody3' test_ref='oval:org.debian.oval:tst:918'/>
              <criterion comment='webmin-inetd DPKG is earlier than 0.94-7woody3' test_ref='oval:org.debian.oval:tst:919'/>
              <criterion comment='webmin-postfix DPKG is earlier than 0.94-7woody3' test_ref='oval:org.debian.oval:tst:920'/>
              <criterion comment='webmin-cpan DPKG is earlier than 0.94-7woody3' test_ref='oval:org.debian.oval:tst:921'/>
              <criterion comment='webmin-mon DPKG is earlier than 0.94-7woody3' test_ref='oval:org.debian.oval:tst:922'/>
              <criterion comment='webmin-xinetd DPKG is earlier than 0.94-7woody3' test_ref='oval:org.debian.oval:tst:923'/>
              <criterion comment='webmin-bind8 DPKG is earlier than 0.94-7woody3' test_ref='oval:org.debian.oval:tst:924'/>
              <criterion comment='webmin-sendmail DPKG is earlier than 0.94-7woody3' test_ref='oval:org.debian.oval:tst:925'/>
              <criterion comment='webmin-dhcpd DPKG is earlier than 0.94-7woody3' test_ref='oval:org.debian.oval:tst:926'/>
              <criterion comment='webmin-apache DPKG is earlier than 0.94-7woody3' test_ref='oval:org.debian.oval:tst:927'/>
              <criterion comment='webmin-heartbeat DPKG is earlier than 0.94-7woody3' test_ref='oval:org.debian.oval:tst:928'/>
              <criterion comment='webmin-lpadmin DPKG is earlier than 0.94-7woody3' test_ref='oval:org.debian.oval:tst:929'/>
              <criterion comment='webmin-squid DPKG is earlier than 0.94-7woody3' test_ref='oval:org.debian.oval:tst:930'/>
              <criterion comment='webmin-postgresql DPKG is earlier than 0.94-7woody3' test_ref='oval:org.debian.oval:tst:931'/>
              <criterion comment='webmin-wuftpd DPKG is earlier than 0.94-7woody3' test_ref='oval:org.debian.oval:tst:932'/>
              <criterion comment='webmin-stunnel DPKG is earlier than 0.94-7woody3' test_ref='oval:org.debian.oval:tst:933'/>
              <criterion comment='webmin-cluster-useradmin DPKG is earlier than 0.94-7woody3' test_ref='oval:org.debian.oval:tst:934'/>
              <criterion comment='webmin-ppp DPKG is earlier than 0.94-7woody3' test_ref='oval:org.debian.oval:tst:935'/>
              <criterion comment='webmin-raid DPKG is earlier than 0.94-7woody3' test_ref='oval:org.debian.oval:tst:936'/>
              <criterion comment='webmin-nis DPKG is earlier than 0.94-7woody3' test_ref='oval:org.debian.oval:tst:937'/>
              <criterion comment='webmin-software DPKG is earlier than 0.94-7woody3' test_ref='oval:org.debian.oval:tst:938'/>
              <criterion comment='webmin-qmailadmin DPKG is earlier than 0.94-7woody3' test_ref='oval:org.debian.oval:tst:939'/>
              <criterion comment='webmin DPKG is earlier than 0.94-7woody3' test_ref='oval:org.debian.oval:tst:940'/>
              <criterion comment='webmin-jabber DPKG is earlier than 0.94-7woody3' test_ref='oval:org.debian.oval:tst:941'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='webmin-grub DPKG is earlier than 0.94-7woody3' test_ref='oval:org.debian.oval:tst:942'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:545' class='vulnerability'>
      <metadata>
        <title>denial of service</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>cupsys</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0558' ref_id='CVE-2004-0558'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-09-15</date>
          <moreinfo>
Alvaro Martinez Echevarria discovered a problem in CUPS, the Common
UNIX Printing System.  An attacker can easily disable browsing in CUPS
by sending a specially crafted UDP datagram to port 631 where cupsd is
running.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='cupsys-bsd DPKG is earlier than 1.1.14-5woody6' test_ref='oval:org.debian.oval:tst:943'/>
            <criterion comment='cupsys-client DPKG is earlier than 1.1.14-5woody6' test_ref='oval:org.debian.oval:tst:944'/>
            <criterion comment='libcupsys2-dev DPKG is earlier than 1.1.14-5woody6' test_ref='oval:org.debian.oval:tst:945'/>
            <criterion comment='cupsys DPKG is earlier than 1.1.14-5woody6' test_ref='oval:org.debian.oval:tst:946'/>
            <criterion comment='libcupsys2 DPKG is earlier than 1.1.14-5woody6' test_ref='oval:org.debian.oval:tst:947'/>
            <criterion comment='cupsys-pstoraster DPKG is earlier than 1.1.14-5woody6' test_ref='oval:org.debian.oval:tst:948'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:546' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>gdk-pixbuf</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0753' ref_id='CVE-2004-0753'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0782' ref_id='CVE-2004-0782'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0788' ref_id='CVE-2004-0788'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-09-16</date>
          <moreinfo>
Chris Evans discovered several problems in gdk-pixbuf, the GdkPixBuf
library used in Gtk.  It is possible for an attacker to execute
arbitrary code on the victims machine.  Gdk-pixbuf for Gtk+1.2 is an
external package.  For Gtk+2.0 it's part of the main gtk package.
The Common Vulnerabilities and Exposures Project identifies the
following vulnerabilities:
Denial of service in bmp loader.
Heap-based overflow in pixbuf_create_from_xpm.
Integer overflow in the ico loader.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libgdk-pixbuf-dev DPKG is earlier than 0.17.0-2woody2' test_ref='oval:org.debian.oval:tst:949'/>
            <criterion comment='libgdk-pixbuf2 DPKG is earlier than 0.17.0-2woody2' test_ref='oval:org.debian.oval:tst:950'/>
            <criterion comment='libgdk-pixbuf-gnome-dev DPKG is earlier than 0.17.0-2woody2' test_ref='oval:org.debian.oval:tst:951'/>
            <criterion comment='libgdk-pixbuf-gnome2 DPKG is earlier than 0.17.0-2woody2' test_ref='oval:org.debian.oval:tst:952'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:547' class='vulnerability'>
      <metadata>
        <title>buffer overflows</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>imagemagick</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0827' ref_id='CVE-2004-0827'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-09-16</date>
          <moreinfo>
Marcus Meissner from SUSE has discovered several buffer overflows in
the ImageMagick graphics library.  An attacker could create a
malicious image or video file in AVI, BMP, or DIB format that could
crash the reading process.  It might be possible that carefully
crafted images could also allow to execute arbitrary code with the
capabilities of the invoking process.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='imagemagick DPKG is earlier than 5.4.4.5-1woody3' test_ref='oval:org.debian.oval:tst:953'/>
            <criterion comment='libmagick5 DPKG is earlier than 5.4.4.5-1woody3' test_ref='oval:org.debian.oval:tst:954'/>
            <criterion comment='libmagick++5 DPKG is earlier than 5.4.4.5-1woody3' test_ref='oval:org.debian.oval:tst:955'/>
            <criterion comment='perlmagick DPKG is earlier than 5.4.4.5-1woody3' test_ref='oval:org.debian.oval:tst:956'/>
            <criterion comment='libmagick5-dev DPKG is earlier than 5.4.4.5-1woody3' test_ref='oval:org.debian.oval:tst:957'/>
            <criterion comment='libmagick++5-dev DPKG is earlier than 5.4.4.5-1woody3' test_ref='oval:org.debian.oval:tst:958'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:548' class='vulnerability'>
      <metadata>
        <title>unsanitised input</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>imlib</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0817' ref_id='CVE-2004-0817'/>
        <description>What information can i put there?</description>
        <debian>
          <moreinfo>
Marcus Meissner discovered a heap overflow error in imlib, an imaging
library for X and X11, that could be abused by an attacker to execute
arbitrary code on the victim's machine.  The updated packages we have
provided in DSA 548-1 did not seem to be sufficient, which should be
fixed by this update.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='imlib-base DPKG is earlier than 1.9.14-2woody3' test_ref='oval:org.debian.oval:tst:959'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='imlib-dev DPKG is earlier than 1.9.14-2woody3' test_ref='oval:org.debian.oval:tst:960'/>
            <criterion comment='imlib-progs DPKG is earlier than 1.9.14-2woody3' test_ref='oval:org.debian.oval:tst:961'/>
            <criterion comment='gdk-imlib-dev DPKG is earlier than 1.9.14-2woody3' test_ref='oval:org.debian.oval:tst:962'/>
            <criterion comment='imlib1 DPKG is earlier than 1.9.14-2woody3' test_ref='oval:org.debian.oval:tst:963'/>
            <criterion comment='gdk-imlib1 DPKG is earlier than 1.9.14-2woody3' test_ref='oval:org.debian.oval:tst:964'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:549' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>gtk+2.0</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0782' ref_id='CVE-2004-0782'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0783' ref_id='CVE-2004-0783'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0788' ref_id='CVE-2004-0788'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-09-17</date>
          <moreinfo>
Chris Evans discovered several problems in gdk-pixbuf, the GdkPixBuf
library used in Gtk.  It is possible for an attacker to execute
arbitrary code on the victims machine.  Gdk-pixbuf for Gtk+1.2 is an
external package.  For Gtk+2.0 it's part of the main gtk package.
The Common Vulnerabilities and Exposures Project identifies the
following vulnerabilities:
Heap-based overflow in pixbuf_create_from_xpm.
Stack-based overflow in xpm_extract_color.
Integer overflow in the ico loader.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='libgtk2.0-doc DPKG is earlier than 2.0.2-5woody2' test_ref='oval:org.debian.oval:tst:965'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='gtk2.0-examples DPKG is earlier than 2.0.2-5woody2' test_ref='oval:org.debian.oval:tst:966'/>
            <criterion comment='libgtk-common DPKG is earlier than 2.0.2-5woody2' test_ref='oval:org.debian.oval:tst:967'/>
            <criterion comment='libgtk2.0-common DPKG is earlier than 2.0.2-5woody2' test_ref='oval:org.debian.oval:tst:968'/>
            <criterion comment='libgtk2.0-0 DPKG is earlier than 2.0.2-5woody2' test_ref='oval:org.debian.oval:tst:969'/>
            <criterion comment='libgtk2.0-dbg DPKG is earlier than 2.0.2-5woody2' test_ref='oval:org.debian.oval:tst:970'/>
            <criterion comment='libgtk2.0-dev DPKG is earlier than 2.0.2-5woody2' test_ref='oval:org.debian.oval:tst:971'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:550' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>wv</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0645' ref_id='CVE-2004-0645'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-09-20</date>
          <moreinfo>
iDEFENSE discovered a buffer overflow in the wv library, used to
convert and preview Microsoft Word documents.  An attacker could
create a specially crafted document that could lead wvHtml to execute
arbitrary code on the victims machine.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='wv DPKG is earlier than 0.7.1+rvt-2woody3' test_ref='oval:org.debian.oval:tst:972'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:551' class='vulnerability'>
      <metadata>
        <title>incorrect internal variable handling</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>lukemftpd</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0794' ref_id='CVE-2004-0794'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-09-21</date>
          <moreinfo>
Przemyslaw Frasunek discovered a vulnerability in tnftpd or lukemftpd
respectively, the enhanced ftp daemon from NetBSD.  An attacker could
utilise this to execute arbitrary code on the server.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='lukemftpd DPKG is earlier than 1.1-1woody2' test_ref='oval:org.debian.oval:tst:973'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:552' class='vulnerability'>
      <metadata>
        <title>unsanitised input</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>imlib2</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0802' ref_id='CVE-2004-0802'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-09-22</date>
          <moreinfo>
Marcus Meissner discovered a heap overflow error in imlib2, an imaging
library for X and X11 and the successor of imlib, that may be utilised
by an attacker to execute arbitrary code on the victims machine.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libimlib2-dev DPKG is earlier than 1.0.5-2woody1' test_ref='oval:org.debian.oval:tst:974'/>
            <criterion comment='libimlib2 DPKG is earlier than 1.0.5-2woody1' test_ref='oval:org.debian.oval:tst:975'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:553' class='vulnerability'>
      <metadata>
        <title>symlink vulnerability</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>getmail</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0880' ref_id='CVE-2004-0880'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0881' ref_id='CVE-2004-0881'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-09-27</date>
          <moreinfo>
A security problem has been discovered in getmail, a POP3 and APOP
mail gatherer and forwarder.  An attacker with a shell account on the
victims host could utilise getmail to overwrite arbitrary files when
it is running as root.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='getmail DPKG is earlier than 2.3.7-2' test_ref='oval:org.debian.oval:tst:976'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:554' class='vulnerability'>
      <metadata>
        <title>pre-set password</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>sendmail</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0833' ref_id='CVE-2004-0833'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-09-27</date>
          <moreinfo>
Hugo Espuny discovered a problem in sendmail, a commonly used program
to deliver electronic mail.  When installing "sasl-bin" to use sasl in
connection with sendmail, the sendmail configuration script use fixed
user/pass information to initialise the sasl database.  Any spammer
with Debian systems knowledge could utilise such a sendmail
installation to relay spam.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='sendmail-doc DPKG is earlier than 8.12.3-7.1' test_ref='oval:org.debian.oval:tst:977'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libmilter-dev DPKG is earlier than 8.12.3-7.1' test_ref='oval:org.debian.oval:tst:978'/>
            <criterion comment='sendmail DPKG is earlier than 8.12.3-7.1' test_ref='oval:org.debian.oval:tst:979'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:555' class='vulnerability'>
      <metadata>
        <title>wrong file permissions</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>freenet6</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0563' ref_id='CVE-2004-0563'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-09-30</date>
          <moreinfo>
Simon Josefsson noticed that the tspc.conf configuration file in
freenet6, a client to configure an IPv6 tunnel to freenet6.net, is set
world readable.  This file can contain the username and the password
used to contact the IPv6 tunnelbroker freenet6.net.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='freenet6 DPKG is earlier than 0.9.6-1woody2' test_ref='oval:org.debian.oval:tst:980'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:556' class='vulnerability'>
      <metadata>
        <title>invalid free(3)</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>netkit-telnet</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0911' ref_id='CVE-2004-0911'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-10-18</date>
          <moreinfo>
Michal Zalewski discovered a bug in the netkit-telnet server (telnetd)
whereby a remote attacker could cause the telnetd process to free an
invalid pointer.  This causes the telnet server process to crash,
leading to a straightforward denial of service (inetd will disable the
service if telnetd is crashed repeatedly), or possibly the execution
of arbitrary code with the privileges of the telnetd process (by
default, the 'telnetd' user).</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='telnetd DPKG is earlier than 0.17-18woody2' test_ref='oval:org.debian.oval:tst:981'/>
            <criterion comment='telnet DPKG is earlier than 0.17-18woody2' test_ref='oval:org.debian.oval:tst:982'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:557' class='vulnerability'>
      <metadata>
        <title>missing privilege dropping</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>rp-pppoe, pppoe</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0564' ref_id='CVE-2004-0564'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-10-04</date>
          <moreinfo>
Max Vozeler discovered a vulnerability in pppoe, the PPP over Ethernet
driver from Roaring Penguin.  When the program is running setuid root
(which is not the case in a default Debian installation), an attacker
could overwrite any file on the file system.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='pppoe DPKG is earlier than 3.3-1.2' test_ref='oval:org.debian.oval:tst:983'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:558' class='vulnerability'>
      <metadata>
        <title>null pointer dereference</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>libapache-mod-dav</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0809' ref_id='CVE-2004-0809'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-10-06</date>
          <moreinfo>
Julian Reschke reported a problem in mod_dav of Apache 2 in connection
with a NULL pointer dereference.  When running in a threaded model,
especially with Apache 2, a segmentation fault can take out a whole
process and hence create a denial of service for the whole server.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libapache-mod-dav DPKG is earlier than 1.0.3-3.1' test_ref='oval:org.debian.oval:tst:984'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:559' class='vulnerability'>
      <metadata>
        <title>insecure temporary file</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>net-acct</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0851' ref_id='CVE-2004-0851'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-10-06</date>
          <moreinfo>
Stefan Nordhausen has identified a local security hole in net-acct, a
user-mode IP accounting daemon.  Old and redundant code from some time
way back in the past created a temporary file in an insecure fashion.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='net-acct DPKG is earlier than 0.71-5woody1' test_ref='oval:org.debian.oval:tst:985'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:560' class='vulnerability'>
      <metadata>
        <title>integer and stack overflows</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>lesstif1-1</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0687' ref_id='CVE-2004-0687'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0688' ref_id='CVE-2004-0688'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-10-07</date>
          <moreinfo>
Chris Evans discovered several stack and integer overflows in the
libXpm library which is included in LessTif.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='lesstif-doc DPKG is earlier than 0.93.18-5' test_ref='oval:org.debian.oval:tst:986'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='lesstif-dbg DPKG is earlier than 0.93.18-5' test_ref='oval:org.debian.oval:tst:987'/>
            <criterion comment='lesstif-bin DPKG is earlier than 0.93.18-5' test_ref='oval:org.debian.oval:tst:988'/>
            <criterion comment='lesstif-dev DPKG is earlier than 0.93.18-5' test_ref='oval:org.debian.oval:tst:989'/>
            <criterion comment='lesstif1 DPKG is earlier than 0.93.18-5' test_ref='oval:org.debian.oval:tst:990'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:561' class='vulnerability'>
      <metadata>
        <title>integer and stack overflows</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>xfree86</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0687' ref_id='CVE-2004-0687'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0688' ref_id='CVE-2004-0688'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-10-11</date>
          <moreinfo>
Chris Evans discovered several stack and integer overflows in the
libXpm library which is provided by X.Org, XFree86 and LessTif.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='xfonts-base-transcoded DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:991'/>
              <criterion comment='xfonts-scalable DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:992'/>
              <criterion comment='x-window-system DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:993'/>
              <criterion comment='xfonts-100dpi DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:994'/>
              <criterion comment='xspecs DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:995'/>
              <criterion comment='xfonts-cyrillic DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:996'/>
              <criterion comment='xfonts-75dpi DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:997'/>
              <criterion comment='xfree86-common DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:998'/>
              <criterion comment='xfonts-base DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:999'/>
              <criterion comment='xlib6g DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1000'/>
              <criterion comment='xfonts-100dpi-transcoded DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1001'/>
              <criterion comment='xfonts-pex DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1002'/>
              <criterion comment='xlib6g-dev DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1003'/>
              <criterion comment='xfonts-75dpi-transcoded DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1004'/>
            </criteria>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libdps1-dbg DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1005'/>
            <criterion comment='xlibs-pic DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1006'/>
            <criterion comment='xlibmesa3 DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1007'/>
            <criterion comment='xlibs DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1008'/>
            <criterion comment='xlibmesa-dev DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1009'/>
            <criterion comment='xlibs-dbg DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1010'/>
            <criterion comment='libxaw6-dev DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1011'/>
            <criterion comment='proxymngr DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1012'/>
            <criterion comment='libxaw6 DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1013'/>
            <criterion comment='libxaw7 DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1014'/>
            <criterion comment='xfwp DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1015'/>
            <criterion comment='xmh DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1016'/>
            <criterion comment='twm DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1017'/>
            <criterion comment='xutils DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1018'/>
            <criterion comment='xprt DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1019'/>
            <criterion comment='libxaw7-dbg DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1020'/>
            <criterion comment='xserver-common DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1021'/>
            <criterion comment='libdps1 DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1022'/>
            <criterion comment='xbase-clients DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1023'/>
            <criterion comment='xdm DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1024'/>
            <criterion comment='xterm DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1025'/>
            <criterion comment='xvfb DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1026'/>
            <criterion comment='libxaw7-dev DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1027'/>
            <criterion comment='libdps-dev DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1028'/>
            <criterion comment='xfs DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1029'/>
            <criterion comment='libxaw6-dbg DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1030'/>
            <criterion comment='xlibs-dev DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1031'/>
            <criterion comment='xlibmesa3-dbg DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1032'/>
            <criterion comment='xnest DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1033'/>
            <criterion comment='lbxproxy DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1034'/>
            <criterion comment='x-window-system-core DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1035'/>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:119'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:112'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:48'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='xlibosmesa3-dbg DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1036'/>
              <criterion comment='xlibosmesa3 DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1037'/>
              <criterion comment='xserver-xfree86 DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1038'/>
              <criterion comment='xlibosmesa-dev DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1039'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported platform section' operator='AND'>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:123'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='xserver-xfree86 DPKG is earlier than 4.1.0-16woody4' test_ref='oval:org.debian.oval:tst:1044'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:562' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>mysql</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0835' ref_id='CVE-2004-0835'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0836' ref_id='CVE-2004-0836'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0837' ref_id='CVE-2004-0837'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-10-11</date>
          <moreinfo>
Several problems have been discovered in MySQL, a commonly used SQL
database on Unix servers.  The following problems have been identified
by the Common Vulnerabilities and Exposures Project:
Oleksandr Byelkin noticed that ALTER TABLE ... RENAME checks
    CREATE/INSERT rights of the old table instead of the new one.
Lukasz Wojtow noticed a buffer overrun in the mysql_real_connect
    function.
Dean Ellis noticed that multiple threads ALTERing the same (or
    different) MERGE tables to change the UNION can cause the server
    to crash or stall.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='mysql-doc DPKG is earlier than 3.23.49-8.5' test_ref='oval:org.debian.oval:tst:1045'/>
              <criterion comment='mysql-common DPKG is earlier than 3.23.49-8.8' test_ref='oval:org.debian.oval:tst:1046'/>
            </criteria>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='mysql-client DPKG is earlier than 3.23.49-8.8' test_ref='oval:org.debian.oval:tst:1047'/>
            <criterion comment='libmysqlclient10 DPKG is earlier than 3.23.49-8.8' test_ref='oval:org.debian.oval:tst:1048'/>
            <criterion comment='libmysqlclient10-dev DPKG is earlier than 3.23.49-8.8' test_ref='oval:org.debian.oval:tst:1049'/>
            <criterion comment='mysql-server DPKG is earlier than 3.23.49-8.8' test_ref='oval:org.debian.oval:tst:1050'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:563' class='vulnerability'>
      <metadata>
        <title>unsanitised input</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>cyrus-sasl</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0884' ref_id='CVE-2004-0884'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-10-14</date>
          <moreinfo>
This advisory is an addition to DSA 563-1 and 563-2 which weren't able
to supersede the library on sparc and arm due to a different version
number for them in the stable archive. Other architectures were
updated properly. Another problem was reported in connection with
sendmail, though, which should be fixed with this update as well.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libsasl-dev DPKG is earlier than 1.5.27-3.1woody5' test_ref='oval:org.debian.oval:tst:1051'/>
            <criterion comment='sasl-bin DPKG is earlier than 1.5.27-3.1woody5' test_ref='oval:org.debian.oval:tst:1052'/>
            <criterion comment='libsasl7 DPKG is earlier than 1.5.27-3.1woody5' test_ref='oval:org.debian.oval:tst:1053'/>
            <criterion comment='libsasl-modules-plain DPKG is earlier than 1.5.27-3.1woody5' test_ref='oval:org.debian.oval:tst:1054'/>
            <criterion comment='libsasl-digestmd5-plain DPKG is earlier than 1.5.27-3.1woody5' test_ref='oval:org.debian.oval:tst:1055'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:564' class='vulnerability'>
      <metadata>
        <title>missing user input sanitising</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>mpg123</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0805' ref_id='CVE-2004-0805'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-10-13</date>
          <moreinfo>
Davide Del Vecchio discovered a vulnerability in mpg123, a popular (but
non-free) MPEG layer 1/2/3 audio player.  A malicious MPEG layer 2/3
file could cause the header checks in mpg123 to fail, which could in
turn allow arbitrary code to be executed with the privileges of the
user running mpg123.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:119'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:120'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:121'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:48'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:123'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='mpg123 DPKG is earlier than 0.59r-13woody3' test_ref='oval:org.debian.oval:tst:1056'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:48'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='mpg123-esd DPKG is earlier than 0.59r-13woody3' test_ref='oval:org.debian.oval:tst:1057'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported platform section' operator='AND'>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='mpg123-nas DPKG is earlier than 0.59r-13woody3' test_ref='oval:org.debian.oval:tst:1058'/>
                <criterion comment='mpg123-oss-i486 DPKG is earlier than 0.59r-13woody3' test_ref='oval:org.debian.oval:tst:1059'/>
                <criterion comment='mpg123-oss-3dnow DPKG is earlier than 0.59r-13woody3' test_ref='oval:org.debian.oval:tst:1060'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:565' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>sox</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0557' ref_id='CVE-2004-0557'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-10-13</date>
          <moreinfo>
Ulf Härnhammar has reported two vulnerabilities in SoX, a universal
sound sample translator, which may be exploited by malicious people to
compromise a user's system with a specially crafted .wav file.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='sox DPKG is earlier than 12.17.3-4woody2' test_ref='oval:org.debian.oval:tst:1061'/>
            <criterion comment='sox-dev DPKG is earlier than 12.17.3-4woody2' test_ref='oval:org.debian.oval:tst:1062'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:566' class='vulnerability'>
      <metadata>
        <title>unsanitised input</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>cupsys</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0923' ref_id='CVE-2004-0923'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-10-14</date>
          <moreinfo>
An information leak has been detected in CUPS, the Common UNIX
Printing System, which may lead to the disclosure of sensitive
information, such as user names and passwords which are written into
log files.
The used patch only eliminates the authentication information in the
device URI which is logged in the error_log file.  It does not
eliminate the URI from the environment and process table, which is why
the CUPS developers recommend that system administrators do not code
authentication information in device URIs in the first place.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='cupsys-bsd DPKG is earlier than 1.1.14-5woody7' test_ref='oval:org.debian.oval:tst:1063'/>
            <criterion comment='cupsys-client DPKG is earlier than 1.1.14-5woody7' test_ref='oval:org.debian.oval:tst:1064'/>
            <criterion comment='libcupsys2-dev DPKG is earlier than 1.1.14-5woody7' test_ref='oval:org.debian.oval:tst:1065'/>
            <criterion comment='cupsys DPKG is earlier than 1.1.14-5woody7' test_ref='oval:org.debian.oval:tst:1066'/>
            <criterion comment='libcupsys2 DPKG is earlier than 1.1.14-5woody7' test_ref='oval:org.debian.oval:tst:1067'/>
            <criterion comment='cupsys-pstoraster DPKG is earlier than 1.1.14-5woody7' test_ref='oval:org.debian.oval:tst:1068'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:567' class='vulnerability'>
      <metadata>
        <title>heap overflows</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>tiff</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0803' ref_id='CVE-2004-0803'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0804' ref_id='CVE-2004-0804'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0886' ref_id='CVE-2004-0886'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-10-15</date>
          <moreinfo>
Several problems have been discovered in libtiff, the Tag Image File
Format library for processing TIFF graphics files.  An attacker could
prepare a specially crafted TIFF graphic that would cause the client
to execute arbitrary code or crash.  The Common Vulnerabilities and
Exposures Project has identified the following problems:
Chris Evans discovered several problems in the RLE (run length
    encoding) decoders that could lead to arbitrary code execution.
Matthias Clasen discovered a division by zero through an integer
    overflow.
Dmitry V. Levin discovered several integer overflows that caused
    malloc issues which can result to either plain crash or memory
    corruption.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libtiff-tools DPKG is earlier than 3.5.5-6woody1' test_ref='oval:org.debian.oval:tst:1069'/>
            <criterion comment='libtiff3g-dev DPKG is earlier than 3.5.5-6woody1' test_ref='oval:org.debian.oval:tst:1070'/>
            <criterion comment='libtiff3g DPKG is earlier than 3.5.5-6woody1' test_ref='oval:org.debian.oval:tst:1071'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:568' class='vulnerability'>
      <metadata>
        <title>unsanitised input</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>cyrus-sasl-mit</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0884' ref_id='CVE-2004-0884'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-10-16</date>
          <moreinfo>
A vulnerability has been discovered in the Cyrus implementation of the
SASL library, the Simple Authentication and Security Layer, a method
for adding authentication support to connection-based protocols.  The
library honors the environment variable SASL_PATH blindly, which
allows a local user to link against a malicious library to run
arbitrary code with the privileges of a setuid or setgid application.
The MIT version of the Cyrus implementation of the SASL library 
provides bindings against MIT GSSAPI and MIT Kerberos4.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libsasl-gssapi-mit DPKG is earlier than 1.5.24-15woody3' test_ref='oval:org.debian.oval:tst:1072'/>
            <criterion comment='libsasl-krb4-mit DPKG is earlier than 1.5.24-15woody3' test_ref='oval:org.debian.oval:tst:1073'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:569' class='vulnerability'>
      <metadata>
        <title>invalid free(3)</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>netkit-telnet-ssl</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0911' ref_id='CVE-2004-0911'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-10-18</date>
          <moreinfo>
Michal Zalewski discovered a bug in the netkit-telnet server (telnetd)
whereby a remote attacker could cause the telnetd process to free an
invalid pointer.  This causes the telnet server process to crash,
leading to a straightforward denial of service (inetd will disable the
service if telnetd is crashed repeatedly), or possibly the execution
of arbitrary code with the privileges of the telnetd process (by
default, the 'telnetd' user).</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='telnet-ssl DPKG is earlier than 0.17.17+0.1-2woody2' test_ref='oval:org.debian.oval:tst:1074'/>
            <criterion comment='telnetd-ssl DPKG is earlier than 0.17.17+0.1-2woody2' test_ref='oval:org.debian.oval:tst:1075'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:570' class='vulnerability'>
      <metadata>
        <title>integer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>libpng</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0599' ref_id='CVE-2004-0599'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-10-20</date>
          <moreinfo>
Several integer overflows have been discovered by its upstream
developers in libpng, a commonly used library to display PNG graphics.
They could be exploited to cause arbitrary code to be executed when a
specially crafted PNG image is processed.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libpng2-dev DPKG is earlier than 1.0.12-3.woody.9' test_ref='oval:org.debian.oval:tst:1076'/>
            <criterion comment='libpng2 DPKG is earlier than 1.0.12-3.woody.9' test_ref='oval:org.debian.oval:tst:1077'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:571' class='vulnerability'>
      <metadata>
        <title>buffer overflows, integer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>libpng3</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0599' ref_id='CVE-2004-0599'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-10-20</date>
          <moreinfo>
Several integer overflows have been discovered by its upstream
developers in libpng, a commonly used library to display PNG graphics.
They could be exploited to cause arbitrary code to be executed when a
specially crafted PNG image is processed.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libpng3 DPKG is earlier than 1.2.1-1.1.woody.9' test_ref='oval:org.debian.oval:tst:1078'/>
            <criterion comment='libpng-dev DPKG is earlier than 1.2.1-1.1.woody.9' test_ref='oval:org.debian.oval:tst:1079'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:572' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>ecartis</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0913' ref_id='CVE-2004-0913'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-10-21</date>
          <moreinfo>
A problem has been discovered in ecartis, a mailing-list manager,
which allows an attacker in the same domain as the list admin to gain
administrator privileges and alter list settings.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='ecartis-cgi DPKG is earlier than 0.129a+1.0.0-snap20020514-1.3' test_ref='oval:org.debian.oval:tst:1080'/>
            <criterion comment='ecartis DPKG is earlier than 0.129a+1.0.0-snap20020514-1.3' test_ref='oval:org.debian.oval:tst:1081'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:573' class='vulnerability'>
      <metadata>
        <title>integer overflows</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>cupsys</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0888' ref_id='CVE-2004-0888'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-10-21</date>
          <moreinfo>
Chris Evans discovered several integer overflows in xpdf, that are
also present in CUPS, the Common UNIX Printing System, which can be
exploited remotely by a specially crafted PDF document.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='cupsys-bsd DPKG is earlier than 1.1.14-5woody10' test_ref='oval:org.debian.oval:tst:1082'/>
            <criterion comment='cupsys-client DPKG is earlier than 1.1.14-5woody10' test_ref='oval:org.debian.oval:tst:1083'/>
            <criterion comment='libcupsys2-dev DPKG is earlier than 1.1.14-5woody10' test_ref='oval:org.debian.oval:tst:1084'/>
            <criterion comment='cupsys DPKG is earlier than 1.1.14-5woody10' test_ref='oval:org.debian.oval:tst:1085'/>
            <criterion comment='libcupsys2 DPKG is earlier than 1.1.14-5woody10' test_ref='oval:org.debian.oval:tst:1086'/>
            <criterion comment='cupsys-pstoraster DPKG is earlier than 1.1.14-5woody10' test_ref='oval:org.debian.oval:tst:1087'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:574' class='vulnerability'>
      <metadata>
        <title>missing directory sanitising</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>cabextract</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0916' ref_id='CVE-2004-0916'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-10-28</date>
          <moreinfo>
The upstream developers discovered a problem in cabextract, a tool to
extract cabinet files.  The program was able to overwrite files in
upper directories.  This could lead an attacker to overwrite arbitrary
files.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='cabextract DPKG is earlier than 0.2-2b' test_ref='oval:org.debian.oval:tst:1088'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:575' class='vulnerability'>
      <metadata>
        <title>insecure temporary file</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>catdoc</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0193' ref_id='CVE-2003-0193'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-10-28</date>
          <moreinfo>
A temporary file problem has been discovered in xlsview from the
catdoc suite, convertors from Word to TeX and plain text, which could
lead to local users being able to overwrite arbitrary files via a
symlink attack on predictable temporary file names.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:118'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:119'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:120'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:122'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:112'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:48'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:128'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:121'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='catdoc DPKG is earlier than 0.91.5-1.woody3' test_ref='oval:org.debian.oval:tst:1089'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:576' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>squid</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0710' ref_id='CVE-1999-0710'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0918' ref_id='CVE-2004-0918'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-10-29</date>
          <moreinfo>
Several security vulnerabilities have been discovered in Squid, the
internet object cache, the popular WWW proxy cache.  The Common
Vulnerabilities and Exposures project identifies the following
problems:
It is possible to bypass access lists and scan arbitrary hosts and
    ports in the network through cachemgr.cgi, which is installed by
    default.  This update disables this feature and introduces a
    configuration file (/etc/squid/cachemgr.conf) to control
    this behavior.
The asn_parse_header function (asn1.c) in the SNMP module for
    Squid allows remote attackers to cause a denial of service via
    certain SNMP packets with negative length fields that causes a
    memory allocation error.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='squidclient DPKG is earlier than 2.4.6-2woody4' test_ref='oval:org.debian.oval:tst:1090'/>
            <criterion comment='squid DPKG is earlier than 2.4.6-2woody4' test_ref='oval:org.debian.oval:tst:1091'/>
            <criterion comment='squid-cgi DPKG is earlier than 2.4.6-2woody4' test_ref='oval:org.debian.oval:tst:1092'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:577' class='vulnerability'>
      <metadata>
        <title>insecure temporary file</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>postgresql</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0977' ref_id='CVE-2004-0977'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-10-29</date>
          <moreinfo>
Trustix Security Engineers identified insecure temporary file creation
in a script included in the postgresql suite, an object-relational SQL
database.  This could lead an attacker to trick a user to overwrite
arbitrary files he has write access to.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='postgresql-doc DPKG is earlier than 7.2.1-2woody6' test_ref='oval:org.debian.oval:tst:1093'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libpgsql2 DPKG is earlier than 7.2.1-2woody6' test_ref='oval:org.debian.oval:tst:1094'/>
            <criterion comment='libpgtcl DPKG is earlier than 7.2.1-2woody6' test_ref='oval:org.debian.oval:tst:1095'/>
            <criterion comment='postgresql DPKG is earlier than 7.2.1-2woody6' test_ref='oval:org.debian.oval:tst:1096'/>
            <criterion comment='pgaccess DPKG is earlier than 7.2.1-2woody6' test_ref='oval:org.debian.oval:tst:1097'/>
            <criterion comment='libpgperl DPKG is earlier than 7.2.1-2woody6' test_ref='oval:org.debian.oval:tst:1098'/>
            <criterion comment='postgresql-contrib DPKG is earlier than 7.2.1-2woody6' test_ref='oval:org.debian.oval:tst:1099'/>
            <criterion comment='odbc-postgresql DPKG is earlier than 7.2.1-2woody6' test_ref='oval:org.debian.oval:tst:1100'/>
            <criterion comment='libecpg3 DPKG is earlier than 7.2.1-2woody6' test_ref='oval:org.debian.oval:tst:1101'/>
            <criterion comment='python-pygresql DPKG is earlier than 7.2.1-2woody6' test_ref='oval:org.debian.oval:tst:1102'/>
            <criterion comment='postgresql-dev DPKG is earlier than 7.2.1-2woody6' test_ref='oval:org.debian.oval:tst:1103'/>
            <criterion comment='postgresql-client DPKG is earlier than 7.2.1-2woody6' test_ref='oval:org.debian.oval:tst:1104'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:578' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>mpg123</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0982' ref_id='CVE-2004-0982'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-11-01</date>
          <moreinfo>
Carlos Barros has discovered a buffer overflow in the HTTP
authentication routine of mpg123, a popular (but non-free) MPEG layer
1/2/3 audio player.  If a user opened a malicious playlist or URL, an
attacker might execute arbitrary code with the rights of the calling
user.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:119'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:120'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:121'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:48'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:123'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='mpg123 DPKG is earlier than 0.59r-13woody4' test_ref='oval:org.debian.oval:tst:1105'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:48'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='mpg123-esd DPKG is earlier than 0.59r-13woody4' test_ref='oval:org.debian.oval:tst:1106'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported platform section' operator='AND'>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='mpg123-nas DPKG is earlier than 0.59r-13woody4' test_ref='oval:org.debian.oval:tst:1107'/>
                <criterion comment='mpg123-oss-i486 DPKG is earlier than 0.59r-13woody4' test_ref='oval:org.debian.oval:tst:1108'/>
                <criterion comment='mpg123-oss-3dnow DPKG is earlier than 0.59r-13woody4' test_ref='oval:org.debian.oval:tst:1109'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:579' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>abiword</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0645' ref_id='CVE-2004-0645'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-11-01</date>
          <moreinfo>
A buffer overflow vulnerability has been discovered in the wv library,
used for converting and previewing word documents.  On exploitation an
attacker could execute arbitrary code with the privileges of the user
running the vulnerable application.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='xfonts-abi DPKG is earlier than 1.0.2+cvs.2002.06.05-1woody2' test_ref='oval:org.debian.oval:tst:1110'/>
              <criterion comment='abiword-doc DPKG is earlier than 1.0.2+cvs.2002.06.05-1woody2' test_ref='oval:org.debian.oval:tst:1111'/>
            </criteria>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='abiword-gnome DPKG is earlier than 1.0.2+cvs.2002.06.05-1woody2' test_ref='oval:org.debian.oval:tst:1112'/>
            <criterion comment='abiword DPKG is earlier than 1.0.2+cvs.2002.06.05-1woody2' test_ref='oval:org.debian.oval:tst:1113'/>
            <criterion comment='abiword-common DPKG is earlier than 1.0.2+cvs.2002.06.05-1woody2' test_ref='oval:org.debian.oval:tst:1114'/>
            <criterion comment='abiword-plugins DPKG is earlier than 1.0.2+cvs.2002.06.05-1woody2' test_ref='oval:org.debian.oval:tst:1115'/>
            <criterion comment='abiword-gtk DPKG is earlier than 1.0.2+cvs.2002.06.05-1woody2' test_ref='oval:org.debian.oval:tst:1116'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:580' class='vulnerability'>
      <metadata>
        <title>missing initialisation</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>iptables</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0986' ref_id='CVE-2004-0986'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-11-01</date>
          <moreinfo>
Faheem Mitha noticed that the iptables command, an administration tool
for IPv4 packet filtering and NAT, did not always load the required
modules on its own as it was supposed to.  This could lead to firewall
rules not being loaded on system startup.  This caused a failure in
connection with rules provided by lokkit at least.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='iptables DPKG is earlier than 1.2.6a-5.0woody2' test_ref='oval:org.debian.oval:tst:1117'/>
            <criterion comment='iptables-dev DPKG is earlier than 1.2.6a-5.0woody2' test_ref='oval:org.debian.oval:tst:1118'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:581' class='vulnerability'>
      <metadata>
        <title>integer overflows</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>xpdf</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0888' ref_id='CVE-2004-0888'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-11-02</date>
          <moreinfo>
Chris Evans discovered several integer overflows in xpdf, a viewer for
PDF files, which can be exploited remotely by a specially crafted PDF
document and lead to the execution of arbitrary code.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='xpdf-common DPKG is earlier than 1.00-3.2' test_ref='oval:org.debian.oval:tst:1119'/>
              <criterion comment='xpdf DPKG is earlier than 1.00-3.2' test_ref='oval:org.debian.oval:tst:1120'/>
            </criteria>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='xpdf-utils DPKG is earlier than 1.00-3.2' test_ref='oval:org.debian.oval:tst:1121'/>
            <criterion comment='xpdf-reader DPKG is earlier than 1.00-3.2' test_ref='oval:org.debian.oval:tst:1122'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:582' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>libxml, libxml2</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0989' ref_id='CVE-2004-0989'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-11-02</date>
          <moreinfo>
"infamous41md" discovered several buffer overflows in libxml and
libxml2, the XML C parser and toolkits for GNOME.  Missing boundary
checks could cause several buffers to be overflown, which may cause
the client to execute arbitrary code.
The following vulnerability matrix lists corrected versions of these
libraries:</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libxml2 DPKG is earlier than 2.4.19-4woody2' test_ref='oval:org.debian.oval:tst:1123'/>
            <criterion comment='libxml1 DPKG is earlier than 1.8.17-2woody2' test_ref='oval:org.debian.oval:tst:1124'/>
            <criterion comment='libxml-dev DPKG is earlier than 1.8.17-2woody2' test_ref='oval:org.debian.oval:tst:1125'/>
            <criterion comment='libxml2-dev DPKG is earlier than 2.4.19-4woody2' test_ref='oval:org.debian.oval:tst:1126'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:583' class='vulnerability'>
      <metadata>
        <title>insecure temporary directory</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>lvm10</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0972' ref_id='CVE-2004-0972'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-11-03</date>
          <moreinfo>
Trustix developers discovered insecure temporary file creation in a
supplemental script in the lvm10 package that didn't check for
existing temporary directories, allowing local users to overwrite
files via a symlink attack.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='lvm10 DPKG is earlier than 1.0.4-5woody2' test_ref='oval:org.debian.oval:tst:1127'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:584' class='vulnerability'>
      <metadata>
        <title>format string vulnerability</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>dhcp</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1006' ref_id='CVE-2004-1006'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-11-04</date>
          <moreinfo>
"infamous41md" noticed that the log functions in dhcp 2.x, which is
still distributed in the stable Debian release, contained pass
parameters to function that use format strings.  One use seems to be
exploitable in connection with a malicious DNS server.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='dhcp DPKG is earlier than 2.0pl5-11woody1' test_ref='oval:org.debian.oval:tst:1128'/>
            <criterion comment='dhcp-client DPKG is earlier than 2.0pl5-11woody1' test_ref='oval:org.debian.oval:tst:1129'/>
            <criterion comment='dhcp-relay DPKG is earlier than 2.0pl5-11woody1' test_ref='oval:org.debian.oval:tst:1130'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:585' class='vulnerability'>
      <metadata>
        <title>programming error</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>shadow</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1001' ref_id='CVE-2004-1001'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-11-05</date>
          <moreinfo>
A vulnerability has been discovered in the shadow suite which provides
programs like chfn and chsh.  It is possible for a user, who is logged
in but has an expired password to alter his account information with
chfn or chsh without having to change the password.  The problem was
originally thought to be more severe.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='passwd DPKG is earlier than 20000902-12woody1' test_ref='oval:org.debian.oval:tst:1131'/>
            <criterion comment='login DPKG is earlier than 20000902-12woody1' test_ref='oval:org.debian.oval:tst:1132'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:586' class='vulnerability'>
      <metadata>
        <title>infinite loop</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>ruby</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0983' ref_id='CVE-2004-0983'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-11-08</date>
          <moreinfo>
The upstream developers of Ruby have corrected a problem in the CGI
module for this language.  Specially crafted requests could cause an
infinite loop and thus cause the program to eat up cpu cycles.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='ruby-elisp DPKG is earlier than 1.6.7-3woody4' test_ref='oval:org.debian.oval:tst:1133'/>
              <criterion comment='ruby-examples DPKG is earlier than 1.6.7-3woody4' test_ref='oval:org.debian.oval:tst:1134'/>
              <criterion comment='irb DPKG is earlier than 1.6.7-3woody4' test_ref='oval:org.debian.oval:tst:1135'/>
            </criteria>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libpty-ruby DPKG is earlier than 1.6.7-3woody4' test_ref='oval:org.debian.oval:tst:1136'/>
            <criterion comment='libdbm-ruby DPKG is earlier than 1.6.7-3woody4' test_ref='oval:org.debian.oval:tst:1137'/>
            <criterion comment='libreadline-ruby DPKG is earlier than 1.6.7-3woody4' test_ref='oval:org.debian.oval:tst:1138'/>
            <criterion comment='ruby-dev DPKG is earlier than 1.6.7-3woody4' test_ref='oval:org.debian.oval:tst:1139'/>
            <criterion comment='libcurses-ruby DPKG is earlier than 1.6.7-3woody4' test_ref='oval:org.debian.oval:tst:1140'/>
            <criterion comment='libsdbm-ruby DPKG is earlier than 1.6.7-3woody4' test_ref='oval:org.debian.oval:tst:1141'/>
            <criterion comment='libruby DPKG is earlier than 1.6.7-3woody4' test_ref='oval:org.debian.oval:tst:1142'/>
            <criterion comment='libgdbm-ruby DPKG is earlier than 1.6.7-3woody4' test_ref='oval:org.debian.oval:tst:1143'/>
            <criterion comment='libtk-ruby DPKG is earlier than 1.6.7-3woody4' test_ref='oval:org.debian.oval:tst:1144'/>
            <criterion comment='libnkf-ruby DPKG is earlier than 1.6.7-3woody4' test_ref='oval:org.debian.oval:tst:1145'/>
            <criterion comment='ruby DPKG is earlier than 1.6.7-3woody4' test_ref='oval:org.debian.oval:tst:1146'/>
            <criterion comment='libsyslog-ruby DPKG is earlier than 1.6.7-3woody4' test_ref='oval:org.debian.oval:tst:1147'/>
            <criterion comment='libtcltk-ruby DPKG is earlier than 1.6.7-3woody4' test_ref='oval:org.debian.oval:tst:1148'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:587' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>freeamp</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0964' ref_id='CVE-2004-0964'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-11-08</date>
          <moreinfo>
Luigi Auriemma discovered a buffer overflow condition in the playlist
module of freeamp which could lead to arbitrary code execution.
Recent versions of freeamp were renamed into zinf.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='freeamp-doc DPKG is earlier than 2.1.1.0-4woody2' test_ref='oval:org.debian.oval:tst:1149'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libfreeamp-esound DPKG is earlier than 2.1.1.0-4woody2' test_ref='oval:org.debian.oval:tst:1150'/>
            <criterion comment='freeamp-extras DPKG is earlier than 2.1.1.0-4woody2' test_ref='oval:org.debian.oval:tst:1151'/>
            <criterion comment='freeamp DPKG is earlier than 2.1.1.0-4woody2' test_ref='oval:org.debian.oval:tst:1152'/>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:119'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:48'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:122'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:123'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libfreeamp-alsa DPKG is earlier than 2.1.1.0-4woody2' test_ref='oval:org.debian.oval:tst:1153'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:588' class='vulnerability'>
      <metadata>
        <title>insecure temporary files</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>gzip</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0970' ref_id='CVE-2004-0970'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-11-08</date>
          <moreinfo>
Trustix developers discovered insecure temporary file creation in
supplemental scripts in the gzip package which may allow local users
to overwrite files via a symlink attack.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='gzip DPKG is earlier than 1.3.2-3woody3' test_ref='oval:org.debian.oval:tst:1154'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:589' class='vulnerability'>
      <metadata>
        <title>integer overflows</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>libgd</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0990' ref_id='CVE-2004-0990'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-11-09</date>
          <moreinfo>
"infamous41md" discovered several integer overflows in the PNG image
decoding routines of the GD graphics library.  This could lead to the
execution of arbitrary code on the victim's machine.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libgd-noxpm-dev DPKG is earlier than 1.8.4-17.woody3' test_ref='oval:org.debian.oval:tst:1155'/>
            <criterion comment='libgd1 DPKG is earlier than 1.8.4-17.woody3' test_ref='oval:org.debian.oval:tst:1156'/>
            <criterion comment='libgd1-noxpm DPKG is earlier than 1.8.4-17.woody3' test_ref='oval:org.debian.oval:tst:1157'/>
            <criterion comment='libgd-dev DPKG is earlier than 1.8.4-17.woody3' test_ref='oval:org.debian.oval:tst:1158'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:590' class='vulnerability'>
      <metadata>
        <title>format string vulnerability</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>gnats</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0623' ref_id='CVE-2004-0623'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-11-09</date>
          <moreinfo>
Khan Shirani discovered a format string vulnerability in gnats, the
GNU problem report management system.  This problem may be exploited
to execute arbitrary code.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='gnats DPKG is earlier than 3.999.beta1+cvs20020303-2' test_ref='oval:org.debian.oval:tst:1159'/>
            <criterion comment='gnats-user DPKG is earlier than 3.999.beta1+cvs20020303-2' test_ref='oval:org.debian.oval:tst:1160'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:591' class='vulnerability'>
      <metadata>
        <title>integer overflows</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>libgd2</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0990' ref_id='CVE-2004-0990'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-11-09</date>
          <moreinfo>
"infamous41md" discovered several integer overflows in the PNG image
decoding routines of the GD graphics library.  This could lead to the
execution of arbitrary code on the victim's machine.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libgd2 DPKG is earlier than 2.0.1-10woody1' test_ref='oval:org.debian.oval:tst:1161'/>
            <criterion comment='libgd2-noxpm DPKG is earlier than 2.0.1-10woody1' test_ref='oval:org.debian.oval:tst:1162'/>
            <criterion comment='libgd-tools DPKG is earlier than 2.0.1-10woody1' test_ref='oval:org.debian.oval:tst:1163'/>
            <criterion comment='libgd2-dev DPKG is earlier than 2.0.1-10woody1' test_ref='oval:org.debian.oval:tst:1164'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:592' class='vulnerability'>
      <metadata>
        <title>format string</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>ez-ipupdate</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0980' ref_id='CVE-2004-0980'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-11-12</date>
          <moreinfo>
Ulf Härnhammar from the Debian Security Audit Project discovered a
format string vulnerability in ez-ipupdate, a client for many dynamic
DNS services.  This problem can only be exploited if ez-ipupdate is
running in daemon mode (most likely) with many but not all service
types.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='ez-ipupdate DPKG is earlier than 3.0.11b5-1woody2' test_ref='oval:org.debian.oval:tst:1165'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:593' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>imagemagick</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0981' ref_id='CVE-2004-0981'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-11-16</date>
          <moreinfo>
A vulnerability has been reported for ImageMagick, a commonly used
image manipulation library.  Due to a boundary error within the EXIF
parsing routine, a specially crafted graphic image could lead to the
execution of arbitrary code.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='imagemagick DPKG is earlier than 5.4.4.5-1woody4' test_ref='oval:org.debian.oval:tst:1166'/>
            <criterion comment='libmagick5 DPKG is earlier than 5.4.4.5-1woody4' test_ref='oval:org.debian.oval:tst:1167'/>
            <criterion comment='libmagick++5 DPKG is earlier than 5.4.4.5-1woody4' test_ref='oval:org.debian.oval:tst:1168'/>
            <criterion comment='perlmagick DPKG is earlier than 5.4.4.5-1woody4' test_ref='oval:org.debian.oval:tst:1169'/>
            <criterion comment='libmagick5-dev DPKG is earlier than 5.4.4.5-1woody4' test_ref='oval:org.debian.oval:tst:1170'/>
            <criterion comment='libmagick++5-dev DPKG is earlier than 5.4.4.5-1woody4' test_ref='oval:org.debian.oval:tst:1171'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:594' class='vulnerability'>
      <metadata>
        <title>buffer overflows</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>apache</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0940' ref_id='CVE-2004-0940'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-11-17</date>
          <moreinfo>
Two vulnerabilities have been identified in the Apache 1.3 webserver:
"Crazy Einstein" has discovered a vulnerability in the
    "mod_include" module, which can cause a buffer to be overflown and
    could lead to the execution of arbitrary code.
Larry Cashdollar has discovered a potential buffer overflow in the
    htpasswd utility, which could be exploited when user-supplied is
    passed to the program via a CGI (or PHP, or ePerl, ...) program.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='apache-doc DPKG is earlier than 1.3.26-0woody6' test_ref='oval:org.debian.oval:tst:1172'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='apache DPKG is earlier than 1.3.26-0woody6' test_ref='oval:org.debian.oval:tst:1173'/>
            <criterion comment='apache-common DPKG is earlier than 1.3.26-0woody6' test_ref='oval:org.debian.oval:tst:1174'/>
            <criterion comment='apache-dev DPKG is earlier than 1.3.26-0woody6' test_ref='oval:org.debian.oval:tst:1175'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:595' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>bnc</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1052' ref_id='CVE-2004-1052'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-11-24</date>
          <moreinfo>
Leon Juranic discovered that BNC, an IRC session bouncing proxy, does
not always protect buffers from being overwritten.  This could
exploited by a malicious IRC server to overflow a buffer of limited
size and execute arbitrary code on the client host.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='bnc DPKG is earlier than 2.6.4-3.3' test_ref='oval:org.debian.oval:tst:1176'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:596' class='vulnerability'>
      <metadata>
        <title>missing input sanitising</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>sudo</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1051' ref_id='CVE-2004-1051'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-11-24</date>
          <moreinfo>
Liam Helmer noticed that sudo, a program that provides limited super
user privileges to specific users, does not clean the environment
sufficiently.  Bash functions and the CDPATH variable are still passed
through to the program running as privileged user, leaving
possibilities to overload system routines.  These vulnerabilities can
only be exploited by users who have been granted limited super user
privileges.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='sudo DPKG is earlier than 1.6.6-1.3' test_ref='oval:org.debian.oval:tst:1177'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:597' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>cyrus-imapd</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1012' ref_id='CVE-2004-1012'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1013' ref_id='CVE-2004-1013'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-11-25</date>
          <moreinfo>
Stefan Esser discovered several security related problems in the Cyrus
IMAP daemon.  Due to a bug in the command parser it is possible to
access memory beyond the allocated buffer in two places which could
lead to the execution of arbitrary code.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='cyrus-nntp DPKG is earlier than 1.5.19-9.2' test_ref='oval:org.debian.oval:tst:1178'/>
            <criterion comment='cyrus-dev DPKG is earlier than 1.5.19-9.2' test_ref='oval:org.debian.oval:tst:1179'/>
            <criterion comment='cyrus-pop3d DPKG is earlier than 1.5.19-9.2' test_ref='oval:org.debian.oval:tst:1180'/>
            <criterion comment='cyrus-common DPKG is earlier than 1.5.19-9.2' test_ref='oval:org.debian.oval:tst:1181'/>
            <criterion comment='cyrus-admin DPKG is earlier than 1.5.19-9.2' test_ref='oval:org.debian.oval:tst:1182'/>
            <criterion comment='cyrus-imapd DPKG is earlier than 1.5.19-9.2' test_ref='oval:org.debian.oval:tst:1183'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:598' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>yardradius</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0987' ref_id='CVE-2004-0987'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-11-25</date>
          <moreinfo>
Max Vozeler noticed that yardradius, the YARD radius authentication
and accounting server, contained a stack overflow similar to the one
from radiusd which is referenced as &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2001-0534">CAN-2001-0534&lt;/a>.  This could lead to
the execution of arbitrary code as root.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='yardradius DPKG is earlier than 1.0.20-2woody1' test_ref='oval:org.debian.oval:tst:1184'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:599' class='vulnerability'>
      <metadata>
        <title>integer overflows</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>tetex-bin</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0888' ref_id='CVE-2004-0888'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-11-25</date>
          <moreinfo>
Chris Evans discovered several integer overflows in xpdf, that are
also present in tetex-bin, binary files for the teTeX distribution,
which can be exploited remotely by a specially crafted PDF document
and lead to the execution of arbitrary code.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libkpathsea-dev DPKG is earlier than 1.0.7+20011202-7.3' test_ref='oval:org.debian.oval:tst:1185'/>
            <criterion comment='libkpathsea3 DPKG is earlier than 1.0.7+20011202-7.3' test_ref='oval:org.debian.oval:tst:1186'/>
            <criterion comment='tetex-bin DPKG is earlier than 1.0.7+20011202-7.3' test_ref='oval:org.debian.oval:tst:1187'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:600' class='vulnerability'>
      <metadata>
        <title>arbitrary file access</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>samba</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0815' ref_id='CVE-2004-0815'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-10-07</date>
          <moreinfo>
A vulnerability has been discovered in samba, a commonly used
LanManager-like file and printer server for Unix.  A remote attacker
may be able to gain access to files which exist outside of the share's
defined path.  Such files must still be readable by the account used
for the connection, though.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='samba-doc DPKG is earlier than 2.2.3a-14.1' test_ref='oval:org.debian.oval:tst:1188'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='smbfs DPKG is earlier than 2.2.3a-14.1' test_ref='oval:org.debian.oval:tst:1189'/>
            <criterion comment='samba DPKG is earlier than 2.2.3a-14.1' test_ref='oval:org.debian.oval:tst:1190'/>
            <criterion comment='libsmbclient DPKG is earlier than 2.2.3a-14.1' test_ref='oval:org.debian.oval:tst:1191'/>
            <criterion comment='smbclient DPKG is earlier than 2.2.3a-14.1' test_ref='oval:org.debian.oval:tst:1192'/>
            <criterion comment='winbind DPKG is earlier than 2.2.3a-14.1' test_ref='oval:org.debian.oval:tst:1193'/>
            <criterion comment='swat DPKG is earlier than 2.2.3a-14.1' test_ref='oval:org.debian.oval:tst:1194'/>
            <criterion comment='libpam-smbpass DPKG is earlier than 2.2.3a-14.1' test_ref='oval:org.debian.oval:tst:1195'/>
            <criterion comment='libsmbclient-dev DPKG is earlier than 2.2.3a-14.1' test_ref='oval:org.debian.oval:tst:1196'/>
            <criterion comment='samba-common DPKG is earlier than 2.2.3a-14.1' test_ref='oval:org.debian.oval:tst:1197'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:601' class='vulnerability'>
      <metadata>
        <title>integer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>libgd1</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0941' ref_id='CVE-2004-0941'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0990' ref_id='CVE-2004-0990'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-11-29</date>
          <moreinfo>
More potential integer overflows have been found in the GD graphics
library which weren't covered by our security advisory 
&lt;a href="dsa-589">DSA 589&lt;/a>.  They
could be exploited by a specially crafted graphic and could lead to
the execution of arbitrary code on the victim's machine.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libgd-noxpm-dev DPKG is earlier than 1.8.4-17.woody4' test_ref='oval:org.debian.oval:tst:1198'/>
            <criterion comment='libgd1 DPKG is earlier than 1.8.4-17.woody4' test_ref='oval:org.debian.oval:tst:1199'/>
            <criterion comment='libgd1-noxpm DPKG is earlier than 1.8.4-17.woody4' test_ref='oval:org.debian.oval:tst:1200'/>
            <criterion comment='libgd-dev DPKG is earlier than 1.8.4-17.woody4' test_ref='oval:org.debian.oval:tst:1201'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:602' class='vulnerability'>
      <metadata>
        <title>integer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>libgd2</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0941' ref_id='CVE-2004-0941'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0990' ref_id='CVE-2004-0990'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-11-29</date>
          <moreinfo>
More potential integer overflows have been found in the GD graphics
library which weren't covered by our security advisory 
&lt;a href="dsa-591">DSA 591&lt;/a>.  They
could be exploited by a specially crafted graphic and could lead to
the execution of arbitrary code on the victim's machine.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libgd2 DPKG is earlier than 2.0.1-10woody2' test_ref='oval:org.debian.oval:tst:1202'/>
            <criterion comment='libgd2-noxpm DPKG is earlier than 2.0.1-10woody2' test_ref='oval:org.debian.oval:tst:1203'/>
            <criterion comment='libgd-tools DPKG is earlier than 2.0.1-10woody2' test_ref='oval:org.debian.oval:tst:1204'/>
            <criterion comment='libgd2-dev DPKG is earlier than 2.0.1-10woody2' test_ref='oval:org.debian.oval:tst:1205'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:603' class='vulnerability'>
      <metadata>
        <title>insecure temporary file</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>openssl</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0975' ref_id='CVE-2004-0975'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-12-01</date>
          <moreinfo>
Trustix developers discovered insecure temporary file creation in a
supplemental script (der_chop) of the openssl package which may allow
local users to overwrite files via a symlink attack.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='ssleay DPKG is earlier than 0.9.6c-2.woody.7' test_ref='oval:org.debian.oval:tst:1206'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libssl-dev DPKG is earlier than 0.9.6c-2.woody.7' test_ref='oval:org.debian.oval:tst:1207'/>
            <criterion comment='libssl0.9.6 DPKG is earlier than 0.9.6c-2.woody.7' test_ref='oval:org.debian.oval:tst:1208'/>
            <criterion comment='openssl DPKG is earlier than 0.9.6c-2.woody.7' test_ref='oval:org.debian.oval:tst:1209'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:604' class='vulnerability'>
      <metadata>
        <title>missing input sanitising</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>hpsockd</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0993' ref_id='CVE-2004-0993'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-12-03</date>
          <moreinfo>
"infamous41md" discovered a buffer overflow condition in hpsockd, the
socks server written at Hewlett-Packard.  An exploit could cause the
program to crash or may have worse effect.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='hpsockd DPKG is earlier than 0.6.woody1' test_ref='oval:org.debian.oval:tst:1210'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:605' class='vulnerability'>
      <metadata>
        <title>settings not honored</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>viewcvs</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0915' ref_id='CVE-2004-0915'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-12-06</date>
          <moreinfo>
Haris Sehic discovered several vulnerabilities in viewcvs, a utility
for viewing CVS and Subversion repositories via HTTP.  When exporting
a repository as a tar archive the hide_cvsroot and forbidden settings
were not honoured enough.
When upgrading the package for woody, please make a copy of your
/etc/viewcvs/viewcvs.conf file if you have manually edited this file.
Upon upgrade the debconf mechanism may alter it in a way so that
viewcvs doesn't understand it anymore.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:8'/>
            <criterion comment='viewcvs DPKG is earlier than 0.9.2-4woody1' test_ref='oval:org.debian.oval:tst:1211'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:606' class='vulnerability'>
      <metadata>
        <title>wrong signal handler</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>nfs-utils</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1014' ref_id='CVE-2004-1014'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-12-08</date>
          <moreinfo>
SGI has discovered that rpc.statd from the nfs-utils package, the
Network Status Monitor, did not ignore the "SIGPIPE".  Hence, a client
prematurely terminating the TCP connection could also terminate the
server process.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='nfs-kernel-server DPKG is earlier than 1.0-2woody3' test_ref='oval:org.debian.oval:tst:1212'/>
            <criterion comment='nfs-common DPKG is earlier than 1.0-2woody3' test_ref='oval:org.debian.oval:tst:1213'/>
            <criterion comment='nhfsstone DPKG is earlier than 1.0-2woody3' test_ref='oval:org.debian.oval:tst:1214'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:607' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.0</platform>
          <product>xfree86</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0914' ref_id='CVE-2004-0914'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2004-12-10</date>
          <moreinfo>
Several developers have discovered a number of problems in the libXpm
library which is provided by X.Org, XFree86 and LessTif.  These bugs
can be exploited by remote and/or local attackers to gain access to
the system or to escalate their local privileges, by using a specially
crafted XPM image.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.0 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval: