<?xml version='1.0' encoding='UTF-8'?>
<oval_definitions xmlns='http://oval.mitre.org/XMLSchema/oval-definitions-5' xmlns:unix-def='http://oval.mitre.org/XMLSchema/oval-definitions-5#unix' xmlns:ind-def ='http://oval.mitre.org/XMLSchema/oval-definitions-5#independent' xmlns:oval='http://oval.mitre.org/XMLSchema/oval-common-5' xmlns:oval-def='http://oval.mitre.org/XMLSchema/oval-definitions-5' xmlns:xsi='http://www.w3.org/2001/XMLSchema-instance' xsi:schemaLocation='http://oval.mitre.org/XMLSchema/oval-definitions-5#independent independent-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd' xmlns:linux-def='http://oval.mitre.org/XMLSchema/oval-definitions-5#linux'>
  <generator>
    <oval:product_name>Debian</oval:product_name>
    <oval:schema_version>5.3</oval:schema_version>
    <oval:timestamp>2008-11-19T19:33:09.188-04:00</oval:timestamp>
  </generator>
  <definitions>
    <definition version='1' id='oval:org.debian:def:1245' class='vulnerability'>
      <metadata>
        <title>programming error</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>proftpd</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4816' ref_id='CVE-2005-4816'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-01-07</date>
          <moreinfo>
Martin Loewer discovered that the proftpd FTP daemon is vulnerable to
denial of service if the addon module for Radius authentication is enabled.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criterion comment='proftpd-doc DPKG is earlier than 1.2.10-15sarge4' test_ref='oval:org.debian.oval:tst:3'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='proftpd DPKG is earlier than 1.2.10-15sarge4' test_ref='oval:org.debian.oval:tst:4'/>
            <criterion comment='proftpd-pgsql DPKG is earlier than 1.2.10-15sarge4' test_ref='oval:org.debian.oval:tst:5'/>
            <criterion comment='proftpd-ldap DPKG is earlier than 1.2.10-15sarge4' test_ref='oval:org.debian.oval:tst:6'/>
            <criterion comment='proftpd-common DPKG is earlier than 1.2.10-15sarge4' test_ref='oval:org.debian.oval:tst:7'/>
            <criterion comment='proftpd-mysql DPKG is earlier than 1.2.10-15sarge4' test_ref='oval:org.debian.oval:tst:8'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1246' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>openoffice.org</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5870' ref_id='CVE-2006-5870'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-01-08</date>
          <moreinfo>
John Heasman from Next Generation Security Software discovered a heap
overflow in the handling of Windows Metafiles in OpenOffice.org, the
free office suite, which could lead to a denial of service and
potentially execution of arbitrary code.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='openoffice.org-l10n-ar DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:9'/>
              <criterion comment='openoffice.org-l10n-cy DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:10'/>
              <criterion comment='openoffice.org DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:11'/>
              <criterion comment='openoffice.org-l10n-da DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:12'/>
              <criterion comment='openoffice.org-l10n-cs DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:13'/>
              <criterion comment='openoffice.org-l10n-af DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:14'/>
              <criterion comment='openoffice.org-l10n-ca DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:15'/>
              <criterion comment='openoffice.org-l10n-en DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:16'/>
              <criterion comment='openoffice.org-l10n-pt-br DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:17'/>
              <criterion comment='openoffice.org-l10n-el DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:18'/>
              <criterion comment='openoffice.org-l10n-gl DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:19'/>
              <criterion comment='openoffice.org-l10n-zu DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:20'/>
              <criterion comment='openoffice.org-thesaurus-en-us DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:21'/>
              <criterion comment='openoffice.org-l10n-kn DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:22'/>
              <criterion comment='openoffice.org-l10n-ko DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:23'/>
              <criterion comment='openoffice.org-l10n-pl DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:24'/>
              <criterion comment='openoffice.org-l10n-it DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:25'/>
              <criterion comment='openoffice.org-l10n-tr DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:26'/>
              <criterion comment='openoffice.org-l10n-zh-tw DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:27'/>
              <criterion comment='openoffice.org-l10n-tn DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:28'/>
              <criterion comment='openoffice.org-l10n-pt DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:29'/>
              <criterion comment='openoffice.org-l10n-et DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:30'/>
              <criterion comment='openoffice.org-l10n-eu DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:31'/>
              <criterion comment='openoffice.org-l10n-es DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:32'/>
              <criterion comment='openoffice.org-l10n-ru DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:33'/>
              <criterion comment='openoffice.org-l10n-th DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:34'/>
              <criterion comment='openoffice.org-l10n-zh-cn DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:35'/>
              <criterion comment='openoffice.org-l10n-fr DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:36'/>
              <criterion comment='ttf-opensymbol DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:37'/>
              <criterion comment='openoffice.org-l10n-ns DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:38'/>
              <criterion comment='openoffice.org-l10n-fi DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:39'/>
              <criterion comment='openoffice.org-l10n-sl DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:40'/>
              <criterion comment='openoffice.org-l10n-lt DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:41'/>
              <criterion comment='openoffice.org-l10n-ja DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:42'/>
              <criterion comment='openoffice.org-l10n-sk DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:43'/>
              <criterion comment='openoffice.org-l10n-de DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:44'/>
              <criterion comment='openoffice.org-l10n-hu DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:45'/>
              <criterion comment='openoffice.org-l10n-hi DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:46'/>
              <criterion comment='openoffice.org-l10n-nn DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:47'/>
              <criterion comment='openoffice.org-l10n-nl DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:48'/>
              <criterion comment='openoffice.org-mimelnk DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:49'/>
              <criterion comment='openoffice.org-l10n-sv DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:50'/>
              <criterion comment='openoffice.org-l10n-he DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:51'/>
              <criterion comment='openoffice.org-l10n-nb DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:52'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='openoffice.org-dev DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:57'/>
              <criterion comment='openoffice.org-gtk-gnome DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:58'/>
              <criterion comment='openoffice.org-evolution DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:59'/>
              <criterion comment='openoffice.org-bin DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:60'/>
              <criterion comment='openoffice.org-kde DPKG is earlier than 1.1.3-9sarge4' test_ref='oval:org.debian.oval:tst:61'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1247' class='vulnerability'>
      <metadata>
        <title>heap overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>libapache-mod-auth-kerb</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5989' ref_id='CVE-2006-5989'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-01-08</date>
          <moreinfo>
An off-by-one error leading to a heap-based buffer overflow has been
identified in libapache-mod-auth-kerb, an Apache module for Kerberos
authentication.  The error could allow an attacker to trigger an
application crash or potentially execute arbitrary code by sending a
specially crafted kerberos message.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:63'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:66'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libapache-mod-auth-kerb DPKG is earlier than 4.996-5.0-rc6-1sarge1' test_ref='oval:org.debian.oval:tst:69'/>
              <criterion comment='libapache2-mod-auth-kerb DPKG is earlier than 4.996-5.0-rc6-1sarge1' test_ref='oval:org.debian.oval:tst:70'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1248' class='vulnerability'>
      <metadata>
        <title>missing input sanitising</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>libsoup</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5876' ref_id='CVE-2006-5876'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-01-12</date>
          <moreinfo>
Roland Lezuo and Josselin Mouette discovered that the libsoup HTTP
library performs insufficient sanitising when parsing HTTP headers,
which might lead to denial of service.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criterion comment='libsoup2.2-doc DPKG is earlier than 2.2.3-2sarge1' test_ref='oval:org.debian.oval:tst:71'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libsoup2.2-dev DPKG is earlier than 2.2.3-2sarge1' test_ref='oval:org.debian.oval:tst:72'/>
            <criterion comment='libsoup2.2-7 DPKG is earlier than 2.2.3-2sarge1' test_ref='oval:org.debian.oval:tst:73'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1249' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>xfree86</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6101' ref_id='CVE-2006-6101'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6102' ref_id='CVE-2006-6102'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6103' ref_id='CVE-2006-6103'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-01-15</date>
          <moreinfo>
Several vulnerabilities have been discovered in the X Window System,
which may lead to privilege escalation or denial of service.
The Common Vulnerabilities and Exposures project identifies the
following problems:
Sean Larsson discovered an integer overflow in the Render extension,
    which might lead to denial of service or local privilege escalation.
Sean Larsson discovered an integer overflow in the DBE extension,
    which might lead to denial of service or local privilege escalation.
Sean Larsson discovered an integer overflow in the DBE extension,
    which might lead to denial of service or local privilege escalation.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='xfonts-base-transcoded DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:74'/>
              <criterion comment='pm-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:75'/>
              <criterion comment='x-window-system DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:76'/>
              <criterion comment='xlibs-data DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:77'/>
              <criterion comment='xfonts-100dpi DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:78'/>
              <criterion comment='xspecs DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:79'/>
              <criterion comment='xfonts-cyrillic DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:80'/>
              <criterion comment='xfonts-75dpi DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:81'/>
              <criterion comment='xfree86-common DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:82'/>
              <criterion comment='xfonts-scalable DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:83'/>
              <criterion comment='xfonts-base DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:84'/>
              <criterion comment='xlibs-pic DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:85'/>
              <criterion comment='xlibmesa3-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:86'/>
              <criterion comment='xlibs-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:87'/>
              <criterion comment='xfonts-100dpi-transcoded DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:88'/>
              <criterion comment='xlibmesa-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:89'/>
              <criterion comment='xlibs-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:90'/>
              <criterion comment='xlibs DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:91'/>
              <criterion comment='xfonts-75dpi-transcoded DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:92'/>
              <criterion comment='x-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:93'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:66'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libxtrap-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:95'/>
              <criterion comment='libxt-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:96'/>
              <criterion comment='libdps1-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:97'/>
              <criterion comment='libdps1 DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:98'/>
              <criterion comment='libxext6 DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:99'/>
              <criterion comment='libxi-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:100'/>
              <criterion comment='libxtst6 DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:101'/>
              <criterion comment='libxmuu1 DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:102'/>
              <criterion comment='libxv-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:103'/>
              <criterion comment='twm DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:104'/>
              <criterion comment='libice6 DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:105'/>
              <criterion comment='libxtst6-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:106'/>
              <criterion comment='xfs DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:107'/>
              <criterion comment='libice6-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:108'/>
              <criterion comment='libsm6 DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:109'/>
              <criterion comment='libxp6-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:110'/>
              <criterion comment='libxaw6-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:111'/>
              <criterion comment='libxtrap6-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:112'/>
              <criterion comment='libxaw6 DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:113'/>
              <criterion comment='libxaw7 DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:114'/>
              <criterion comment='xfwp DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:115'/>
              <criterion comment='xmh DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:116'/>
              <criterion comment='libxpm4 DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:117'/>
              <criterion comment='libsm-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:118'/>
              <criterion comment='libxtrap6 DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:119'/>
              <criterion comment='xutils DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:120'/>
              <criterion comment='libxpm-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:121'/>
              <criterion comment='xnest DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:122'/>
              <criterion comment='libxi6 DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:123'/>
              <criterion comment='libxaw6-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:124'/>
              <criterion comment='libxaw7-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:125'/>
              <criterion comment='libxrandr2-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:126'/>
              <criterion comment='libxmuu1-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:127'/>
              <criterion comment='proxymngr DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:128'/>
              <criterion comment='xlibmesa-glu-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:129'/>
              <criterion comment='libx11-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:130'/>
              <criterion comment='xserver-common DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:131'/>
              <criterion comment='libx11-6 DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:132'/>
              <criterion comment='libxrandr2 DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:133'/>
              <criterion comment='xlibs-static-pic DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:134'/>
              <criterion comment='libxext-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:135'/>
              <criterion comment='libice-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:136'/>
              <criterion comment='xbase-clients DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:137'/>
              <criterion comment='libxft1 DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:138'/>
              <criterion comment='xdm DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:139'/>
              <criterion comment='xterm DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:140'/>
              <criterion comment='libxext6-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:141'/>
              <criterion comment='x-window-system-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:142'/>
              <criterion comment='libx11-6-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:143'/>
              <criterion comment='libxmu6 DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:144'/>
              <criterion comment='libxaw7-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:145'/>
              <criterion comment='libdps-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:146'/>
              <criterion comment='libsm6-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:147'/>
              <criterion comment='xlibmesa-glu DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:148'/>
              <criterion comment='xlibmesa3 DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:149'/>
              <criterion comment='libxtst-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:150'/>
              <criterion comment='libxmu-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:151'/>
              <criterion comment='libxt6-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:152'/>
              <criterion comment='libxt6 DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:153'/>
              <criterion comment='libxmu6-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:154'/>
              <criterion comment='libxp-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:155'/>
              <criterion comment='xlibs-static-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:156'/>
              <criterion comment='libxpm4-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:157'/>
              <criterion comment='xvfb DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:158'/>
              <criterion comment='libxv1 DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:159'/>
              <criterion comment='libxp6 DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:160'/>
              <criterion comment='xlibmesa-gl-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:161'/>
              <criterion comment='libxmuu-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:162'/>
              <criterion comment='libxv1-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:163'/>
              <criterion comment='lbxproxy DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:164'/>
              <criterion comment='libxft1-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:165'/>
              <criterion comment='xlibmesa-gl-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:166'/>
              <criterion comment='libxi6-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:167'/>
              <criterion comment='libxrandr-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:168'/>
              <criterion comment='xlibmesa-glu-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:169'/>
              <criterion comment='xlibmesa-gl DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:170'/>
              <criterion comment='x-window-system-core DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:171'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='xlibosmesa-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:172'/>
              <criterion comment='xlibmesa-dri DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:173'/>
              <criterion comment='xlibosmesa4 DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:174'/>
              <criterion comment='xserver-xfree86 DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:175'/>
              <criterion comment='xlibmesa-dri-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:176'/>
              <criterion comment='xserver-xfree86-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:177'/>
              <criterion comment='xlibosmesa4-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:178'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported platform section' operator='AND'>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='xserver-xfree86-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:185'/>
                <criterion comment='xserver-xfree86 DPKG is earlier than 4.3.0.dfsg.1-14sarge3' test_ref='oval:org.debian.oval:tst:186'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1250' class='vulnerability'>
      <metadata>
        <title>missing input sanitising</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>cacti</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6799' ref_id='CVE-2006-6799'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-01-17</date>
          <moreinfo>
It was discovered that cacti, a frontend to rrdtool, performs insufficient
validation of data passed to the &lt;q>cmd&lt;/q> script, which allows SQL
injection and the execution of arbitrary shell commands.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criterion comment='cacti DPKG is earlier than 0.8.6c-7sarge4' test_ref='oval:org.debian.oval:tst:187'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1251' class='vulnerability'>
      <metadata>
        <title>insufficient escaping</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>netrik</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6678' ref_id='CVE-2006-6678'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-01-21</date>
          <moreinfo>
It has been discovered that netrik, a text mode WWW browser with vi like
keybindings, doesn't properly sanitize temporary filenames when editing
textareas which could allow attackers to execute arbitrary commands via
shell metacharacters.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='netrik DPKG is earlier than 1.15.3-1sarge1' test_ref='oval:org.debian.oval:tst:188'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1252' class='vulnerability'>
      <metadata>
        <title>format string</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>vlc</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0017' ref_id='CVE-2007-0017'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-01-27</date>
          <moreinfo>
Kevin Finisterre discovered several format string problems in vlc, a
multimedia player and streamer, that could lead to the execution of
arbitrary code.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='wxvlc DPKG is earlier than 0.8.1.svn20050314-1sarge2' test_ref='oval:org.debian.oval:tst:189'/>
            <criterion comment='vlc-esd DPKG is earlier than 0.8.1.svn20050314-1sarge2' test_ref='oval:org.debian.oval:tst:190'/>
            <criterion comment='gvlc DPKG is earlier than 0.8.1.svn20050314-1sarge2' test_ref='oval:org.debian.oval:tst:191'/>
            <criterion comment='vlc-plugin-arts DPKG is earlier than 0.8.1.svn20050314-1sarge2' test_ref='oval:org.debian.oval:tst:192'/>
            <criterion comment='vlc DPKG is earlier than 0.8.1.svn20050314-1sarge2' test_ref='oval:org.debian.oval:tst:193'/>
            <criterion comment='vlc-qt DPKG is earlier than 0.8.1.svn20050314-1sarge2' test_ref='oval:org.debian.oval:tst:194'/>
            <criterion comment='mozilla-plugin-vlc DPKG is earlier than 0.8.1.svn20050314-1sarge2' test_ref='oval:org.debian.oval:tst:195'/>
            <criterion comment='qvlc DPKG is earlier than 0.8.1.svn20050314-1sarge2' test_ref='oval:org.debian.oval:tst:196'/>
            <criterion comment='vlc-gnome DPKG is earlier than 0.8.1.svn20050314-1sarge2' test_ref='oval:org.debian.oval:tst:197'/>
            <criterion comment='vlc-plugin-ggi DPKG is earlier than 0.8.1.svn20050314-1sarge2' test_ref='oval:org.debian.oval:tst:198'/>
            <criterion comment='libvlc0-dev DPKG is earlier than 0.8.1.svn20050314-1sarge2' test_ref='oval:org.debian.oval:tst:199'/>
            <criterion comment='vlc-plugin-alsa DPKG is earlier than 0.8.1.svn20050314-1sarge2' test_ref='oval:org.debian.oval:tst:200'/>
            <criterion comment='vlc-plugin-sdl DPKG is earlier than 0.8.1.svn20050314-1sarge2' test_ref='oval:org.debian.oval:tst:201'/>
            <criterion comment='vlc-ggi DPKG is earlier than 0.8.1.svn20050314-1sarge2' test_ref='oval:org.debian.oval:tst:202'/>
            <criterion comment='gnome-vlc DPKG is earlier than 0.8.1.svn20050314-1sarge2' test_ref='oval:org.debian.oval:tst:203'/>
            <criterion comment='vlc-alsa DPKG is earlier than 0.8.1.svn20050314-1sarge2' test_ref='oval:org.debian.oval:tst:204'/>
            <criterion comment='kvlc DPKG is earlier than 0.8.1.svn20050314-1sarge2' test_ref='oval:org.debian.oval:tst:205'/>
            <criterion comment='vlc-gtk DPKG is earlier than 0.8.1.svn20050314-1sarge2' test_ref='oval:org.debian.oval:tst:206'/>
            <criterion comment='vlc-plugin-esd DPKG is earlier than 0.8.1.svn20050314-1sarge2' test_ref='oval:org.debian.oval:tst:207'/>
            <criterion comment='vlc-sdl DPKG is earlier than 0.8.1.svn20050314-1sarge2' test_ref='oval:org.debian.oval:tst:208'/>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='vlc-glide DPKG is earlier than 0.8.1.svn20050314-1sarge2' test_ref='oval:org.debian.oval:tst:209'/>
              <criterion comment='vlc-plugin-glide DPKG is earlier than 0.8.1.svn20050314-1sarge2' test_ref='oval:org.debian.oval:tst:210'/>
              <criterion comment='vlc-plugin-svgalib DPKG is earlier than 0.8.1.svn20050314-1sarge2' test_ref='oval:org.debian.oval:tst:211'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1253' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>mozilla-firefox</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6497' ref_id='CVE-2006-6497'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6498' ref_id='CVE-2006-6498'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6499' ref_id='CVE-2006-6499'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6501' ref_id='CVE-2006-6501'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6502' ref_id='CVE-2006-6502'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6503' ref_id='CVE-2006-6503'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-01-27</date>
          <moreinfo>
Several security related problems have been discovered in Mozilla and
derived products such as Mozilla Firefox.  The Common Vulnerabilities
and Exposures project identifies the following vulnerabilities:
Several vulnerabilities in the layout engine allow remote
    attackers to cause a denial of service and possibly permit them to
    execute arbitrary code. [MFSA 2006-68]
Several vulnerabilities in the JavaScript engine allow remote
    attackers to cause a denial of service and possibly permit them to
    execute arbitrary code. [MFSA 2006-68]
A bug in the js_dtoa function allows remote attackers to cause a
    denial of service. [MFSA 2006-68]
"shutdown" discovered a vulnerability that allows remote attackers
    to gain privileges and install malicious code via the watch
    JavaScript function. [MFSA 2006-70]
Steven Michaud discovered a programming bug that allows remote
    attackers to cause a denial of service. [MFSA 2006-71]
"moz_bug_r_a4" reported that the src attribute of an IMG element
    could be used to inject JavaScript code. [MFSA 2006-72]</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='mozilla-firefox-gnome-support DPKG is earlier than 1.0.4-2sarge15' test_ref='oval:org.debian.oval:tst:212'/>
            <criterion comment='mozilla-firefox-dom-inspector DPKG is earlier than 1.0.4-2sarge15' test_ref='oval:org.debian.oval:tst:213'/>
            <criterion comment='mozilla-firefox DPKG is earlier than 1.0.4-2sarge15' test_ref='oval:org.debian.oval:tst:214'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1254' class='vulnerability'>
      <metadata>
        <title>insufficient input sanitising</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>bind9</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0494' ref_id='CVE-2007-0494'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-01-27</date>
          <moreinfo>
It was discovered that the Bind name server daemon is vulnerable to denial
of service by triggering an assertion through a crafted DNS query. This
only affects installations which use the DNSSEC extentions.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criterion comment='bind9-doc DPKG is earlier than 9.2.4-1sarge2' test_ref='oval:org.debian.oval:tst:215'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='dnsutils DPKG is earlier than 9.2.4-1sarge2' test_ref='oval:org.debian.oval:tst:216'/>
            <criterion comment='libbind-dev DPKG is earlier than 9.2.4-1sarge2' test_ref='oval:org.debian.oval:tst:217'/>
            <criterion comment='bind9 DPKG is earlier than 9.2.4-1sarge2' test_ref='oval:org.debian.oval:tst:218'/>
            <criterion comment='libisccfg0 DPKG is earlier than 9.2.4-1sarge2' test_ref='oval:org.debian.oval:tst:219'/>
            <criterion comment='libisccc0 DPKG is earlier than 9.2.4-1sarge2' test_ref='oval:org.debian.oval:tst:220'/>
            <criterion comment='libisc7 DPKG is earlier than 9.2.4-1sarge2' test_ref='oval:org.debian.oval:tst:221'/>
            <criterion comment='libdns16 DPKG is earlier than 9.2.4-1sarge2' test_ref='oval:org.debian.oval:tst:222'/>
            <criterion comment='liblwres1 DPKG is earlier than 9.2.4-1sarge2' test_ref='oval:org.debian.oval:tst:223'/>
            <criterion comment='bind9-host DPKG is earlier than 9.2.4-1sarge2' test_ref='oval:org.debian.oval:tst:224'/>
            <criterion comment='lwresd DPKG is earlier than 9.2.4-1sarge2' test_ref='oval:org.debian.oval:tst:225'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1255' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>libgtop2</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0235' ref_id='CVE-2007-0235'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-01-31</date>
          <moreinfo>
Liu Qishuai discovered that the GNOME gtop library performs insufficient
sanitising when parsing the system's /proc table, which may lead to
the execution of arbitrary code.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libgtop2-2 DPKG is earlier than 2.6.0-4sarge1' test_ref='oval:org.debian.oval:tst:226'/>
            <criterion comment='libgtop2-daemon DPKG is earlier than 2.6.0-4sarge1' test_ref='oval:org.debian.oval:tst:227'/>
            <criterion comment='libgtop2-dev DPKG is earlier than 2.6.0-4sarge1' test_ref='oval:org.debian.oval:tst:228'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1256' class='vulnerability'>
      <metadata>
        <title>programming error</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>gtk+2.0</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0010' ref_id='CVE-2007-0010'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-01-31</date>
          <moreinfo>
It was discovered that the image loading code in the GTK+ graphical user
interface library performs insufficient error handling when loading
malformed images, which may lead to denial of service.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libgtk2.0-common DPKG is earlier than 2.6.4-3.2' test_ref='oval:org.debian.oval:tst:229'/>
              <criterion comment='libgtk2.0-doc DPKG is earlier than 2.6.4-3.2' test_ref='oval:org.debian.oval:tst:230'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:66'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='gtk2.0-examples DPKG is earlier than 2.6.4-3.2' test_ref='oval:org.debian.oval:tst:231'/>
              <criterion comment='gtk2-engines-pixbuf DPKG is earlier than 2.6.4-3.2' test_ref='oval:org.debian.oval:tst:232'/>
              <criterion comment='libgtk2.0-bin DPKG is earlier than 2.6.4-3.2' test_ref='oval:org.debian.oval:tst:233'/>
              <criterion comment='libgtk2.0-0 DPKG is earlier than 2.6.4-3.2' test_ref='oval:org.debian.oval:tst:234'/>
              <criterion comment='libgtk2.0-dev DPKG is earlier than 2.6.4-3.2' test_ref='oval:org.debian.oval:tst:235'/>
              <criterion comment='libgtk2.0-0-dbg DPKG is earlier than 2.6.4-3.2' test_ref='oval:org.debian.oval:tst:236'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1257' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>samba</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0452' ref_id='CVE-2007-0452'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0454' ref_id='CVE-2007-0454'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-02-05</date>
          <moreinfo>
Several remote vulnerabilities have been discovered in samba, a free
implementation of the SMB/CIFS protocol, which may lead to the execution
of arbitrary code or denial of service. The Common Vulnerabilities and
Exposures project identifies the following problems:
It was discovered that incorrect handling of deferred file open calls
    may lead to an infinite loop, which results in denial of service.
"zybadawg333" discovered that the AFS ACL mapping VFS plugin performs
    insecure format string handling, which may lead to the execution of
    arbitrary code.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criterion comment='samba-doc DPKG is earlier than 3.0.14a-3sarge4' test_ref='oval:org.debian.oval:tst:237'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='smbfs DPKG is earlier than 3.0.14a-3sarge4' test_ref='oval:org.debian.oval:tst:238'/>
            <criterion comment='samba DPKG is earlier than 3.0.14a-3sarge4' test_ref='oval:org.debian.oval:tst:239'/>
            <criterion comment='libsmbclient DPKG is earlier than 3.0.14a-3sarge4' test_ref='oval:org.debian.oval:tst:240'/>
            <criterion comment='smbclient DPKG is earlier than 3.0.14a-3sarge4' test_ref='oval:org.debian.oval:tst:241'/>
            <criterion comment='winbind DPKG is earlier than 3.0.14a-3sarge4' test_ref='oval:org.debian.oval:tst:242'/>
            <criterion comment='swat DPKG is earlier than 3.0.14a-3sarge4' test_ref='oval:org.debian.oval:tst:243'/>
            <criterion comment='samba-dbg DPKG is earlier than 3.0.14a-3sarge4' test_ref='oval:org.debian.oval:tst:244'/>
            <criterion comment='libsmbclient-dev DPKG is earlier than 3.0.14a-3sarge4' test_ref='oval:org.debian.oval:tst:245'/>
            <criterion comment='samba-common DPKG is earlier than 3.0.14a-3sarge4' test_ref='oval:org.debian.oval:tst:246'/>
            <criterion comment='python2.3-samba DPKG is earlier than 3.0.14a-3sarge4' test_ref='oval:org.debian.oval:tst:247'/>
            <criterion comment='libpam-smbpass DPKG is earlier than 3.0.14a-3sarge4' test_ref='oval:org.debian.oval:tst:248'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1258' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>mozilla-thunderbird</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6497' ref_id='CVE-2006-6497'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6498' ref_id='CVE-2006-6498'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6499' ref_id='CVE-2006-6499'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6501' ref_id='CVE-2006-6501'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6502' ref_id='CVE-2006-6502'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6503' ref_id='CVE-2006-6503'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-02-07</date>
          <moreinfo>
Several security related problems have been discovered in Mozilla and
derived products such as Mozilla Firefox.  The Common Vulnerabilities
and Exposures project identifies the following vulnerabilities:
Several vulnerabilities in the layout engine allow remote
    attackers to cause a denial of service and possibly permit them to
    execute arbitrary code. [MFSA 2006-68]
Several vulnerabilities in the JavaScript engine allow remote
    attackers to cause a denial of service and possibly permit them to
    execute arbitrary code. [MFSA 2006-68]
A bug in the js_dtoa function allows remote attackers to cause a
    denial of service. [MFSA 2006-68]
"shutdown" discovered a vulnerability that allows remote attackers
    to gain privileges and install malicious code via the watch
    JavaScript function. [MFSA 2006-70]
Steven Michaud discovered a programming bug that allows remote
    attackers to cause a denial of service. [MFSA 2006-71]
"moz_bug_r_a4" reported that the src attribute of an IMG element
    could be used to inject JavaScript code. [MFSA 2006-72]</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='mozilla-thunderbird-offline DPKG is earlier than 1.0.2-2.sarge1.0.8e.2' test_ref='oval:org.debian.oval:tst:249'/>
            <criterion comment='mozilla-thunderbird DPKG is earlier than 1.0.2-2.sarge1.0.8e.2' test_ref='oval:org.debian.oval:tst:250'/>
            <criterion comment='mozilla-thunderbird-typeaheadfind DPKG is earlier than 1.0.2-2.sarge1.0.8e.2' test_ref='oval:org.debian.oval:tst:251'/>
            <criterion comment='mozilla-thunderbird-dev DPKG is earlier than 1.0.2-2.sarge1.0.8e.2' test_ref='oval:org.debian.oval:tst:252'/>
            <criterion comment='mozilla-thunderbird-inspector DPKG is earlier than 1.0.2-2.sarge1.0.8e.2' test_ref='oval:org.debian.oval:tst:253'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1259' class='vulnerability'>
      <metadata>
        <title>programming error</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>fetchmail</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5867' ref_id='CVE-2006-5867'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-02-14</date>
          <moreinfo>
Isaac Wilcox discovered that fetchmail, a popular mail retrieval and
forwarding utility, insufficiently enforces encryption of connections,
which might lead to information disclosure.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='fetchmail-ssl DPKG is earlier than 6.2.5-12sarge5' test_ref='oval:org.debian.oval:tst:254'/>
              <criterion comment='fetchmailconf DPKG is earlier than 6.2.5-12sarge5' test_ref='oval:org.debian.oval:tst:255'/>
            </criteria>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='fetchmail DPKG is earlier than 6.2.5-12sarge5' test_ref='oval:org.debian.oval:tst:256'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1260' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>imagemagick</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0770' ref_id='CVE-2007-0770'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-02-14</date>
          <moreinfo>
Vladimir Nadvornik discovered that the fix for a vulnerability in the
PALM decoder of Imagemagick, a collection of image manipulation programs,
was ineffective. To avoid confusion a new CVE ID has been assigned;
the original issue was tracked as &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5456">CVE-2006-5456&lt;/a>.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='imagemagick DPKG is earlier than 6.0.6.2-2.9' test_ref='oval:org.debian.oval:tst:257'/>
            <criterion comment='libmagick6-dev DPKG is earlier than 6.0.6.2-2.9' test_ref='oval:org.debian.oval:tst:258'/>
            <criterion comment='libmagick++6-dev DPKG is earlier than 6.0.6.2-2.9' test_ref='oval:org.debian.oval:tst:259'/>
            <criterion comment='libmagick6 DPKG is earlier than 6.0.6.2-2.9' test_ref='oval:org.debian.oval:tst:260'/>
            <criterion comment='perlmagick DPKG is earlier than 6.0.6.2-2.9' test_ref='oval:org.debian.oval:tst:261'/>
            <criterion comment='libmagick++6 DPKG is earlier than 6.0.6.2-2.9' test_ref='oval:org.debian.oval:tst:262'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1261' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>postgresql</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0555' ref_id='CVE-2007-0555'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-02-15</date>
          <moreinfo>
It was discovered that the PostgreSQL database performs insufficient type
checking for SQL function arguments, which might lead to denial of service
or information disclosure.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criterion comment='postgresql-doc DPKG is earlier than 7.4.7-6sarge4' test_ref='oval:org.debian.oval:tst:263'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libpgtcl DPKG is earlier than 7.4.7-6sarge4' test_ref='oval:org.debian.oval:tst:264'/>
            <criterion comment='postgresql DPKG is earlier than 7.4.7-6sarge4' test_ref='oval:org.debian.oval:tst:265'/>
            <criterion comment='libecpg4 DPKG is earlier than 7.4.7-6sarge4' test_ref='oval:org.debian.oval:tst:266'/>
            <criterion comment='postgresql-contrib DPKG is earlier than 7.4.7-6sarge4' test_ref='oval:org.debian.oval:tst:267'/>
            <criterion comment='libpq3 DPKG is earlier than 7.4.7-6sarge4' test_ref='oval:org.debian.oval:tst:268'/>
            <criterion comment='libecpg-dev DPKG is earlier than 7.4.7-6sarge4' test_ref='oval:org.debian.oval:tst:269'/>
            <criterion comment='libpgtcl-dev DPKG is earlier than 7.4.7-6sarge4' test_ref='oval:org.debian.oval:tst:270'/>
            <criterion comment='postgresql-dev DPKG is earlier than 7.4.7-6sarge4' test_ref='oval:org.debian.oval:tst:271'/>
            <criterion comment='postgresql-client DPKG is earlier than 7.4.7-6sarge4' test_ref='oval:org.debian.oval:tst:272'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1262' class='vulnerability'>
      <metadata>
        <title>format string</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>gnomemeeting</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1007' ref_id='CVE-2007-1007'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-03-04</date>
          <moreinfo>
&lt;q>Mu Security&lt;/q> discovered that a format string vulnerability in
the VoIP solution GnomeMeeting allows the execution of arbitrary code.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='gnomemeeting DPKG is earlier than 1.2.1-1sarge1' test_ref='oval:org.debian.oval:tst:273'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1263' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>clamav</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0897' ref_id='CVE-2007-0897'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0898' ref_id='CVE-2007-0898'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-03-06</date>
          <moreinfo>
Several remote vulnerabilities have been discovered in the Clam
anti-virus toolkit, which may lead to denial of service. The Common
Vulnerabilities and Exposures project identifies the following problems:
It was discovered that malformed CAB archives may exhaust file
    descriptors, which allows denial of service.
It was discovered that a directory traversal vulnerability in the MIME
    header parser may lead to denial of service.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='clamav-docs DPKG is earlier than 0.84-2.sarge.15' test_ref='oval:org.debian.oval:tst:274'/>
              <criterion comment='clamav-testfiles DPKG is earlier than 0.84-2.sarge.15' test_ref='oval:org.debian.oval:tst:275'/>
              <criterion comment='clamav-base DPKG is earlier than 0.84-2.sarge.15' test_ref='oval:org.debian.oval:tst:276'/>
            </criteria>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libclamav-dev DPKG is earlier than 0.84-2.sarge.15' test_ref='oval:org.debian.oval:tst:277'/>
            <criterion comment='clamav-daemon DPKG is earlier than 0.84-2.sarge.15' test_ref='oval:org.debian.oval:tst:278'/>
            <criterion comment='clamav DPKG is earlier than 0.84-2.sarge.15' test_ref='oval:org.debian.oval:tst:279'/>
            <criterion comment='libclamav1 DPKG is earlier than 0.84-2.sarge.15' test_ref='oval:org.debian.oval:tst:280'/>
            <criterion comment='clamav-milter DPKG is earlier than 0.84-2.sarge.15' test_ref='oval:org.debian.oval:tst:281'/>
            <criterion comment='clamav-freshclam DPKG is earlier than 0.84-2.sarge.15' test_ref='oval:org.debian.oval:tst:282'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1264' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>php4</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0906' ref_id='CVE-2007-0906'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0907' ref_id='CVE-2007-0907'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0908' ref_id='CVE-2007-0908'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0909' ref_id='CVE-2007-0909'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0910' ref_id='CVE-2007-0910'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0988' ref_id='CVE-2007-0988'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-03-07</date>
          <moreinfo>
Several remote vulnerabilities have been discovered in PHP, a server-side,
HTML-embedded scripting language, which may lead to the execution of
arbitrary code. The Common Vulnerabilities and Exposures project identifies
the following problems:
It was discovered that an integer overflow in the str_replace()
    function could lead to the execution of arbitrary code.
It was discovered that a buffer underflow in the sapi_header_op()
    function could crash the PHP interpreter.
Stefan Esser discovered that a programming error in the wddx
    extension allows information disclosure.
It was discovered that a format string vulnerability in the
    odbc_result_all() functions allows the execution of arbitrary code.
It was discovered that super-global variables could be overwritten
    with session data.
Stefan Esser discovered that the zend_hash_init() function could
    be tricked into an endless loop, allowing denial of service through
    resource consumption until a timeout is triggered.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='php4 DPKG is earlier than 4.3.10-19' test_ref='oval:org.debian.oval:tst:283'/>
              <criterion comment='php4-pear DPKG is earlier than 4.3.10-19' test_ref='oval:org.debian.oval:tst:284'/>
            </criteria>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='php4-mcal DPKG is earlier than 4.3.10-19' test_ref='oval:org.debian.oval:tst:285'/>
            <criterion comment='php4-sybase DPKG is earlier than 4.3.10-19' test_ref='oval:org.debian.oval:tst:286'/>
            <criterion comment='libapache-mod-php4 DPKG is earlier than 4.3.10-19' test_ref='oval:org.debian.oval:tst:287'/>
            <criterion comment='php4-odbc DPKG is earlier than 4.3.10-19' test_ref='oval:org.debian.oval:tst:288'/>
            <criterion comment='php4-dev DPKG is earlier than 4.3.10-19' test_ref='oval:org.debian.oval:tst:289'/>
            <criterion comment='php4-recode DPKG is earlier than 4.3.10-19' test_ref='oval:org.debian.oval:tst:290'/>
            <criterion comment='php4-gd DPKG is earlier than 4.3.10-19' test_ref='oval:org.debian.oval:tst:291'/>
            <criterion comment='php4-xslt DPKG is earlier than 4.3.10-19' test_ref='oval:org.debian.oval:tst:292'/>
            <criterion comment='php4-ldap DPKG is earlier than 4.3.10-19' test_ref='oval:org.debian.oval:tst:293'/>
            <criterion comment='php4-mysql DPKG is earlier than 4.3.10-19' test_ref='oval:org.debian.oval:tst:294'/>
            <criterion comment='php4-common DPKG is earlier than 4.3.10-19' test_ref='oval:org.debian.oval:tst:295'/>
            <criterion comment='php4-curl DPKG is earlier than 4.3.10-19' test_ref='oval:org.debian.oval:tst:296'/>
            <criterion comment='php4-imap DPKG is earlier than 4.3.10-19' test_ref='oval:org.debian.oval:tst:297'/>
            <criterion comment='php4-mhash DPKG is earlier than 4.3.10-19' test_ref='oval:org.debian.oval:tst:298'/>
            <criterion comment='php4-snmp DPKG is earlier than 4.3.10-19' test_ref='oval:org.debian.oval:tst:299'/>
            <criterion comment='libapache2-mod-php4 DPKG is earlier than 4.3.10-19' test_ref='oval:org.debian.oval:tst:300'/>
            <criterion comment='php4-cgi DPKG is earlier than 4.3.10-19' test_ref='oval:org.debian.oval:tst:301'/>
            <criterion comment='php4-cli DPKG is earlier than 4.3.10-19' test_ref='oval:org.debian.oval:tst:302'/>
            <criterion comment='php4-domxml DPKG is earlier than 4.3.10-19' test_ref='oval:org.debian.oval:tst:303'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1265' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>mozilla</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6497' ref_id='CVE-2006-6497'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6498' ref_id='CVE-2006-6498'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6499' ref_id='CVE-2006-6499'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6501' ref_id='CVE-2006-6501'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6502' ref_id='CVE-2006-6502'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6503' ref_id='CVE-2006-6503'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6505' ref_id='CVE-2006-6505'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-03-10</date>
          <moreinfo>
Several security related problems have been discovered in Mozilla and
derived products.  The Common Vulnerabilities and Exposures project
identifies the following vulnerabilities:
Several vulnerabilities in the layout engine allow remote
    attackers to cause a denial of service and possibly permit them to
    execute arbitrary code. [MFSA 2006-68]
Several vulnerabilities in the JavaScript engine allow remote
    attackers to cause a denial of service and possibly permit them to
    execute arbitrary code. [MFSA 2006-68]
A bug in the js_dtoa function allows remote attackers to cause a
    denial of service. [MFSA 2006-68]
&lt;q>shutdown&lt;/q> discovered a vulnerability that allows remote attackers
    to gain privileges and install malicious code via the watch
    JavaScript function. [MFSA 2006-70]
Steven Michaud discovered a programming bug that allows remote
    attackers to cause a denial of service. [MFSA 2006-71]
&lt;q>moz_bug_r_a4&lt;/q> reported that the src attribute of an IMG element
    could be used to inject JavaScript code. [MFSA 2006-72]
Georgi Guninski discovered several heap-based buffer overflows
    that allow remote attackers to execute arbitrary code. [MFSA 2006-74]</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='mozilla DPKG is earlier than 1.7.8-1sarge10' test_ref='oval:org.debian.oval:tst:304'/>
            <criterion comment='mozilla-chatzilla DPKG is earlier than 1.7.8-1sarge10' test_ref='oval:org.debian.oval:tst:305'/>
            <criterion comment='libnspr4 DPKG is earlier than 1.7.8-1sarge10' test_ref='oval:org.debian.oval:tst:306'/>
            <criterion comment='libnss-dev DPKG is earlier than 1.7.8-1sarge10' test_ref='oval:org.debian.oval:tst:307'/>
            <criterion comment='mozilla-psm DPKG is earlier than 1.7.8-1sarge10' test_ref='oval:org.debian.oval:tst:308'/>
            <criterion comment='mozilla-mailnews DPKG is earlier than 1.7.8-1sarge10' test_ref='oval:org.debian.oval:tst:309'/>
            <criterion comment='mozilla-dom-inspector DPKG is earlier than 1.7.8-1sarge10' test_ref='oval:org.debian.oval:tst:310'/>
            <criterion comment='libnspr-dev DPKG is earlier than 1.7.8-1sarge10' test_ref='oval:org.debian.oval:tst:311'/>
            <criterion comment='mozilla-browser DPKG is earlier than 1.7.8-1sarge10' test_ref='oval:org.debian.oval:tst:312'/>
            <criterion comment='mozilla-dev DPKG is earlier than 1.7.8-1sarge10' test_ref='oval:org.debian.oval:tst:313'/>
            <criterion comment='mozilla-js-debugger DPKG is earlier than 1.7.8-1sarge10' test_ref='oval:org.debian.oval:tst:314'/>
            <criterion comment='mozilla-calendar DPKG is earlier than 1.7.8-1sarge10' test_ref='oval:org.debian.oval:tst:315'/>
            <criterion comment='libnss3 DPKG is earlier than 1.7.8-1sarge10' test_ref='oval:org.debian.oval:tst:316'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1266' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>gnupg</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1263' ref_id='CVE-2007-1263'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-03-13</date>
          <moreinfo>
Gerardo Richarte discovered that GnuPG, a free PGP replacement, provides
insufficient user feedback if an OpenPGP message contains both unsigned
and signed portions. Inserting text segments into an otherwise signed
message could be exploited to forge the content of signed messages.
This update prevents such attacks; the old behaviour can still be
activated by passing the --allow-multiple-messages option.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='gnupg DPKG is earlier than 1.4.1-1.sarge7' test_ref='oval:org.debian.oval:tst:317'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1267' class='vulnerability'>
      <metadata>
        <title>missing input sanitising</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>webcalendar</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1343' ref_id='CVE-2007-1343'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-03-15</date>
          <moreinfo>
It was discovered that WebCalendar, a PHP-based calendar application,
insufficiently protects an internal variable, which allows remote file
inclusion.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criterion comment='webcalendar DPKG is earlier than 0.9.45-4sarge6' test_ref='oval:org.debian.oval:tst:318'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1268' class='vulnerability'>
      <metadata>
        <title>integer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>libwpd</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0002' ref_id='CVE-2007-0002'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-03-17</date>
          <moreinfo>
iDefense reported several integer overflow bugs in libwpd, a library
for handling WordPerfect documents.  Attackers were able to exploit
these with carefully crafted Word Perfect files that could cause an
application linked with libwpd to crash or possibly execute arbitrary code.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criterion comment='libwpd8-doc DPKG is earlier than 0.8.7-6' test_ref='oval:org.debian.oval:tst:319'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libwpd-stream8 DPKG is earlier than 0.8.1-1sarge1' test_ref='oval:org.debian.oval:tst:320'/>
            <criterion comment='libwpd-stream8c2a DPKG is earlier than 0.8.7-6' test_ref='oval:org.debian.oval:tst:321'/>
            <criterion comment='libwpd8c2a DPKG is earlier than 0.8.7-6' test_ref='oval:org.debian.oval:tst:322'/>
            <criterion comment='libwpd-tools DPKG is earlier than 0.8.7-6' test_ref='oval:org.debian.oval:tst:323'/>
            <criterion comment='libwpd8 DPKG is earlier than 0.8.1-1sarge1' test_ref='oval:org.debian.oval:tst:324'/>
            <criterion comment='libwpd8-dev DPKG is earlier than 0.8.7-6' test_ref='oval:org.debian.oval:tst:325'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1269' class='vulnerability'>
      <metadata>
        <title>insecure temporary file</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>lookup-el</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0237' ref_id='CVE-2007-0237'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-03-18</date>
          <moreinfo>
Tatsuya Kinoshita discovered that Lookup, a search interface to
electronic dictionaries on emacsen, creates a temporary file in an
insecure fashion when the ndeb-binary feature is used, which allows a
local attacker to craft a symlink attack to overwrite arbitrary files.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criterion comment='lookup-el DPKG is earlier than 1.4-3sarge1' test_ref='oval:org.debian.oval:tst:326'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1270' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>openoffice.org</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0002' ref_id='CVE-2007-0002'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0238' ref_id='CVE-2007-0238'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0239' ref_id='CVE-2007-0239'/>
        <description>What information can i put there?</description>
        <debian>
          <moreinfo>
Several security related problems have been discovered in
OpenOffice.org, the free office suite.  The Common Vulnerabilities and
Exposures project identifies the following problems:
iDefense reported several integer overflow bugs in libwpd, a
    library for handling WordPerfect documents that is included in
    OpenOffice.org.  Attackers are able to exploit these with
    carefully crafted WordPerfect files that could cause an
    application linked with libwpd to crash or possibly execute
    arbitrary code.
Next Generation Security discovered that the StarCalc parser in
    OpenOffice.org contains an easily exploitable stack overflow that
    could be used by a specially crafted document to execute
    arbitrary code.
It has been reported that OpenOffice.org does not escape shell
    meta characters and is hence vulnerable to execute arbitrary shell
    commands via a specially crafted document after the user clicked
    to a prepared link.
This updated advisory only provides packages for the upcoming etch
release alias Debian GNU/Linux 4.0.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='openoffice.org-l10n-ar DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:327'/>
              <criterion comment='openoffice.org-l10n-cy DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:328'/>
              <criterion comment='openoffice.org DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:329'/>
              <criterion comment='openoffice.org-l10n-da DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:330'/>
              <criterion comment='openoffice.org-l10n-cs DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:331'/>
              <criterion comment='openoffice.org-l10n-af DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:332'/>
              <criterion comment='openoffice.org-l10n-ca DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:333'/>
              <criterion comment='openoffice.org-l10n-en DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:334'/>
              <criterion comment='openoffice.org-l10n-pt-br DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:335'/>
              <criterion comment='openoffice.org-l10n-el DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:336'/>
              <criterion comment='openoffice.org-l10n-gl DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:337'/>
              <criterion comment='openoffice.org-l10n-zu DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:338'/>
              <criterion comment='openoffice.org-thesaurus-en-us DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:339'/>
              <criterion comment='openoffice.org-l10n-kn DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:340'/>
              <criterion comment='openoffice.org-l10n-ko DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:341'/>
              <criterion comment='openoffice.org-l10n-pl DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:342'/>
              <criterion comment='openoffice.org-l10n-it DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:343'/>
              <criterion comment='openoffice.org-l10n-tr DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:344'/>
              <criterion comment='openoffice.org-l10n-zh-tw DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:345'/>
              <criterion comment='openoffice.org-l10n-tn DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:346'/>
              <criterion comment='openoffice.org-l10n-pt DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:347'/>
              <criterion comment='openoffice.org-l10n-et DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:348'/>
              <criterion comment='openoffice.org-l10n-eu DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:349'/>
              <criterion comment='openoffice.org-l10n-es DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:350'/>
              <criterion comment='openoffice.org-l10n-ru DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:351'/>
              <criterion comment='openoffice.org-l10n-th DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:352'/>
              <criterion comment='openoffice.org-l10n-zh-cn DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:353'/>
              <criterion comment='openoffice.org-l10n-fr DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:354'/>
              <criterion comment='ttf-opensymbol DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:355'/>
              <criterion comment='openoffice.org-l10n-ns DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:356'/>
              <criterion comment='openoffice.org-l10n-fi DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:357'/>
              <criterion comment='openoffice.org-l10n-sl DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:358'/>
              <criterion comment='openoffice.org-l10n-lt DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:359'/>
              <criterion comment='openoffice.org-l10n-ja DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:360'/>
              <criterion comment='openoffice.org-l10n-sk DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:361'/>
              <criterion comment='openoffice.org-l10n-de DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:362'/>
              <criterion comment='openoffice.org-l10n-hu DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:363'/>
              <criterion comment='openoffice.org-l10n-hi DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:364'/>
              <criterion comment='openoffice.org-l10n-nn DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:365'/>
              <criterion comment='openoffice.org-l10n-nl DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:366'/>
              <criterion comment='openoffice.org-mimelnk DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:367'/>
              <criterion comment='openoffice.org-l10n-sv DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:368'/>
              <criterion comment='openoffice.org-l10n-he DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:369'/>
              <criterion comment='openoffice.org-l10n-nb DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:370'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='openoffice.org-dev DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:371'/>
              <criterion comment='openoffice.org-gtk-gnome DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:372'/>
              <criterion comment='openoffice.org-evolution DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:373'/>
              <criterion comment='openoffice.org-bin DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:374'/>
              <criterion comment='openoffice.org-kde DPKG is earlier than 1.1.3-9sarge6' test_ref='oval:org.debian.oval:tst:375'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1271' class='vulnerability'>
      <metadata>
        <title>design error</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>openafs</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1507' ref_id='CVE-2007-1507'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-03-20</date>
          <moreinfo>
A design error has been identified in the OpenAFS, a cross-platform
distributed filesystem included with Debian.
OpenAFS historically has enabled setuid filesystem support for the local
cell.  However, with its existing protocol, OpenAFS can only use
encryption, and therefore integrity protection, if the user is
authenticated.  Unauthenticated access doesn't do integrity protection.
The practical result is that it's possible for an attacker with
knowledge of AFS to forge an AFS FetchStatus call and make an arbitrary
binary file appear to an AFS client host to be setuid.  If they can then
arrange for that binary to be executed, they will be able to achieve
privilege escalation.
OpenAFS 1.3.81-3sarge2 changes the default behavior to disable setuid
files globally, including the local cell.  It is important to note that
this change will not take effect until the AFS kernel module, built from
the openafs-modules-source package, is rebuilt and loaded into your
kernel.  As a temporary workaround until the kernel module can be
reloaded, setuid support can be manually disabled for the local cell by
running the following command as root
Following the application of this update, if you are certain there is
no security risk of an attacker forging AFS fileserver responses, you
can re-enable setuid status selectively with the following command,
however this should not be done on sites that are visible to the
Internet</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criterion comment='openafs-modules-source DPKG is earlier than 1.3.81-3sarge2' test_ref='oval:org.debian.oval:tst:376'/>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='openafs-client DPKG is earlier than 1.3.81-3sarge2' test_ref='oval:org.debian.oval:tst:377'/>
              <criterion comment='openafs-dbserver DPKG is earlier than 1.3.81-3sarge2' test_ref='oval:org.debian.oval:tst:378'/>
              <criterion comment='openafs-fileserver DPKG is earlier than 1.3.81-3sarge2' test_ref='oval:org.debian.oval:tst:379'/>
              <criterion comment='libpam-openafs-kaserver DPKG is earlier than 1.3.81-3sarge2' test_ref='oval:org.debian.oval:tst:380'/>
              <criterion comment='libopenafs-dev DPKG is earlier than 1.3.81-3sarge2' test_ref='oval:org.debian.oval:tst:381'/>
              <criterion comment='openafs-kpasswd DPKG is earlier than 1.3.81-3sarge2' test_ref='oval:org.debian.oval:tst:382'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1272' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>tcpdump</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1218' ref_id='CVE-2007-1218'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-03-22</date>
          <moreinfo>
Moritz Jodeit discovered an off-by-one buffer overflow in tcpdump, a
powerful tool for network monitoring and data acquisition, which allows
denial of service.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='tcpdump DPKG is earlier than 3.8.3-5sarge2' test_ref='oval:org.debian.oval:tst:383'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1273' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>nas</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1543' ref_id='CVE-2007-1543'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1544' ref_id='CVE-2007-1544'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1545' ref_id='CVE-2007-1545'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1546' ref_id='CVE-2007-1546'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1547' ref_id='CVE-2007-1547'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-03-27</date>
          <moreinfo>
Several vulnerabilities have been discovered in nas, the Network Audio
System.
A stack-based buffer overflow in the accept_att_local function in
server/os/connection.c in nas allows remote attackers to execute
arbitrary code via a long path slave name in a USL socket connection.
An integer overflow in the ProcAuWriteElement function in
server/dia/audispatch.c allows remote attackers to cause a denial of
service (crash) and possibly execute arbitrary code via a large
max_samples value.
The AddResource function in server/dia/resource.c allows remote
attackers to cause a denial of service (server crash) via a
nonexistent client ID.
An array index error allows remote attackers to cause a denial of service
(crash) via (1) large num_action values in the ProcAuSetElements
function in server/dia/audispatch.c or (2) a large inputNum parameter
to the compileInputs function in server/dia/auutil.c.
The ReadRequestFromClient function in server/os/io.c allows remote
attackers to cause a denial of service (crash) via multiple
simultaneous connections, which triggers a NULL pointer dereference.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criterion comment='nas-doc DPKG is earlier than 1.7-2sarge1' test_ref='oval:org.debian.oval:tst:384'/>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:63'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:66'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libaudio2 DPKG is earlier than 1.7-2sarge1' test_ref='oval:org.debian.oval:tst:385'/>
              <criterion comment='nas DPKG is earlier than 1.7-2sarge1' test_ref='oval:org.debian.oval:tst:386'/>
              <criterion comment='nas-bin DPKG is earlier than 1.7-2sarge1' test_ref='oval:org.debian.oval:tst:387'/>
              <criterion comment='libaudio-dev DPKG is earlier than 1.7-2sarge1' test_ref='oval:org.debian.oval:tst:388'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1274' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>file</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1536' ref_id='CVE-2007-1536'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-04-02</date>
          <moreinfo>
An integer underflow bug has been found in the file_printf function in
file, a tool to determine file types based analysis of file content.
The bug could allow an attacker to execute arbitrary code by inducing a
local user to examine a specially crafted file that triggers a buffer
overflow.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libmagic-dev DPKG is earlier than 4.12-1sarge1' test_ref='oval:org.debian.oval:tst:389'/>
            <criterion comment='libmagic1 DPKG is earlier than 4.12-1sarge1' test_ref='oval:org.debian.oval:tst:390'/>
            <criterion comment='file DPKG is earlier than 4.12-1sarge1' test_ref='oval:org.debian.oval:tst:391'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1275' class='vulnerability'>
      <metadata>
        <title>cross-site scripting</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>zope2.7</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0240' ref_id='CVE-2007-0240'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-04-02</date>
          <moreinfo>
A cross-site scripting vulnerability in zope, a web application
server, could allow an attacker to inject arbitrary HTML and/or
JavaScript into the victim's web browser.  This code would run within
the security context of the web browser, potentially allowing the
attacker to access private data such as authentication cookies, or to
affect the rendering or behavior of zope web pages.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='zope2.7 DPKG is earlier than 2.7.5-2sarge4' test_ref='oval:org.debian.oval:tst:392'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1276' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>krb5</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0956' ref_id='CVE-2007-0956'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0957' ref_id='CVE-2007-0957'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1216' ref_id='CVE-2007-1216'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-04-03</date>
          <moreinfo>
Several remote vulnerabilities have been discovered in the MIT reference
implementation of the Kerberos network authentication protocol suite,
which may lead to the execution of arbitrary code. The Common 
Vulnerabilities and Exposures project identifies the following problems:
It was discovered that the krb5 telnet daemon performs insufficient
    validation of usernames, which might allow unauthorized logins or
    privilege escalation.
iDefense discovered that a buffer overflow in the logging code of the
    KDC and the administration daemon might lead to arbitrary code
    execution.
It was discovered that a double free in the RPCSEC_GSS part of the 
    GSS library code might lead to arbitrary code execution.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
              <criterion comment='krb5-doc DPKG is earlier than 1.4.4-7etch1' test_ref='oval:org.debian.oval:tst:394'/>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
                <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
                <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:63'/>
                <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
                <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:66'/>
                <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
                <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
                <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
                <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='krb5-rsh-server DPKG is earlier than 1.4.4-7etch1' test_ref='oval:org.debian.oval:tst:395'/>
                <criterion comment='krb5-telnetd DPKG is earlier than 1.4.4-7etch1' test_ref='oval:org.debian.oval:tst:396'/>
                <criterion comment='libkrb53 DPKG is earlier than 1.4.4-7etch1' test_ref='oval:org.debian.oval:tst:397'/>
                <criterion comment='libkrb5-dev DPKG is earlier than 1.4.4-7etch1' test_ref='oval:org.debian.oval:tst:398'/>
                <criterion comment='krb5-ftpd DPKG is earlier than 1.4.4-7etch1' test_ref='oval:org.debian.oval:tst:399'/>
                <criterion comment='libkadm55 DPKG is earlier than 1.4.4-7etch1' test_ref='oval:org.debian.oval:tst:400'/>
                <criterion comment='libkrb5-dbg DPKG is earlier than 1.4.4-7etch1' test_ref='oval:org.debian.oval:tst:401'/>
                <criterion comment='krb5-user DPKG is earlier than 1.4.4-7etch1' test_ref='oval:org.debian.oval:tst:402'/>
                <criterion comment='krb5-kdc DPKG is earlier than 1.4.4-7etch1' test_ref='oval:org.debian.oval:tst:403'/>
                <criterion comment='krb5-clients DPKG is earlier than 1.4.4-7etch1' test_ref='oval:org.debian.oval:tst:404'/>
                <criterion comment='krb5-admin-server DPKG is earlier than 1.4.4-7etch1' test_ref='oval:org.debian.oval:tst:405'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
              <criterion comment='krb5-doc DPKG is earlier than 1.3.6-2sarge4' test_ref='oval:org.debian.oval:tst:406'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='krb5-rsh-server DPKG is earlier than 1.3.6-2sarge4' test_ref='oval:org.debian.oval:tst:407'/>
              <criterion comment='krb5-telnetd DPKG is earlier than 1.3.6-2sarge4' test_ref='oval:org.debian.oval:tst:408'/>
              <criterion comment='libkrb53 DPKG is earlier than 1.3.6-2sarge4' test_ref='oval:org.debian.oval:tst:409'/>
              <criterion comment='libkrb5-dev DPKG is earlier than 1.3.6-2sarge4' test_ref='oval:org.debian.oval:tst:410'/>
              <criterion comment='krb5-ftpd DPKG is earlier than 1.3.6-2sarge4' test_ref='oval:org.debian.oval:tst:411'/>
              <criterion comment='libkadm55 DPKG is earlier than 1.3.6-2sarge4' test_ref='oval:org.debian.oval:tst:412'/>
              <criterion comment='krb5-user DPKG is earlier than 1.3.6-2sarge4' test_ref='oval:org.debian.oval:tst:413'/>
              <criterion comment='krb5-kdc DPKG is earlier than 1.3.6-2sarge4' test_ref='oval:org.debian.oval:tst:414'/>
              <criterion comment='krb5-clients DPKG is earlier than 1.3.6-2sarge4' test_ref='oval:org.debian.oval:tst:415'/>
              <criterion comment='krb5-admin-server DPKG is earlier than 1.3.6-2sarge4' test_ref='oval:org.debian.oval:tst:416'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1277' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>xmms</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0654' ref_id='CVE-2007-0654'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0653' ref_id='CVE-2007-0653'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-04-04</date>
          <moreinfo>
Multiple errors have been found in the skin handling routines in xmms,
the X Multimedia System.  These vulnerabilities could allow an
attacker to run arbitrary code as the user running xmms by inducing
the victim to load specially crafted interface skin files.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='xmms DPKG is earlier than 1.2.10+cvs20050209-2sarge1' test_ref='oval:org.debian.oval:tst:417'/>
            <criterion comment='xmms-dev DPKG is earlier than 1.2.10+cvs20050209-2sarge1' test_ref='oval:org.debian.oval:tst:418'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1278' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>man-db</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4250' ref_id='CVE-2006-4250'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-04-06</date>
          <moreinfo>
A buffer overflow has been discovered in the man command that could
allow an attacker to execute code as the man user by providing
specially crafted arguments to the -H flag.  This is likely to be an
issue only on machines with the man and mandb programs installed
setuid.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='man-db DPKG is earlier than 2.4.2-21sarge1' test_ref='oval:org.debian.oval:tst:419'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1279' class='vulnerability'>
      <metadata>
        <title>missing input sanitising</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>webcalendar</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6669' ref_id='CVE-2006-6669'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-04-22</date>
          <moreinfo>
It was discovered that WebCalendar, a PHP-based calendar application,
performs insufficient sanitising in the exports handler, which allows
injection of web script.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criterion comment='webcalendar DPKG is earlier than 0.9.45-4sarge7' test_ref='oval:org.debian.oval:tst:420'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1280' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>aircrack-ng</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2057' ref_id='CVE-2007-2057'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-04-24</date>
          <moreinfo>
It was discovered that aircrack-ng, a WEP/WPA security analysis tool,
performs insufficient validation of 802.11 authentication packets, which
allows the execution of arbitrary code.
The oldstable distribution (sarge) doesn't contain aircrack-ng packages.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criterion comment='aircrack DPKG is earlier than 0.6.2-7etch1' test_ref='oval:org.debian.oval:tst:421'/>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='aircrack-ng DPKG is earlier than 0.6.2-7etch1' test_ref='oval:org.debian.oval:tst:422'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1281' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>clamav</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1745' ref_id='CVE-2007-1745'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1997' ref_id='CVE-2007-1997'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2029' ref_id='CVE-2007-2029'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-04-25</date>
          <moreinfo>
Several remote vulnerabilities have been discovered in the Clam
anti-virus toolkit. The Common Vulnerabilities and Exposures project
identifies the following problems:
It was discovered that a file descriptor leak in the CHM handler may
    lead to denial of service.
It was discovered that a buffer overflow in the CAB handler may lead
    to the execution of arbitrary code.
It was discovered that a file descriptor leak in the PDF handler may
    lead to denial of service.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='clamav-docs DPKG is earlier than 0.90.1-3etch1' test_ref='oval:org.debian.oval:tst:423'/>
                <criterion comment='clamav-testfiles DPKG is earlier than 0.90.1-3etch1' test_ref='oval:org.debian.oval:tst:424'/>
                <criterion comment='clamav-base DPKG is earlier than 0.90.1-3etch1' test_ref='oval:org.debian.oval:tst:425'/>
              </criteria>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
                <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
                <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
                <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
                <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='libclamav-dev DPKG is earlier than 0.90.1-3etch1' test_ref='oval:org.debian.oval:tst:426'/>
                <criterion comment='clamav DPKG is earlier than 0.90.1-3etch1' test_ref='oval:org.debian.oval:tst:427'/>
                <criterion comment='clamav-dbg DPKG is earlier than 0.90.1-3etch1' test_ref='oval:org.debian.oval:tst:428'/>
                <criterion comment='libclamav2 DPKG is earlier than 0.90.1-3etch1' test_ref='oval:org.debian.oval:tst:429'/>
                <criterion comment='clamav-daemon DPKG is earlier than 0.90.1-3etch1' test_ref='oval:org.debian.oval:tst:430'/>
                <criterion comment='clamav-milter DPKG is earlier than 0.90.1-3etch1' test_ref='oval:org.debian.oval:tst:431'/>
                <criterion comment='clamav-freshclam DPKG is earlier than 0.90.1-3etch1' test_ref='oval:org.debian.oval:tst:432'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='clamav-docs DPKG is earlier than 0.84-2.sarge.16' test_ref='oval:org.debian.oval:tst:433'/>
                <criterion comment='clamav-testfiles DPKG is earlier than 0.84-2.sarge.16' test_ref='oval:org.debian.oval:tst:434'/>
                <criterion comment='clamav-base DPKG is earlier than 0.84-2.sarge.16' test_ref='oval:org.debian.oval:tst:435'/>
              </criteria>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
                <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
                <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
                <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='libclamav-dev DPKG is earlier than 0.84-2.sarge.16' test_ref='oval:org.debian.oval:tst:436'/>
                <criterion comment='clamav-daemon DPKG is earlier than 0.84-2.sarge.16' test_ref='oval:org.debian.oval:tst:437'/>
                <criterion comment='clamav DPKG is earlier than 0.84-2.sarge.16' test_ref='oval:org.debian.oval:tst:438'/>
                <criterion comment='libclamav1 DPKG is earlier than 0.84-2.sarge.16' test_ref='oval:org.debian.oval:tst:439'/>
                <criterion comment='clamav-milter DPKG is earlier than 0.84-2.sarge.16' test_ref='oval:org.debian.oval:tst:440'/>
                <criterion comment='clamav-freshclam DPKG is earlier than 0.84-2.sarge.16' test_ref='oval:org.debian.oval:tst:441'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1282' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>php4</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1286' ref_id='CVE-2007-1286'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1380' ref_id='CVE-2007-1380'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1521' ref_id='CVE-2007-1521'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1711' ref_id='CVE-2007-1711'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1718' ref_id='CVE-2007-1718'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1777' ref_id='CVE-2007-1777'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-04-26</date>
          <moreinfo>
Several remote vulnerabilities have been discovered in PHP, a
server-side, HTML-embedded scripting language, which may lead to the
execution of arbitrary code. The Common Vulnerabilities and Exposures
project identifies the following problems:
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1286">CVE-2007-1286&lt;/a>
    Stefan Esser discovered an overflow in the object reference handling
    code of the unserialize() function, which allows the execution of
    arbitrary code if malformed input is passed from an application.
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1380">CVE-2007-1380&lt;/a>
    Stefan Esser discovered that the session handler performs
    insufficient validation of variable name length values, which allows
    information disclosure through a heap information leak.
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1521">CVE-2007-1521&lt;/a>
    Stefan Esser discovered a double free vulnerability in the
    session_regenerate_id() function, which allows the execution of
    arbitrary code. 
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1711">CVE-2007-1711&lt;/a>
    Stefan Esser discovered a double free vulnerability in the session
    management code, which allows the execution of arbitrary code. 
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1718">CVE-2007-1718&lt;/a>
    Stefan Esser discovered that the mail() function performs
    insufficient validation of folded mail headers, which allows mail
    header injection.
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1777">CVE-2007-1777&lt;/a>
    Stefan Esser discovered that the extension to handle ZIP archives
    performs insufficient length checks, which allows the execution of
    arbitrary code.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='php4 DPKG is earlier than 4.4.4-8+etch2' test_ref='oval:org.debian.oval:tst:442'/>
                <criterion comment='php4-pear DPKG is earlier than 4.4.4-8+etch2' test_ref='oval:org.debian.oval:tst:443'/>
              </criteria>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
                <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
                <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
                <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
                <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='libapache-mod-php4 DPKG is earlier than 4.4.4-8+etch2' test_ref='oval:org.debian.oval:tst:444'/>
                <criterion comment='php4-recode DPKG is earlier than 4.4.4-8+etch2' test_ref='oval:org.debian.oval:tst:445'/>
                <criterion comment='php4-xslt DPKG is earlier than 4.4.4-8+etch2' test_ref='oval:org.debian.oval:tst:446'/>
                <criterion comment='php4-mcal DPKG is earlier than 4.4.4-8+etch2' test_ref='oval:org.debian.oval:tst:447'/>
                <criterion comment='php4-domxml DPKG is earlier than 4.4.4-8+etch2' test_ref='oval:org.debian.oval:tst:448'/>
                <criterion comment='php4-mhash DPKG is earlier than 4.4.4-8+etch2' test_ref='oval:org.debian.oval:tst:449'/>
                <criterion comment='php4-odbc DPKG is earlier than 4.4.4-8+etch2' test_ref='oval:org.debian.oval:tst:450'/>
                <criterion comment='libapache2-mod-php4 DPKG is earlier than 4.4.4-8+etch2' test_ref='oval:org.debian.oval:tst:451'/>
                <criterion comment='php4-cli DPKG is earlier than 4.4.4-8+etch2' test_ref='oval:org.debian.oval:tst:452'/>
                <criterion comment='php4-mcrypt DPKG is earlier than 4.4.4-8+etch2' test_ref='oval:org.debian.oval:tst:453'/>
                <criterion comment='php4-gd DPKG is earlier than 4.4.4-8+etch2' test_ref='oval:org.debian.oval:tst:454'/>
                <criterion comment='php4-mysql DPKG is earlier than 4.4.4-8+etch2' test_ref='oval:org.debian.oval:tst:455'/>
                <criterion comment='php4-imap DPKG is earlier than 4.4.4-8+etch2' test_ref='oval:org.debian.oval:tst:456'/>
                <criterion comment='php4-cgi DPKG is earlier than 4.4.4-8+etch2' test_ref='oval:org.debian.oval:tst:457'/>
                <criterion comment='php4-pgsql DPKG is earlier than 4.4.4-8+etch2' test_ref='oval:org.debian.oval:tst:458'/>
                <criterion comment='php4-snmp DPKG is earlier than 4.4.4-8+etch2' test_ref='oval:org.debian.oval:tst:459'/>
                <criterion comment='php4-dev DPKG is earlier than 4.4.4-8+etch2' test_ref='oval:org.debian.oval:tst:460'/>
                <criterion comment='php4-pspell DPKG is earlier than 4.4.4-8+etch2' test_ref='oval:org.debian.oval:tst:461'/>
                <criterion comment='php4-ldap DPKG is earlier than 4.4.4-8+etch2' test_ref='oval:org.debian.oval:tst:462'/>
                <criterion comment='php4-common DPKG is earlier than 4.4.4-8+etch2' test_ref='oval:org.debian.oval:tst:463'/>
                <criterion comment='php4-curl DPKG is earlier than 4.4.4-8+etch2' test_ref='oval:org.debian.oval:tst:464'/>
                <criterion comment='php4-sybase DPKG is earlier than 4.4.4-8+etch2' test_ref='oval:org.debian.oval:tst:465'/>
              </criteria>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
                <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='php4-interbase DPKG is earlier than 4.4.4-8+etch2' test_ref='oval:org.debian.oval:tst:466'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='php4 DPKG is earlier than 4.3.10-20' test_ref='oval:org.debian.oval:tst:467'/>
                <criterion comment='php4-pear DPKG is earlier than 4.3.10-20' test_ref='oval:org.debian.oval:tst:468'/>
              </criteria>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
                <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
                <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
                <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
                <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='php4-mcal DPKG is earlier than 4.3.10-20' test_ref='oval:org.debian.oval:tst:469'/>
                <criterion comment='php4-sybase DPKG is earlier than 4.3.10-20' test_ref='oval:org.debian.oval:tst:470'/>
                <criterion comment='libapache-mod-php4 DPKG is earlier than 4.3.10-20' test_ref='oval:org.debian.oval:tst:471'/>
                <criterion comment='php4-odbc DPKG is earlier than 4.3.10-20' test_ref='oval:org.debian.oval:tst:472'/>
                <criterion comment='php4-recode DPKG is earlier than 4.3.10-20' test_ref='oval:org.debian.oval:tst:473'/>
                <criterion comment='php4-dev DPKG is earlier than 4.3.10-20' test_ref='oval:org.debian.oval:tst:474'/>
                <criterion comment='php4-gd DPKG is earlier than 4.3.10-20' test_ref='oval:org.debian.oval:tst:475'/>
                <criterion comment='php4-xslt DPKG is earlier than 4.3.10-20' test_ref='oval:org.debian.oval:tst:476'/>
                <criterion comment='php4-ldap DPKG is earlier than 4.3.10-20' test_ref='oval:org.debian.oval:tst:477'/>
                <criterion comment='php4-mysql DPKG is earlier than 4.3.10-20' test_ref='oval:org.debian.oval:tst:478'/>
                <criterion comment='php4-common DPKG is earlier than 4.3.10-20' test_ref='oval:org.debian.oval:tst:479'/>
                <criterion comment='php4-curl DPKG is earlier than 4.3.10-20' test_ref='oval:org.debian.oval:tst:480'/>
                <criterion comment='php4-imap DPKG is earlier than 4.3.10-20' test_ref='oval:org.debian.oval:tst:481'/>
                <criterion comment='php4-mhash DPKG is earlier than 4.3.10-20' test_ref='oval:org.debian.oval:tst:482'/>
                <criterion comment='php4-snmp DPKG is earlier than 4.3.10-20' test_ref='oval:org.debian.oval:tst:483'/>
                <criterion comment='libapache2-mod-php4 DPKG is earlier than 4.3.10-20' test_ref='oval:org.debian.oval:tst:484'/>
                <criterion comment='php4-cgi DPKG is earlier than 4.3.10-20' test_ref='oval:org.debian.oval:tst:485'/>
                <criterion comment='php4-cli DPKG is earlier than 4.3.10-20' test_ref='oval:org.debian.oval:tst:486'/>
                <criterion comment='php4-domxml DPKG is earlier than 4.3.10-20' test_ref='oval:org.debian.oval:tst:487'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1283' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>php5</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1286' ref_id='CVE-2007-1286'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1375' ref_id='CVE-2007-1375'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1376' ref_id='CVE-2007-1376'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1380' ref_id='CVE-2007-1380'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1453' ref_id='CVE-2007-1453'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1454' ref_id='CVE-2007-1454'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1521' ref_id='CVE-2007-1521'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1583' ref_id='CVE-2007-1583'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1700' ref_id='CVE-2007-1700'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1711' ref_id='CVE-2007-1711'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1718' ref_id='CVE-2007-1718'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1777' ref_id='CVE-2007-1777'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1824' ref_id='CVE-2007-1824'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1887' ref_id='CVE-2007-1887'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1889' ref_id='CVE-2007-1889'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1900' ref_id='CVE-2007-1900'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-04-29</date>
          <moreinfo>
Several remote vulnerabilities have been discovered in PHP, a
server-side, HTML-embedded scripting language, which may lead to the
execution of arbitrary code. The Common Vulnerabilities and Exposures
project identifies the following problems:
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1286">CVE-2007-1286&lt;/a>
    Stefan Esser discovered an overflow in the object reference handling
    code of the unserialize() function, which allows the execution of
    arbitrary code if malformed input is passed from an application.
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1375">CVE-2007-1375&lt;/a>
    Stefan Esser discovered that an integer overflow in the substr_compare()
    function allows information disclosure of heap memory.
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1376">CVE-2007-1376&lt;/a>
    Stefan Esser discovered that insufficient validation of shared memory
    functions allows the disclosure of heap memory.
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1380">CVE-2007-1380&lt;/a>
    Stefan Esser discovered that the session handler performs
    insufficient validation of variable name length values, which allows
    information disclosure through a heap information leak.
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1453">CVE-2007-1453&lt;/a>
    Stefan Esser discovered that the filtering framework performs insufficient
    input validation, which allows the execution of arbitrary code through a
    buffer underflow.
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1454">CVE-2007-1454&lt;/a>
    Stefan Esser discovered that the filtering framework can be bypassed 
    with a special whitespace character.
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1521">CVE-2007-1521&lt;/a>
    Stefan Esser discovered a double free vulnerability in the
    session_regenerate_id() function, which allows the execution of
    arbitrary code. 
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1583">CVE-2007-1583&lt;/a>
    Stefan Esser discovered that a programming error in the mb_parse_str()
    function allows the activation of &lt;q>register_globals&lt;/q>.
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1700">CVE-2007-1700&lt;/a>
    Stefan Esser discovered that the session extension incorrectly maintains
    the reference count of session variables, which allows the execution of
    arbitrary code.
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1711">CVE-2007-1711&lt;/a>
    Stefan Esser discovered a double free vulnerability in the session
    management code, which allows the execution of arbitrary code. 
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1718">CVE-2007-1718&lt;/a>
    Stefan Esser discovered that the mail() function performs
    insufficient validation of folded mail headers, which allows mail
    header injection.
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1777">CVE-2007-1777&lt;/a>
    Stefan Esser discovered that the extension to handle ZIP archives
    performs insufficient length checks, which allows the execution of
    arbitrary code.
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1824">CVE-2007-1824&lt;/a>
    Stefan Esser discovered an off-by-one error in the filtering framework, which
    allows the execution of arbitrary code.
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1887">CVE-2007-1887&lt;/a>
    Stefan Esser discovered that a buffer overflow in the sqlite extension
    allows the execution of arbitrary code.
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1889">CVE-2007-1889&lt;/a>
    Stefan Esser discovered that the PHP memory manager performs an
    incorrect type cast, which allows the execution of arbitrary code
    through buffer overflows. 
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1900">CVE-2007-1900&lt;/a>
    Stefan Esser discovered that incorrect validation in the email filter
    extension allows the injection of mail headers.
The oldstable distribution (sarge) doesn't include php5.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='php-pear DPKG is earlier than 5.2.0-8+etch3' test_ref='oval:org.debian.oval:tst:488'/>
              <criterion comment='php5 DPKG is earlier than 5.2.0-8+etch3' test_ref='oval:org.debian.oval:tst:489'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libapache-mod-php5 DPKG is earlier than 5.2.0-8+etch3' test_ref='oval:org.debian.oval:tst:490'/>
              <criterion comment='php5-recode DPKG is earlier than 5.2.0-8+etch3' test_ref='oval:org.debian.oval:tst:491'/>
              <criterion comment='php5-xmlrpc DPKG is earlier than 5.2.0-8+etch3' test_ref='oval:org.debian.oval:tst:492'/>
              <criterion comment='php5-curl DPKG is earlier than 5.2.0-8+etch3' test_ref='oval:org.debian.oval:tst:493'/>
              <criterion comment='php5-snmp DPKG is earlier than 5.2.0-8+etch3' test_ref='oval:org.debian.oval:tst:494'/>
              <criterion comment='php5-mysql DPKG is earlier than 5.2.0-8+etch3' test_ref='oval:org.debian.oval:tst:495'/>
              <criterion comment='php5-odbc DPKG is earlier than 5.2.0-8+etch3' test_ref='oval:org.debian.oval:tst:496'/>
              <criterion comment='php5-xsl DPKG is earlier than 5.2.0-8+etch3' test_ref='oval:org.debian.oval:tst:497'/>
              <criterion comment='php5-gd DPKG is earlier than 5.2.0-8+etch3' test_ref='oval:org.debian.oval:tst:498'/>
              <criterion comment='libapache2-mod-php5 DPKG is earlier than 5.2.0-8+etch3' test_ref='oval:org.debian.oval:tst:499'/>
              <criterion comment='php5-mhash DPKG is earlier than 5.2.0-8+etch3' test_ref='oval:org.debian.oval:tst:500'/>
              <criterion comment='php5-tidy DPKG is earlier than 5.2.0-8+etch3' test_ref='oval:org.debian.oval:tst:501'/>
              <criterion comment='php5-mcrypt DPKG is earlier than 5.2.0-8+etch3' test_ref='oval:org.debian.oval:tst:502'/>
              <criterion comment='php5-dev DPKG is earlier than 5.2.0-8+etch3' test_ref='oval:org.debian.oval:tst:503'/>
              <criterion comment='php5-pgsql DPKG is earlier than 5.2.0-8+etch3' test_ref='oval:org.debian.oval:tst:504'/>
              <criterion comment='php5-cgi DPKG is earlier than 5.2.0-8+etch3' test_ref='oval:org.debian.oval:tst:505'/>
              <criterion comment='php5-imap DPKG is earlier than 5.2.0-8+etch3' test_ref='oval:org.debian.oval:tst:506'/>
              <criterion comment='php5-sqlite DPKG is earlier than 5.2.0-8+etch3' test_ref='oval:org.debian.oval:tst:507'/>
              <criterion comment='php5-ldap DPKG is earlier than 5.2.0-8+etch3' test_ref='oval:org.debian.oval:tst:508'/>
              <criterion comment='php5-cli DPKG is earlier than 5.2.0-8+etch3' test_ref='oval:org.debian.oval:tst:509'/>
              <criterion comment='php5-sybase DPKG is earlier than 5.2.0-8+etch3' test_ref='oval:org.debian.oval:tst:510'/>
              <criterion comment='php5-pspell DPKG is earlier than 5.2.0-8+etch3' test_ref='oval:org.debian.oval:tst:511'/>
              <criterion comment='php5-common DPKG is earlier than 5.2.0-8+etch3' test_ref='oval:org.debian.oval:tst:512'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='php5-interbase DPKG is earlier than 5.2.0-8+etch3' test_ref='oval:org.debian.oval:tst:513'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1284' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>qemu</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1320' ref_id='CVE-2007-1320'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1321' ref_id='CVE-2007-1321'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1322' ref_id='CVE-2007-1322'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1323' ref_id='CVE-2007-1323'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1366' ref_id='CVE-2007-1366'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-05-01</date>
          <moreinfo>
Several vulnerabilities have been discovered in the QEMU processor
emulator, which may lead to the execution of arbitrary code or denial of
service. The Common Vulnerabilities and Exposures project identifies the
following problems:
Tavis Ormandy discovered that a memory management routine of the Cirrus
    video driver performs insufficient bounds checking, which might
    allow the execution of arbitrary code through a heap overflow.
Tavis Ormandy discovered that the NE2000 network driver and the socket
    code perform insufficient input validation, which might allow the
    execution of arbitrary code through a heap overflow.
Tavis Ormandy discovered that the &lt;q>icebp&lt;/q> instruction can be abused to
    terminate the emulation, resulting in denial of service.
Tavis Ormandy discovered that the NE2000 network driver and the socket
    code perform insufficient input validation, which might allow the
    execution of arbitrary code through a heap overflow.
Tavis Ormandy discovered that the &lt;q>aam&lt;/q> instruction can be abused to
    crash qemu through a division by zero, resulting in denial of
    service.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
                <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
                <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='qemu DPKG is earlier than 0.8.2-4etch1' test_ref='oval:org.debian.oval:tst:514'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
                <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='qemu DPKG is earlier than 0.6.1+20050407-1sarge1' test_ref='oval:org.debian.oval:tst:515'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1285' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>wordpress</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1622' ref_id='CVE-2007-1622'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1893' ref_id='CVE-2007-1893'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1894' ref_id='CVE-2007-1894'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1897' ref_id='CVE-2007-1897'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-05-01</date>
          <moreinfo>
Cross-site scripting (XSS) vulnerability in wp-admin/vars.php in
    WordPress before 2.0.10 RC2, and before 2.1.3 RC2 in the 2.1 series,
    allows remote authenticated users with theme privileges to inject
    arbitrary web script or HTML via the PATH_INFO in the administration
    interface, related to loose regular expression processing of PHP_SELF.
WordPress 2.1.2, and probably earlier, allows remote authenticated
    users with the contributor role to bypass intended access restrictions
    and invoke the publish_posts functionality, which can be used to
    &lt;q>publish a previously saved post.&lt;/q>
Cross-site scripting (XSS) vulnerability in
    wp-includes/general-template.php in WordPress before 20070309 allows
    remote attackers to inject arbitrary web script or HTML via the year
    parameter in the wp_title function.
SQL injection vulnerability in xmlrpc.php in WordPress 2.1.2, and
    probably earlier, allows remote authenticated users to execute
    arbitrary SQL commands via a string parameter value in an XML RPC
    mt.setPostCategories method call, related to the post_id variable.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criterion comment='wordpress DPKG is earlier than 2.0.10-1' test_ref='oval:org.debian.oval:tst:516'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1286' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>linux-2.6</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0005' ref_id='CVE-2007-0005'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0958' ref_id='CVE-2007-0958'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1357' ref_id='CVE-2007-1357'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1592' ref_id='CVE-2007-1592'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-05-02</date>
          <moreinfo>
Several local and remote vulnerabilities have been discovered in the Linux
kernel that may lead to a denial of service or the execution of arbitrary
code. The Common Vulnerabilities and Exposures project identifies the
following problems:
Daniel Roethlisberger discovered two buffer overflows in the cm4040
    driver for the Omnikey CardMan 4040 device. A local user or malicious
    device could exploit this to execute arbitrary code in kernel space.
Santosh Eraniose reported a vulnerability that allows local users to read
    otherwise unreadable files by triggering a core dump while using PT_INTERP.
    This is related to &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1073">CVE-2004-1073&lt;/a>.
Jean Delvare reported a vulnerability in the appletalk subsystem.
    Systems with the appletalk module loaded can be triggered to crash
    by other systems on the local network via a malformed frame.
Masayuki Nakagawa discovered that flow labels were inadvertently
    being shared between listening sockets and child sockets. This defect
    can be exploited by local users to cause a DoS (Oops).
This problem has been fixed in the stable distribution in version 
2.6.18.dfsg.1-12etch1.
The following matrix lists additional packages that were rebuilt for
compatibility with or to take advantage of this update:
We recommend that you upgrade your kernel package immediately and reboot
the machine. If you have built a custom kernel from the kernel source
package, you will need to rebuild to take advantage of these fixes.
Updated packages for the mips and mipsel architectures are not yet available.
They will be provided later.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='linux-patch-debian-2.6.18 DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:517'/>
              <criterion comment='linux-support-2.6.18-4 DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:518'/>
              <criterion comment='linux-source-2.6.18 DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:519'/>
              <criterion comment='linux-manual-2.6.18 DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:520'/>
              <criterion comment='linux-tree-2.6.18 DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:521'/>
              <criterion comment='linux-doc-2.6.18 DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:522'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='linux-headers-2.6.18-4-s390 DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:523'/>
              <criterion comment='linux-image-2.6.18-4-s390 DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:524'/>
              <criterion comment='linux-image-2.6.18-4-s390-tape DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:525'/>
              <criterion comment='linux-headers-2.6.18-4-s390x DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:526'/>
              <criterion comment='linux-image-2.6.18-4-vserver-s390x DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:527'/>
              <criterion comment='linux-headers-2.6.18-4-all DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:528'/>
              <criterion comment='linux-headers-2.6.18-4-all-s390 DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:529'/>
              <criterion comment='linux-headers-2.6.18-4 DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:530'/>
              <criterion comment='linux-headers-2.6.18-4-vserver-s390x DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:531'/>
              <criterion comment='linux-headers-2.6.18-4-vserver DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:532'/>
              <criterion comment='linux-image-2.6.18-4-s390x DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:533'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='linux-headers-2.6.18-4-xen DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:534'/>
              <criterion comment='linux-image-2.6.18-4-vserver-amd64 DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:535'/>
              <criterion comment='linux-headers-2.6.18-4-vserver-amd64 DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:536'/>
              <criterion comment='linux-headers-2.6.18-4-xen-vserver-amd64 DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:537'/>
              <criterion comment='fai-kernels DPKG is earlier than 1.17etch1' test_ref='oval:org.debian.oval:tst:538'/>
              <criterion comment='linux-headers-2.6.18-4-xen-amd64 DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:539'/>
              <criterion comment='linux-image-2.6.18-4-xen-amd64 DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:540'/>
              <criterion comment='linux-image-2.6.18-4-xen-vserver-amd64 DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:541'/>
              <criterion comment='linux-headers-2.6.18-4-xen-vserver DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:542'/>
              <criterion comment='linux-modules-2.6.18-4-xen-amd64 DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:543'/>
              <criterion comment='xen-linux-system-2.6.18-4-xen-amd64 DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:544'/>
              <criterion comment='linux-headers-2.6.18-4-all DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:545'/>
              <criterion comment='linux-headers-2.6.18-4-all-amd64 DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:546'/>
              <criterion comment='linux-image-2.6.18-4-amd64 DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:547'/>
              <criterion comment='xen-linux-system-2.6.18-4-xen-vserver-amd64 DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:548'/>
              <criterion comment='linux-headers-2.6.18-4 DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:549'/>
              <criterion comment='linux-headers-2.6.18-4-amd64 DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:550'/>
              <criterion comment='linux-headers-2.6.18-4-vserver DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:551'/>
              <criterion comment='linux-modules-2.6.18-4-xen-vserver-amd64 DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:552'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported platform section' operator='AND'>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='linux-image-2.6.18-4-parisc-smp DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:646'/>
                <criterion comment='linux-image-2.6.18-4-parisc64-smp DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:647'/>
                <criterion comment='linux-image-2.6.18-4-parisc DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:648'/>
                <criterion comment='linux-headers-2.6.18-4-parisc-smp DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:649'/>
                <criterion comment='linux-headers-2.6.18-4-parisc64 DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:650'/>
                <criterion comment='linux-image-2.6.18-4-parisc64 DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:651'/>
                <criterion comment='linux-headers-2.6.18-4-all DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:652'/>
                <criterion comment='linux-headers-2.6.18-4-parisc64-smp DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:653'/>
                <criterion comment='linux-headers-2.6.18-4-parisc DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:654'/>
                <criterion comment='linux-headers-2.6.18-4-all-hppa DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:655'/>
                <criterion comment='linux-headers-2.6.18-4 DPKG is earlier than 2.6.18.dfsg.1-12etch1' test_ref='oval:org.debian.oval:tst:656'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1287' class='vulnerability'>
      <metadata>
        <title>multiple vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>ldap-account-manager</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-7191' ref_id='CVE-2006-7191'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1840' ref_id='CVE-2007-1840'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-05-07</date>
          <moreinfo>
Two vulnerabilities have been identified in the version of
ldap-account-manager shipped with Debian 3.1 (sarge).
An untrusted PATH vulnerability could allow a local attacker to execute
    arbitrary code with elevated privileges by providing a malicious rm
    executable and specifying a PATH environment variable referencing this
    executable.
Improper escaping of HTML content could allow an attacker to execute a
    cross-site scripting attack (XSS) and execute arbitrary code in the
    victim's browser in the security context of the affected web site.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criterion comment='ldap-account-manager DPKG is earlier than 0.4.9-2sarge1' test_ref='oval:org.debian.oval:tst:657'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1288' class='vulnerability'>
      <metadata>
        <title>programming error</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>pptpd</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0244' ref_id='CVE-2007-0244'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-05-08</date>
          <moreinfo>
It was discovered that the PoPToP Point to Point Tunneling Server
contains a programming error, which allows the tear-down of a PPTP
connection through a malformed GRE packet, resulting in denial of
service.
The oldstable distribution (sarge) is not affected by this problem.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='bcrelay DPKG is earlier than 1.3.0-2etch1' test_ref='oval:org.debian.oval:tst:658'/>
            <criterion comment='pptpd DPKG is earlier than 1.3.0-2etch1' test_ref='oval:org.debian.oval:tst:659'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1289' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>linux-2.6</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1496' ref_id='CVE-2007-1496'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1497' ref_id='CVE-2007-1497'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1861' ref_id='CVE-2007-1861'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-05-13</date>
          <moreinfo>
Several local and remote vulnerabilities have been discovered in the Linux
kernel that may lead to a denial of service or the execution of arbitrary
code. The Common Vulnerabilities and Exposures project identifies the
following problems:
Michal Miroslaw reported a DoS vulnerability (crash) in netfilter.
    A remote attacker can cause a NULL pointer dereference in the
    nfnetlink_log function.
Patrick McHardy reported an vulnerability in netfilter that may
    allow attackers to bypass certain firewall rules. The nfctinfo
    value of reassembled IPv6 packet fragments were incorrectly initialized
    to 0 which allowed these packets to become tracked as ESTABLISHED.
Jaco Kroon reported a bug in which NETLINK_FIB_LOOKUP packages were
    incorrectly routed back to the kernel resulting in an infinite
    recursion condition. Local users can exploit this behavior
    to cause a DoS (crash).</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='linux-patch-debian-2.6.18 DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:660'/>
              <criterion comment='linux-support-2.6.18-4 DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:661'/>
              <criterion comment='linux-source-2.6.18 DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:662'/>
              <criterion comment='linux-manual-2.6.18 DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:663'/>
              <criterion comment='kernel-patch-openvz DPKG is earlier than 028.18.1etch1' test_ref='oval:org.debian.oval:tst:664'/>
              <criterion comment='linux-tree-2.6.18 DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:665'/>
              <criterion comment='linux-doc-2.6.18 DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:666'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='linux-headers-2.6.18-4-s390 DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:667'/>
              <criterion comment='linux-image-2.6.18-4-s390 DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:668'/>
              <criterion comment='linux-image-2.6.18-4-s390-tape DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:669'/>
              <criterion comment='linux-headers-2.6.18-4-s390x DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:670'/>
              <criterion comment='linux-image-2.6.18-4-vserver-s390x DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:671'/>
              <criterion comment='linux-headers-2.6.18-4-all DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:672'/>
              <criterion comment='linux-headers-2.6.18-4-all-s390 DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:673'/>
              <criterion comment='linux-headers-2.6.18-4 DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:674'/>
              <criterion comment='linux-headers-2.6.18-4-vserver-s390x DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:675'/>
              <criterion comment='linux-headers-2.6.18-4-vserver DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:676'/>
              <criterion comment='linux-image-2.6.18-4-s390x DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:677'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='linux-headers-2.6.18-4-xen DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:678'/>
              <criterion comment='linux-image-2.6.18-4-vserver-amd64 DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:679'/>
              <criterion comment='linux-headers-2.6.18-4-vserver-amd64 DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:680'/>
              <criterion comment='linux-headers-2.6.18-4-xen-vserver-amd64 DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:681'/>
              <criterion comment='fai-kernels DPKG is earlier than 1.17+etch2' test_ref='oval:org.debian.oval:tst:682'/>
              <criterion comment='linux-headers-2.6.18-4-xen-amd64 DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:683'/>
              <criterion comment='linux-image-2.6.18-4-xen-amd64 DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:684'/>
              <criterion comment='linux-image-2.6.18-4-xen-vserver-amd64 DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:685'/>
              <criterion comment='linux-headers-2.6.18-4-xen-vserver DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:686'/>
              <criterion comment='linux-modules-2.6.18-4-xen-amd64 DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:687'/>
              <criterion comment='xen-linux-system-2.6.18-4-xen-amd64 DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:688'/>
              <criterion comment='linux-headers-2.6.18-4-all DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:689'/>
              <criterion comment='linux-headers-2.6.18-4-all-amd64 DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:690'/>
              <criterion comment='linux-image-2.6.18-4-amd64 DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:691'/>
              <criterion comment='xen-linux-system-2.6.18-4-xen-vserver-amd64 DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:692'/>
              <criterion comment='linux-headers-2.6.18-4 DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:693'/>
              <criterion comment='linux-headers-2.6.18-4-amd64 DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:694'/>
              <criterion comment='linux-headers-2.6.18-4-vserver DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:695'/>
              <criterion comment='linux-modules-2.6.18-4-xen-vserver-amd64 DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:696'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported platform section' operator='AND'>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='linux-image-2.6.18-4-parisc-smp DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:818'/>
                <criterion comment='linux-image-2.6.18-4-parisc64-smp DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:819'/>
                <criterion comment='linux-image-2.6.18-4-parisc DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:820'/>
                <criterion comment='linux-headers-2.6.18-4-parisc-smp DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:821'/>
                <criterion comment='linux-headers-2.6.18-4-parisc64 DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:822'/>
                <criterion comment='linux-image-2.6.18-4-parisc64 DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:823'/>
                <criterion comment='linux-headers-2.6.18-4-all DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:824'/>
                <criterion comment='linux-headers-2.6.18-4-parisc64-smp DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:825'/>
                <criterion comment='linux-headers-2.6.18-4-parisc DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:826'/>
                <criterion comment='linux-headers-2.6.18-4-all-hppa DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:827'/>
                <criterion comment='linux-headers-2.6.18-4 DPKG is earlier than 2.6.18.dfsg.1-12etch2' test_ref='oval:org.debian.oval:tst:828'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1290' class='vulnerability'>
      <metadata>
        <title>missing input sanitising</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>squirrelmail</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1262' ref_id='CVE-2007-1262'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-05-13</date>
          <moreinfo>
It was discovered that the webmail package Squirrelmail performs
insufficient sanitising inside the HTML filter, which allows the
injection of arbitrary web script code during the display of HTML
email messages.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
              <criterion comment='squirrelmail DPKG is earlier than 1.4.9a-2' test_ref='oval:org.debian.oval:tst:829'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
              <criterion comment='squirrelmail DPKG is earlier than 1.4.4-11' test_ref='oval:org.debian.oval:tst:830'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1291' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>samba</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2444' ref_id='CVE-2007-2444'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2446' ref_id='CVE-2007-2446'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2447' ref_id='CVE-2007-2447'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-05-15</date>
          <moreinfo>
Several issues have been identified in Samba, the SMB/CIFS
file- and print-server implementation for GNU/Linux.
When translating SIDs to/from names using Samba local list of user and
    group accounts, a logic error in the smbd daemon's internal security
    stack may result in a transition to the root user id rather than the
    non-root user.  The user is then able to temporarily issue SMB/CIFS
    protocol operations as the root user.  This window of opportunity may
    allow the attacker to establish addition means of gaining root access to
    the server.
Various bugs in Samba's NDR parsing can allow a user to send specially
    crafted MS-RPC requests that will overwrite the heap space with user
    defined data.
Unescaped user input parameters are passed as arguments to /bin/sh
    allowing for remote command execution.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='samba-doc DPKG is earlier than 3.0.24-6etch1' test_ref='oval:org.debian.oval:tst:831'/>
              <criterion comment='samba-doc-pdf DPKG is earlier than 3.0.24-6etch1' test_ref='oval:org.debian.oval:tst:832'/>
            </criteria>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='smbfs DPKG is earlier than 3.0.24-6etch1' test_ref='oval:org.debian.oval:tst:833'/>
            <criterion comment='samba DPKG is earlier than 3.0.24-6etch1' test_ref='oval:org.debian.oval:tst:834'/>
            <criterion comment='libsmbclient DPKG is earlier than 3.0.24-6etch1' test_ref='oval:org.debian.oval:tst:835'/>
            <criterion comment='smbclient DPKG is earlier than 3.0.24-6etch1' test_ref='oval:org.debian.oval:tst:836'/>
            <criterion comment='winbind DPKG is earlier than 3.0.24-6etch1' test_ref='oval:org.debian.oval:tst:837'/>
            <criterion comment='swat DPKG is earlier than 3.0.24-6etch1' test_ref='oval:org.debian.oval:tst:838'/>
            <criterion comment='samba-dbg DPKG is earlier than 3.0.24-6etch1' test_ref='oval:org.debian.oval:tst:839'/>
            <criterion comment='libsmbclient-dev DPKG is earlier than 3.0.24-6etch1' test_ref='oval:org.debian.oval:tst:840'/>
            <criterion comment='python-samba DPKG is earlier than 3.0.24-6etch1' test_ref='oval:org.debian.oval:tst:841'/>
            <criterion comment='samba-common DPKG is earlier than 3.0.24-6etch1' test_ref='oval:org.debian.oval:tst:842'/>
            <criterion comment='libpam-smbpass DPKG is earlier than 3.0.24-6etch1' test_ref='oval:org.debian.oval:tst:843'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1292' class='vulnerability'>
      <metadata>
        <title>missing input validation</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>qt4-x11</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0242' ref_id='CVE-2007-0242'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-05-15</date>
          <moreinfo>
Andreas Nolden discovered a bug in the UTF8 decoding routines in
qt4-x11, a C++ GUI library framework, that could allow remote
attackers to conduct cross-site scripting (XSS) and directory
traversal attacks via long sequences that decode to dangerous
metacharacters.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criterion comment='qt4-doc DPKG is earlier than 4.2.1-2etch1' test_ref='oval:org.debian.oval:tst:844'/>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:66'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='qt4-dev-tools DPKG is earlier than 4.2.1-2etch1' test_ref='oval:org.debian.oval:tst:845'/>
              <criterion comment='libqt4-core DPKG is earlier than 4.2.1-2etch1' test_ref='oval:org.debian.oval:tst:846'/>
              <criterion comment='libqt4-debug DPKG is earlier than 4.2.1-2etch1' test_ref='oval:org.debian.oval:tst:847'/>
              <criterion comment='libqt4-dev DPKG is earlier than 4.2.1-2etch1' test_ref='oval:org.debian.oval:tst:848'/>
              <criterion comment='qt4-qtconfig DPKG is earlier than 4.2.1-2etch1' test_ref='oval:org.debian.oval:tst:849'/>
              <criterion comment='qt4-designer DPKG is earlier than 4.2.1-2etch1' test_ref='oval:org.debian.oval:tst:850'/>
              <criterion comment='libqt4-gui DPKG is earlier than 4.2.1-2etch1' test_ref='oval:org.debian.oval:tst:851'/>
              <criterion comment='libqt4-qt3support DPKG is earlier than 4.2.1-2etch1' test_ref='oval:org.debian.oval:tst:852'/>
              <criterion comment='libqt4-sql DPKG is earlier than 4.2.1-2etch1' test_ref='oval:org.debian.oval:tst:853'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1293' class='vulnerability'>
      <metadata>
        <title>out of boundary read</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>quagga</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1995' ref_id='CVE-2007-1995'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-05-17</date>
          <moreinfo>
Paul Jakma discovered that specially crafted UPDATE messages can
trigger an out of boundary read that can result in a system crash of
quagga, the BGP/OSPF/RIP routing daemon.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
              <criterion comment='quagga-doc DPKG is earlier than 0.99.5-5etch2' test_ref='oval:org.debian.oval:tst:854'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='quagga DPKG is earlier than 0.99.5-5etch2' test_ref='oval:org.debian.oval:tst:855'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
              <criterion comment='quagga-doc DPKG is earlier than 0.98.3-7.4' test_ref='oval:org.debian.oval:tst:856'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='quagga DPKG is earlier than 0.98.3-7.4' test_ref='oval:org.debian.oval:tst:857'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1294' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>xfree86</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1003' ref_id='CVE-2007-1003'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1351' ref_id='CVE-2007-1351'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1352' ref_id='CVE-2007-1352'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1667' ref_id='CVE-2007-1667'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-05-17</date>
          <moreinfo>
Several vulnerabilities have been discovered in the X Window System,
which may lead to privilege escalation. The Common Vulnerabilities and
Exposures project identifies the following problems:
Sean Larsson discovered an integer overflow in the XC-MISC extension,
    which might lead to denial of service or local privilege escalation.
Greg MacManus discovered an integer overflow in the font handling,
    which might lead to denial of service or local privilege escalation.
Greg MacManus discovered an integer overflow in the font handling,
    which might lead to denial of service or local privilege escalation.
Sami Leides discovered an integer overflow in the libx11 library
    which might lead to the execution of arbitrary code.
    This update introduces tighter sanity checking of input passed to
    XCreateImage(). To cope with this an updated rdesktop package is
    delivered along with this security update. Another application
    reported to break is the proprietary Opera browser, which isn't
    part of Debian. The vendor has released updated packages, though.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='xfonts-base-transcoded DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:858'/>
              <criterion comment='pm-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:859'/>
              <criterion comment='x-window-system DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:860'/>
              <criterion comment='xlibs-data DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:861'/>
              <criterion comment='xfonts-100dpi DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:862'/>
              <criterion comment='xspecs DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:863'/>
              <criterion comment='xfonts-cyrillic DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:864'/>
              <criterion comment='xfonts-75dpi DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:865'/>
              <criterion comment='xfree86-common DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:866'/>
              <criterion comment='xfonts-scalable DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:867'/>
              <criterion comment='xfonts-base DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:868'/>
              <criterion comment='xlibs-pic DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:869'/>
              <criterion comment='xlibmesa3-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:870'/>
              <criterion comment='xlibs-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:871'/>
              <criterion comment='xfonts-100dpi-transcoded DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:872'/>
              <criterion comment='xlibmesa-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:873'/>
              <criterion comment='xlibs-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:874'/>
              <criterion comment='xlibs DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:875'/>
              <criterion comment='xfonts-75dpi-transcoded DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:876'/>
              <criterion comment='x-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:877'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:63'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:66'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libxtrap-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:878'/>
              <criterion comment='libxt-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:879'/>
              <criterion comment='libdps1-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:880'/>
              <criterion comment='libdps1 DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:881'/>
              <criterion comment='libxext6 DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:882'/>
              <criterion comment='libxi-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:883'/>
              <criterion comment='libxtst6 DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:884'/>
              <criterion comment='libxmuu1 DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:885'/>
              <criterion comment='libxv-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:886'/>
              <criterion comment='twm DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:887'/>
              <criterion comment='rdesktop DPKG is earlier than 1.4.0-2sarge1' test_ref='oval:org.debian.oval:tst:888'/>
              <criterion comment='libice6 DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:889'/>
              <criterion comment='libxtst6-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:890'/>
              <criterion comment='xfs DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:891'/>
              <criterion comment='libice6-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:892'/>
              <criterion comment='libsm6 DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:893'/>
              <criterion comment='libxp6-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:894'/>
              <criterion comment='libxaw6-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:895'/>
              <criterion comment='libxtrap6-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:896'/>
              <criterion comment='libxaw6 DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:897'/>
              <criterion comment='libxaw7 DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:898'/>
              <criterion comment='xfwp DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:899'/>
              <criterion comment='xmh DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:900'/>
              <criterion comment='libxpm4 DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:901'/>
              <criterion comment='libsm-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:902'/>
              <criterion comment='libxtrap6 DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:903'/>
              <criterion comment='xutils DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:904'/>
              <criterion comment='libxpm-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:905'/>
              <criterion comment='xnest DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:906'/>
              <criterion comment='libxi6 DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:907'/>
              <criterion comment='libxaw6-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:908'/>
              <criterion comment='libxaw7-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:909'/>
              <criterion comment='libxrandr2-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:910'/>
              <criterion comment='libxmuu1-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:911'/>
              <criterion comment='proxymngr DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:912'/>
              <criterion comment='xlibmesa-glu-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:913'/>
              <criterion comment='libx11-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:914'/>
              <criterion comment='xserver-common DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:915'/>
              <criterion comment='libx11-6 DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:916'/>
              <criterion comment='libxrandr2 DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:917'/>
              <criterion comment='xlibs-static-pic DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:918'/>
              <criterion comment='libxext-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:919'/>
              <criterion comment='libice-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:920'/>
              <criterion comment='xbase-clients DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:921'/>
              <criterion comment='libxft1 DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:922'/>
              <criterion comment='xdm DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:923'/>
              <criterion comment='xterm DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:924'/>
              <criterion comment='libxext6-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:925'/>
              <criterion comment='x-window-system-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:926'/>
              <criterion comment='libx11-6-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:927'/>
              <criterion comment='libxmu6 DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:928'/>
              <criterion comment='libxaw7-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:929'/>
              <criterion comment='libdps-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:930'/>
              <criterion comment='libsm6-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:931'/>
              <criterion comment='xlibmesa-glu DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:932'/>
              <criterion comment='xlibmesa3 DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:933'/>
              <criterion comment='libxtst-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:934'/>
              <criterion comment='libxmu-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:935'/>
              <criterion comment='libxt6-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:936'/>
              <criterion comment='libxt6 DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:937'/>
              <criterion comment='libxmu6-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:938'/>
              <criterion comment='libxp-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:939'/>
              <criterion comment='xlibs-static-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:940'/>
              <criterion comment='libxpm4-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:941'/>
              <criterion comment='xvfb DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:942'/>
              <criterion comment='libxv1 DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:943'/>
              <criterion comment='libxp6 DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:944'/>
              <criterion comment='xlibmesa-gl-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:945'/>
              <criterion comment='libxmuu-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:946'/>
              <criterion comment='libxv1-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:947'/>
              <criterion comment='lbxproxy DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:948'/>
              <criterion comment='libxft1-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:949'/>
              <criterion comment='xlibmesa-gl-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:950'/>
              <criterion comment='libxi6-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:951'/>
              <criterion comment='libxrandr-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:952'/>
              <criterion comment='xlibmesa-glu-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:953'/>
              <criterion comment='xlibmesa-gl DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:954'/>
              <criterion comment='x-window-system-core DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:955'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='xlibosmesa-dev DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:956'/>
              <criterion comment='xlibmesa-dri DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:957'/>
              <criterion comment='xlibosmesa4 DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:958'/>
              <criterion comment='xserver-xfree86 DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:959'/>
              <criterion comment='xlibmesa-dri-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:960'/>
              <criterion comment='xserver-xfree86-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:961'/>
              <criterion comment='xlibosmesa4-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:962'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported platform section' operator='AND'>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='xserver-xfree86-dbg DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:1056'/>
                <criterion comment='xserver-xfree86 DPKG is earlier than 4.3.0.dfsg.1-14sarge4' test_ref='oval:org.debian.oval:tst:1057'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1295' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>php5</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2509' ref_id='CVE-2007-2509'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2510' ref_id='CVE-2007-2510'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-05-19</date>
          <moreinfo>
Several remote vulnerabilities have been discovered in PHP, a
server-side, HTML-embedded scripting language, which may lead to the
execution of arbitrary code. The Common Vulnerabilities and Exposures
project identifies the following problems:
It was discovered that missing input sanitising inside the ftp
    extension permits an attacker to execute arbitrary FTP commands.
    This requires the attacker to already have access to the FTP
    server.
It was discovered that a buffer overflow in the SOAP extension permits
    the execution of arbitrary code.
The oldstable distribution (sarge) doesn't include php5.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='php-pear DPKG is earlier than 5.2.0-8+etch4' test_ref='oval:org.debian.oval:tst:1058'/>
              <criterion comment='php5 DPKG is earlier than 5.2.0-8+etch4' test_ref='oval:org.debian.oval:tst:1059'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:66'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libapache-mod-php5 DPKG is earlier than 5.2.0-8+etch4' test_ref='oval:org.debian.oval:tst:1060'/>
              <criterion comment='php5-recode DPKG is earlier than 5.2.0-8+etch4' test_ref='oval:org.debian.oval:tst:1061'/>
              <criterion comment='php5-cgi DPKG is earlier than 5.2.0-8+etch4' test_ref='oval:org.debian.oval:tst:1062'/>
              <criterion comment='php5-curl DPKG is earlier than 5.2.0-8+etch4' test_ref='oval:org.debian.oval:tst:1063'/>
              <criterion comment='php5-snmp DPKG is earlier than 5.2.0-8+etch4' test_ref='oval:org.debian.oval:tst:1064'/>
              <criterion comment='php5-mysql DPKG is earlier than 5.2.0-8+etch4' test_ref='oval:org.debian.oval:tst:1065'/>
              <criterion comment='php5-odbc DPKG is earlier than 5.2.0-8+etch4' test_ref='oval:org.debian.oval:tst:1066'/>
              <criterion comment='php5-xsl DPKG is earlier than 5.2.0-8+etch4' test_ref='oval:org.debian.oval:tst:1067'/>
              <criterion comment='php5-gd DPKG is earlier than 5.2.0-8+etch4' test_ref='oval:org.debian.oval:tst:1068'/>
              <criterion comment='libapache2-mod-php5 DPKG is earlier than 5.2.0-8+etch4' test_ref='oval:org.debian.oval:tst:1069'/>
              <criterion comment='php5-mhash DPKG is earlier than 5.2.0-8+etch4' test_ref='oval:org.debian.oval:tst:1070'/>
              <criterion comment='php5-tidy DPKG is earlier than 5.2.0-8+etch4' test_ref='oval:org.debian.oval:tst:1071'/>
              <criterion comment='php5-mcrypt DPKG is earlier than 5.2.0-8+etch4' test_ref='oval:org.debian.oval:tst:1072'/>
              <criterion comment='php5-dev DPKG is earlier than 5.2.0-8+etch4' test_ref='oval:org.debian.oval:tst:1073'/>
              <criterion comment='php5-pgsql DPKG is earlier than 5.2.0-8+etch4' test_ref='oval:org.debian.oval:tst:1074'/>
              <criterion comment='php5-xmlrpc DPKG is earlier than 5.2.0-8+etch4' test_ref='oval:org.debian.oval:tst:1075'/>
              <criterion comment='php5-imap DPKG is earlier than 5.2.0-8+etch4' test_ref='oval:org.debian.oval:tst:1076'/>
              <criterion comment='php5-sqlite DPKG is earlier than 5.2.0-8+etch4' test_ref='oval:org.debian.oval:tst:1077'/>
              <criterion comment='php5-ldap DPKG is earlier than 5.2.0-8+etch4' test_ref='oval:org.debian.oval:tst:1078'/>
              <criterion comment='php5-cli DPKG is earlier than 5.2.0-8+etch4' test_ref='oval:org.debian.oval:tst:1079'/>
              <criterion comment='php5-sybase DPKG is earlier than 5.2.0-8+etch4' test_ref='oval:org.debian.oval:tst:1080'/>
              <criterion comment='php5-pspell DPKG is earlier than 5.2.0-8+etch4' test_ref='oval:org.debian.oval:tst:1081'/>
              <criterion comment='php5-common DPKG is earlier than 5.2.0-8+etch4' test_ref='oval:org.debian.oval:tst:1082'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='php5-interbase DPKG is earlier than 5.2.0-8+etch4' test_ref='oval:org.debian.oval:tst:1083'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1296' class='vulnerability'>
      <metadata>
        <title>missing input sanitising</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>php4</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2509' ref_id='CVE-2007-2509'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-05-21</date>
          <moreinfo>
It was discovered that the ftp extension of PHP, a server-side,
HTML-embedded scripting language performs insufficient input sanitising,
which permits an attacker to execute arbitrary FTP commands. This
requires the attacker to already have access to the FTP server.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='php4 DPKG is earlier than 4.4.4-8+etch3' test_ref='oval:org.debian.oval:tst:1084'/>
                <criterion comment='php4-pear DPKG is earlier than 4.4.4-8+etch3' test_ref='oval:org.debian.oval:tst:1085'/>
              </criteria>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
                <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
                <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
                <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:66'/>
                <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
                <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
                <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
                <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='libapache-mod-php4 DPKG is earlier than 4.4.4-8+etch3' test_ref='oval:org.debian.oval:tst:1086'/>
                <criterion comment='php4-recode DPKG is earlier than 4.4.4-8+etch3' test_ref='oval:org.debian.oval:tst:1087'/>
                <criterion comment='php4-xslt DPKG is earlier than 4.4.4-8+etch3' test_ref='oval:org.debian.oval:tst:1088'/>
                <criterion comment='php4-mcal DPKG is earlier than 4.4.4-8+etch3' test_ref='oval:org.debian.oval:tst:1089'/>
                <criterion comment='php4-domxml DPKG is earlier than 4.4.4-8+etch3' test_ref='oval:org.debian.oval:tst:1090'/>
                <criterion comment='php4-mhash DPKG is earlier than 4.4.4-8+etch3' test_ref='oval:org.debian.oval:tst:1091'/>
                <criterion comment='php4-odbc DPKG is earlier than 4.4.4-8+etch3' test_ref='oval:org.debian.oval:tst:1092'/>
                <criterion comment='libapache2-mod-php4 DPKG is earlier than 4.4.4-8+etch3' test_ref='oval:org.debian.oval:tst:1093'/>
                <criterion comment='php4-cli DPKG is earlier than 4.4.4-8+etch3' test_ref='oval:org.debian.oval:tst:1094'/>
                <criterion comment='php4-mcrypt DPKG is earlier than 4.4.4-8+etch3' test_ref='oval:org.debian.oval:tst:1095'/>
                <criterion comment='php4-gd DPKG is earlier than 4.4.4-8+etch3' test_ref='oval:org.debian.oval:tst:1096'/>
                <criterion comment='php4-mysql DPKG is earlier than 4.4.4-8+etch3' test_ref='oval:org.debian.oval:tst:1097'/>
                <criterion comment='php4-imap DPKG is earlier than 4.4.4-8+etch3' test_ref='oval:org.debian.oval:tst:1098'/>
                <criterion comment='php4-cgi DPKG is earlier than 4.4.4-8+etch3' test_ref='oval:org.debian.oval:tst:1099'/>
                <criterion comment='php4-pgsql DPKG is earlier than 4.4.4-8+etch3' test_ref='oval:org.debian.oval:tst:1100'/>
                <criterion comment='php4-snmp DPKG is earlier than 4.4.4-8+etch3' test_ref='oval:org.debian.oval:tst:1101'/>
                <criterion comment='php4-dev DPKG is earlier than 4.4.4-8+etch3' test_ref='oval:org.debian.oval:tst:1102'/>
                <criterion comment='php4-pspell DPKG is earlier than 4.4.4-8+etch3' test_ref='oval:org.debian.oval:tst:1103'/>
                <criterion comment='php4-ldap DPKG is earlier than 4.4.4-8+etch3' test_ref='oval:org.debian.oval:tst:1104'/>
                <criterion comment='php4-common DPKG is earlier than 4.4.4-8+etch3' test_ref='oval:org.debian.oval:tst:1105'/>
                <criterion comment='php4-curl DPKG is earlier than 4.4.4-8+etch3' test_ref='oval:org.debian.oval:tst:1106'/>
                <criterion comment='php4-sybase DPKG is earlier than 4.4.4-8+etch3' test_ref='oval:org.debian.oval:tst:1107'/>
              </criteria>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
                <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='php4-interbase DPKG is earlier than 4.4.4-8+etch3' test_ref='oval:org.debian.oval:tst:1108'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='php4 DPKG is earlier than 4.3.10-21' test_ref='oval:org.debian.oval:tst:1109'/>
                <criterion comment='php4-pear DPKG is earlier than 4.3.10-21' test_ref='oval:org.debian.oval:tst:1110'/>
              </criteria>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
                <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
                <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:63'/>
                <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
                <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:66'/>
                <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
                <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
                <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
                <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='php4-sybase DPKG is earlier than 4.3.10-21' test_ref='oval:org.debian.oval:tst:1111'/>
                <criterion comment='libapache-mod-php4 DPKG is earlier than 4.3.10-21' test_ref='oval:org.debian.oval:tst:1112'/>
                <criterion comment='php4-odbc DPKG is earlier than 4.3.10-21' test_ref='oval:org.debian.oval:tst:1113'/>
                <criterion comment='php4-dev DPKG is earlier than 4.3.10-21' test_ref='oval:org.debian.oval:tst:1114'/>
                <criterion comment='php4-recode DPKG is earlier than 4.3.10-21' test_ref='oval:org.debian.oval:tst:1115'/>
                <criterion comment='php4-gd DPKG is earlier than 4.3.10-21' test_ref='oval:org.debian.oval:tst:1116'/>
                <criterion comment='php4-xslt DPKG is earlier than 4.3.10-21' test_ref='oval:org.debian.oval:tst:1117'/>
                <criterion comment='php4-ldap DPKG is earlier than 4.3.10-21' test_ref='oval:org.debian.oval:tst:1118'/>
                <criterion comment='php4-snmp DPKG is earlier than 4.3.10-21' test_ref='oval:org.debian.oval:tst:1119'/>
                <criterion comment='php4-mysql DPKG is earlier than 4.3.10-21' test_ref='oval:org.debian.oval:tst:1120'/>
                <criterion comment='php4-mcal DPKG is earlier than 4.3.10-21' test_ref='oval:org.debian.oval:tst:1121'/>
                <criterion comment='php4-cli DPKG is earlier than 4.3.10-21' test_ref='oval:org.debian.oval:tst:1122'/>
                <criterion comment='php4-common DPKG is earlier than 4.3.10-21' test_ref='oval:org.debian.oval:tst:1123'/>
                <criterion comment='php4-mhash DPKG is earlier than 4.3.10-21' test_ref='oval:org.debian.oval:tst:1124'/>
                <criterion comment='php4-imap DPKG is earlier than 4.3.10-21' test_ref='oval:org.debian.oval:tst:1125'/>
                <criterion comment='libapache2-mod-php4 DPKG is earlier than 4.3.10-21' test_ref='oval:org.debian.oval:tst:1126'/>
                <criterion comment='php4-cgi DPKG is earlier than 4.3.10-21' test_ref='oval:org.debian.oval:tst:1127'/>
                <criterion comment='php4-curl DPKG is earlier than 4.3.10-21' test_ref='oval:org.debian.oval:tst:1128'/>
                <criterion comment='php4-domxml DPKG is earlier than 4.3.10-21' test_ref='oval:org.debian.oval:tst:1129'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1297' class='vulnerability'>
      <metadata>
        <title>missing input sanitising</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>gforge-plugin-scmcvs</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0246' ref_id='CVE-2007-0246'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-05-24</date>
          <moreinfo>
Bernhard R. Link discovered that the CVS browsing interface of Gforge, a
collaborative development tool, performs insufficient escaping of URLs,
which allows the execution of arbitrary shell commands with the privileges
of the www-data user.
The oldstable distribution (sarge) is not affected by this problem.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criterion comment='gforge-plugin-scmcvs DPKG is earlier than 4.5.14-5etch1' test_ref='oval:org.debian.oval:tst:1130'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1298' class='vulnerability'>
      <metadata>
        <title>missing input sanitising</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>otrs2</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2524' ref_id='CVE-2007-2524'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-05-28</date>
          <moreinfo>
It was discovered that the Open Ticket Request System performs
insufficient input sanitising for the Subaction parameter, which allows
the injection of arbitrary web script code.
The oldstable distribution (sarge) doesn't include otrs2.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criterion comment='otrs2 DPKG is earlier than 2.0.4p01-18' test_ref='oval:org.debian.oval:tst:1131'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1299' class='vulnerability'>
      <metadata>
        <title>missing input sanitising</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>ipsec-tools</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1841' ref_id='CVE-2007-1841'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-06-07</date>
          <moreinfo>
It was discovered that a specially-crafted packet sent to the racoon
ipsec key exchange server could cause a tunnel to crash, resulting in
a denial of service.
The oldstable distribution (sarge) isn't affected by this problem.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='racoon DPKG is earlier than 0.6.6-3.1etch1' test_ref='oval:org.debian.oval:tst:1132'/>
            <criterion comment='ipsec-tools DPKG is earlier than 0.6.6-3.1etch1' test_ref='oval:org.debian.oval:tst:1133'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1300' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>iceape</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1362' ref_id='CVE-2007-1362'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1558' ref_id='CVE-2007-1558'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2867' ref_id='CVE-2007-2867'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2868' ref_id='CVE-2007-2868'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2870' ref_id='CVE-2007-2870'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2871' ref_id='CVE-2007-2871'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-06-07</date>
          <moreinfo>
Several remote vulnerabilities have been discovered in the Iceape internet
suite, an unbranded version of the Seamonkey Internet Suite. The Common
Vulnerabilities and Exposures project identifies the following problems:
Nicolas Derouet discovered that Iceape performs insufficient 
    validation of cookies, which could lead to denial of service.
Gatan Leurent discovered a cryptographical weakness in APOP
    authentication, which reduces the required efforts for an MITM attack
    to intercept a password. The update enforces stricter validation, which
    prevents this attack.
Boris Zbarsky, Eli Friedman, Georgi Guninski, Jesse Ruderman, Martijn
    Wargers and Olli Pettay discovered crashes in the layout engine, which
    might allow the execution of arbitrary code.
Brendan Eich, Igor Bukanov, Jesse Ruderman, &lt;q>moz_bug_r_a4&lt;/q> and Wladimir Palant
    discovered crashes in the javascript engine, which might allow the execution of
    arbitrary code.
&lt;q>moz_bug_r_a4&lt;/q> discovered that adding an event listener through the
     addEventListener() function allows cross-site scripting.
Chris Thomas discovered that XUL popups can be abused for spoofing or
    phishing attacks.
Fixes for the oldstable distribution (sarge) are not available. While there
will be another round of security updates for Mozilla products, Debian doesn't
have the resources to backport further security fixes to the old Mozilla
products. You're strongly encouraged to upgrade to stable as soon as possible.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='mozilla-calendar DPKG is earlier than 1.8+1.0.9-0etch1' test_ref='oval:org.debian.oval:tst:1134'/>
              <criterion comment='mozilla-chatzilla DPKG is earlier than 1.8+1.0.9-0etch1' test_ref='oval:org.debian.oval:tst:1135'/>
              <criterion comment='iceape DPKG is earlier than 1.0.9-0etch1' test_ref='oval:org.debian.oval:tst:1136'/>
              <criterion comment='iceape-chatzilla DPKG is earlier than 1.0.9-0etch1' test_ref='oval:org.debian.oval:tst:1137'/>
              <criterion comment='iceape-dev DPKG is earlier than 1.0.9-0etch1' test_ref='oval:org.debian.oval:tst:1138'/>
              <criterion comment='mozilla-psm DPKG is earlier than 1.8+1.0.9-0etch1' test_ref='oval:org.debian.oval:tst:1139'/>
              <criterion comment='mozilla-mailnews DPKG is earlier than 1.8+1.0.9-0etch1' test_ref='oval:org.debian.oval:tst:1140'/>
              <criterion comment='mozilla-dom-inspector DPKG is earlier than 1.8+1.0.9-0etch1' test_ref='oval:org.debian.oval:tst:1141'/>
              <criterion comment='mozilla-js-debugger DPKG is earlier than 1.8+1.0.9-0etch1' test_ref='oval:org.debian.oval:tst:1142'/>
              <criterion comment='mozilla-browser DPKG is earlier than 1.8+1.0.9-0etch1' test_ref='oval:org.debian.oval:tst:1143'/>
              <criterion comment='mozilla-dev DPKG is earlier than 1.8+1.0.9-0etch1' test_ref='oval:org.debian.oval:tst:1144'/>
              <criterion comment='mozilla DPKG is earlier than 1.8+1.0.9-0etch1' test_ref='oval:org.debian.oval:tst:1145'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:66'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='iceape-dbg DPKG is earlier than 1.0.9-0etch1' test_ref='oval:org.debian.oval:tst:1146'/>
              <criterion comment='iceape-dom-inspector DPKG is earlier than 1.0.9-0etch1' test_ref='oval:org.debian.oval:tst:1147'/>
              <criterion comment='iceape-mailnews DPKG is earlier than 1.0.9-0etch1' test_ref='oval:org.debian.oval:tst:1148'/>
              <criterion comment='iceape-browser DPKG is earlier than 1.0.9-0etch1' test_ref='oval:org.debian.oval:tst:1149'/>
              <criterion comment='iceape-calendar DPKG is earlier than 1.0.9-0etch1' test_ref='oval:org.debian.oval:tst:1150'/>
              <criterion comment='iceape-gnome-support DPKG is earlier than 1.0.9-0etch1' test_ref='oval:org.debian.oval:tst:1151'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1301' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>gimp</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2356' ref_id='CVE-2007-2356'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-06-09</date>
          <moreinfo>
A buffer overflow has been identified in Gimp's SUNRAS plugin in
versions prior to 2.2.15.  This bug could allow an attacker to execute
arbitrary code on the victim's computer by inducing the victim to open a
specially crafted RAS file.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='libgimp2.0-doc DPKG is earlier than 2.2.13-1etch1' test_ref='oval:org.debian.oval:tst:1152'/>
                <criterion comment='gimp-data DPKG is earlier than 2.2.13-1etch1' test_ref='oval:org.debian.oval:tst:1153'/>
              </criteria>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libgimp2.0 DPKG is earlier than 2.2.13-1etch1' test_ref='oval:org.debian.oval:tst:1154'/>
              <criterion comment='gimp-svg DPKG is earlier than 2.2.13-1etch1' test_ref='oval:org.debian.oval:tst:1155'/>
              <criterion comment='gimp-helpbrowser DPKG is earlier than 2.2.13-1etch1' test_ref='oval:org.debian.oval:tst:1156'/>
              <criterion comment='gimp-dbg DPKG is earlier than 2.2.13-1etch1' test_ref='oval:org.debian.oval:tst:1157'/>
              <criterion comment='gimp-python DPKG is earlier than 2.2.13-1etch1' test_ref='oval:org.debian.oval:tst:1158'/>
              <criterion comment='libgimp2.0-dev DPKG is earlier than 2.2.13-1etch1' test_ref='oval:org.debian.oval:tst:1159'/>
              <criterion comment='gimp DPKG is earlier than 2.2.13-1etch1' test_ref='oval:org.debian.oval:tst:1160'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='libgimp2.0-doc DPKG is earlier than 2.2.6-1sarge2' test_ref='oval:org.debian.oval:tst:1161'/>
                <criterion comment='gimp-data DPKG is earlier than 2.2.6-1sarge2' test_ref='oval:org.debian.oval:tst:1162'/>
                <criterion comment='gimp1.2 DPKG is earlier than 2.2.6-1sarge2' test_ref='oval:org.debian.oval:tst:1163'/>
              </criteria>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
                <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
                <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:63'/>
                <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
                <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:66'/>
                <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
                <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
                <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='libgimp2.0 DPKG is earlier than 2.2.6-1sarge2' test_ref='oval:org.debian.oval:tst:1164'/>
                <criterion comment='gimp-svg DPKG is earlier than 2.2.6-1sarge2' test_ref='oval:org.debian.oval:tst:1165'/>
                <criterion comment='gimp-helpbrowser DPKG is earlier than 2.2.6-1sarge2' test_ref='oval:org.debian.oval:tst:1166'/>
                <criterion comment='gimp-python DPKG is earlier than 2.2.6-1sarge2' test_ref='oval:org.debian.oval:tst:1167'/>
                <criterion comment='libgimp2.0-dev DPKG is earlier than 2.2.6-1sarge2' test_ref='oval:org.debian.oval:tst:1168'/>
                <criterion comment='gimp DPKG is earlier than 2.2.6-1sarge2' test_ref='oval:org.debian.oval:tst:1169'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1302' class='vulnerability'>
      <metadata>
        <title>integer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>freetype</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2754' ref_id='CVE-2007-2754'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-06-10</date>
          <moreinfo>
A problem was discovered in freetype, a FreeType2 font engine, which
could allow the execution of arbitrary code via an integer overflow in
specially crafted TTF files.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libfreetype6-dev DPKG is earlier than 2.2.1-5+etch1' test_ref='oval:org.debian.oval:tst:1170'/>
            <criterion comment='freetype2-demos DPKG is earlier than 2.2.1-5+etch1' test_ref='oval:org.debian.oval:tst:1171'/>
            <criterion comment='libfreetype6 DPKG is earlier than 2.2.1-5+etch1' test_ref='oval:org.debian.oval:tst:1172'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1303' class='vulnerability'>
      <metadata>
        <title>denial of service</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>lighttpd</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1870' ref_id='CVE-2007-1870'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1869' ref_id='CVE-2007-1869'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-06-10</date>
          <moreinfo>
Two problems were discovered with lighttpd, a fast webserver with
minimal memory footprint, which could allow denial of service.
The Common Vulnerabilities and Exposures project identifies the
following problems:
Remote attackers could cause denial of service by disconnecting
  partway through making a request.
A NULL pointer dereference could cause a crash when serving files
  with a mtime of 0.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criterion comment='lighttpd-doc DPKG is earlier than 1.4.13-4etch1' test_ref='oval:org.debian.oval:tst:1173'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='lighttpd-mod-mysql-vhost DPKG is earlier than 1.4.13-4etch1' test_ref='oval:org.debian.oval:tst:1174'/>
            <criterion comment='lighttpd-mod-magnet DPKG is earlier than 1.4.13-4etch1' test_ref='oval:org.debian.oval:tst:1175'/>
            <criterion comment='lighttpd DPKG is earlier than 1.4.13-4etch1' test_ref='oval:org.debian.oval:tst:1176'/>
            <criterion comment='lighttpd-mod-cml DPKG is earlier than 1.4.13-4etch1' test_ref='oval:org.debian.oval:tst:1177'/>
            <criterion comment='lighttpd-mod-webdav DPKG is earlier than 1.4.13-4etch1' test_ref='oval:org.debian.oval:tst:1178'/>
            <criterion comment='lighttpd-mod-trigger-b4-dl DPKG is earlier than 1.4.13-4etch1' test_ref='oval:org.debian.oval:tst:1179'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1304' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>kernel-source-2.6.8</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4811' ref_id='CVE-2005-4811'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4814' ref_id='CVE-2006-4814'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4623' ref_id='CVE-2006-4623'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5753' ref_id='CVE-2006-5753'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-06-16</date>
          <moreinfo>
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6060">CVE-2006-6060&lt;/a> &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6106">CVE-2006-6106&lt;/a> &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6535">CVE-2006-6535&lt;/a> &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0958">CVE-2007-0958&lt;/a>
                 &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1357">CVE-2007-1357&lt;/a> &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1592">CVE-2007-1592&lt;/a>
Several local and remote vulnerabilities have been discovered in the Linux
kernel that may lead to a denial of service or the execution of arbitrary
code. 
This update also fixes a regression in the smbfs subsystem which was introduced
in DSA-1233 which caused symlinks to be interpreted as regular files.
The Common Vulnerabilities and Exposures project identifies the
following problems:
David Gibson reported an issue in the hugepage code which could permit
    a local DoS (system crash) on appropriately configured systems.
Doug Chapman discovered a potential local DoS (deadlock) in the mincore
    function caused by improper lock handling.
Ang Way Chuang reported a remote DoS (crash) in the dvb driver which
    can be triggered by a ULE package with an SNDU length of 0.
Eric Sandeen provided a fix for a local memory corruption vulnerability
    resulting from a misinterpretation of return values when operating on
    inodes which have been marked bad.
Darrick Wong discovered a local DoS (crash) vulnerability resulting from
    the incorrect initialization of &lt;q>nr_pages&lt;/q> in aio_setup_ring().
LMH reported a potential local DoS which could be exploited by a malicious
    user with the privileges to mount and read a corrupted iso9660 filesystem.
LMH reported a potential local DoS which could be exploited by a malicious
    user with the privileges to mount and read a corrupted ext3 filesystem.
LMH reported a potential local DoS which could be exploited by a malicious
    user with the privileges to mount and read a corrupted hfs filesystem on
    systems with SELinux hooks enabled (Debian does not enable SELinux by
    default).
LMH reported a potential local DoS (infinite loop) which could be exploited
    by a malicious user with the privileges to mount and read a corrupted NTFS
    filesystem.
Marcel Holtman discovered multiple buffer overflows in the Bluetooth
    subsystem which can be used to trigger a remote DoS (crash) and potentially
    execute arbitrary code.
Kostantin Khorenko discovered an invalid error path in dev_queue_xmit()
    which could be exploited by a local user to cause data corruption.
Santosh Eraniose reported a vulnerability that allows local users to read
    otherwise unreadable files by triggering a core dump while using PT_INTERP.
    This is related to &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1073">CVE-2004-1073&lt;/a>.
Jean Delvare reported a vulnerability in the appletalk subsystem.
    Systems with the appletalk module loaded can be triggered to crash
    by other systems on the local network via a malformed frame.
Masayuki Nakagawa discovered that flow labels were inadvertently
    being shared between listening sockets and child sockets. This defect
    can be exploited by local users to cause a DoS (Oops).
The following matrix explains which kernel version for which architecture
fix the problems mentioned above:
We recommend that you upgrade your kernel package immediately and reboot
the machine. If you have built a custom kernel from the kernel source
package, you will need to rebuild to take advantage of these fixes.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-patch-2.6.8-s390 DPKG is earlier than 2.6.8-5sarge7' test_ref='oval:org.debian.oval:tst:1180'/>
              <criterion comment='kernel-tree-2.6.8 DPKG is earlier than 2.6.8-16sarge7' test_ref='oval:org.debian.oval:tst:1181'/>
              <criterion comment='kernel-doc-2.6.8 DPKG is earlier than 2.6.8-16sarge7' test_ref='oval:org.debian.oval:tst:1182'/>
              <criterion comment='kernel-patch-debian-2.6.8 DPKG is earlier than 2.6.8-16sarge7' test_ref='oval:org.debian.oval:tst:1183'/>
              <criterion comment='kernel-source-2.6.8 DPKG is earlier than 2.6.8-16sarge7' test_ref='oval:org.debian.oval:tst:1184'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-headers-2.6.8-4 DPKG is earlier than 2.6.8-5sarge7' test_ref='oval:org.debian.oval:tst:1185'/>
              <criterion comment='kernel-image-2.6.8-4-s390-tape DPKG is earlier than 2.6.8-5sarge7' test_ref='oval:org.debian.oval:tst:1186'/>
              <criterion comment='kernel-image-2.6.8-4-s390 DPKG is earlier than 2.6.8-5sarge7' test_ref='oval:org.debian.oval:tst:1187'/>
              <criterion comment='kernel-image-2.6.8-4-s390x DPKG is earlier than 2.6.8-5sarge7' test_ref='oval:org.debian.oval:tst:1188'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='kernel-headers-2.6.8-13-amd64-generic DPKG is earlier than 2.6.8-16sarge7' test_ref='oval:org.debian.oval:tst:1189'/>
              <criterion comment='kernel-image-2.6.8-13-em64t-p4-smp DPKG is earlier than 2.6.8-16sarge7' test_ref='oval:org.debian.oval:tst:1190'/>
              <criterion comment='kernel-headers-2.6.8-13-em64t-p4-smp DPKG is earlier than 2.6.8-16sarge7' test_ref='oval:org.debian.oval:tst:1191'/>
              <criterion comment='kernel-headers-2.6.8-13-amd64-k8 DPKG is earlier than 2.6.8-16sarge7' test_ref='oval:org.debian.oval:tst:1192'/>
              <criterion comment='kernel-headers-2.6.8-13-amd64-k8-smp DPKG is earlier than 2.6.8-16sarge7' test_ref='oval:org.debian.oval:tst:1193'/>
              <criterion comment='kernel-headers-2.6.8-13-em64t-p4 DPKG is earlier than 2.6.8-16sarge7' test_ref='oval:org.debian.oval:tst:1194'/>
              <criterion comment='kernel-image-2.6.8-13-amd64-k8-smp DPKG is earlier than 2.6.8-16sarge7' test_ref='oval:org.debian.oval:tst:1195'/>
              <criterion comment='kernel-image-2.6.8-13-amd64-k8 DPKG is earlier than 2.6.8-16sarge7' test_ref='oval:org.debian.oval:tst:1196'/>
              <criterion comment='kernel-image-2.6.8-13-amd64-generic DPKG is earlier than 2.6.8-16sarge7' test_ref='oval:org.debian.oval:tst:1197'/>
              <criterion comment='kernel-image-2.6.8-13-em64t-p4 DPKG is earlier than 2.6.8-16sarge7' test_ref='oval:org.debian.oval:tst:1198'/>
              <criterion comment='kernel-headers-2.6.8-13 DPKG is earlier than 2.6.8-16sarge7' test_ref='oval:org.debian.oval:tst:1199'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported platform section' operator='AND'>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='kernel-headers-2.6.8-4 DPKG is earlier than 2.6.8-6sarge7' test_ref='oval:org.debian.oval:tst:1278'/>
                <criterion comment='kernel-image-2.6.8-4-64 DPKG is earlier than 2.6.8-6sarge7' test_ref='oval:org.debian.oval:tst:1279'/>
                <criterion comment='kernel-headers-2.6.8-4-64 DPKG is earlier than 2.6.8-6sarge7' test_ref='oval:org.debian.oval:tst:1280'/>
                <criterion comment='kernel-image-2.6.8-4-64-smp DPKG is earlier than 2.6.8-6sarge7' test_ref='oval:org.debian.oval:tst:1281'/>
                <criterion comment='kernel-headers-2.6.8-4-32 DPKG is earlier than 2.6.8-6sarge7' test_ref='oval:org.debian.oval:tst:1282'/>
                <criterion comment='kernel-image-2.6.8-4-32-smp DPKG is earlier than 2.6.8-6sarge7' test_ref='oval:org.debian.oval:tst:1283'/>
                <criterion comment='kernel-headers-2.6.8-4-32-smp DPKG is earlier than 2.6.8-6sarge7' test_ref='oval:org.debian.oval:tst:1284'/>
                <criterion comment='kernel-headers-2.6.8-4-64-smp DPKG is earlier than 2.6.8-6sarge7' test_ref='oval:org.debian.oval:tst:1285'/>
                <criterion comment='kernel-image-2.6.8-4-32 DPKG is earlier than 2.6.8-6sarge7' test_ref='oval:org.debian.oval:tst:1286'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1305' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>icedove</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1558' ref_id='CVE-2007-1558'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2867' ref_id='CVE-2007-2867'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2868' ref_id='CVE-2007-2868'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-06-13</date>
          <moreinfo>
Several remote vulnerabilities have been discovered in the Icedove mail client,
an unbranded version of the Thunderbird client. The Common Vulnerabilities and
Exposures project identifies the following problems:
Gatan Leurent discovered a cryptographical weakness in APOP
    authentication, which reduces the required efforts for an MITM attack
    to intercept a password. The update enforces stricter validation, which
    prevents this attack.
Boris Zbarsky, Eli Friedman, Georgi Guninski, Jesse Ruderman, Martijn
    Wargers and Olli Pettay discovered crashes in the layout engine, which
    might allow the execution of arbitrary code.
Brendan Eich, Igor Bukanov, Jesse Ruderman, &lt;q>moz_bug_r_a4&lt;/q> and Wladimir Palant
    discovered crashes in the Javascript engine, which might allow the execution of
    arbitrary code. Generally, enabling Javascript in Icedove is not recommended.
Fixes for the oldstable distribution (sarge) are not available. While there
will be another round of security updates for Mozilla products, Debian doesn't
have the resources to backport further security fixes to the old Mozilla
products. You're strongly encouraged to upgrade to stable as soon as possible.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='thunderbird-gnome-support DPKG is earlier than 1.5.0.12.dfsg1-0etch1' test_ref='oval:org.debian.oval:tst:1287'/>
              <criterion comment='mozilla-thunderbird DPKG is earlier than 1.5.0.12.dfsg1-0etch1' test_ref='oval:org.debian.oval:tst:1288'/>
              <criterion comment='thunderbird DPKG is earlier than 1.5.0.12.dfsg1-0etch1' test_ref='oval:org.debian.oval:tst:1289'/>
              <criterion comment='mozilla-thunderbird-dev DPKG is earlier than 1.5.0.12.dfsg1-0etch1' test_ref='oval:org.debian.oval:tst:1290'/>
              <criterion comment='mozilla-thunderbird-inspector DPKG is earlier than 1.5.0.12.dfsg1-0etch1' test_ref='oval:org.debian.oval:tst:1291'/>
              <criterion comment='mozilla-thunderbird-typeaheadfind DPKG is earlier than 1.5.0.12.dfsg1-0etch1' test_ref='oval:org.debian.oval:tst:1292'/>
              <criterion comment='thunderbird-dev DPKG is earlier than 1.5.0.12.dfsg1-0etch1' test_ref='oval:org.debian.oval:tst:1293'/>
              <criterion comment='thunderbird-typeaheadfind DPKG is earlier than 1.5.0.12.dfsg1-0etch1' test_ref='oval:org.debian.oval:tst:1294'/>
              <criterion comment='thunderbird-dbg DPKG is earlier than 1.5.0.12.dfsg1-0etch1' test_ref='oval:org.debian.oval:tst:1295'/>
              <criterion comment='thunderbird-inspector DPKG is earlier than 1.5.0.12.dfsg1-0etch1' test_ref='oval:org.debian.oval:tst:1296'/>
            </criteria>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='icedove-typeaheadfind DPKG is earlier than 1.5.0.12.dfsg1-0etch1' test_ref='oval:org.debian.oval:tst:1297'/>
            <criterion comment='icedove DPKG is earlier than 1.5.0.12.dfsg1-0etch1' test_ref='oval:org.debian.oval:tst:1298'/>
            <criterion comment='icedove-inspector DPKG is earlier than 1.5.0.12.dfsg1-0etch1' test_ref='oval:org.debian.oval:tst:1299'/>
            <criterion comment='icedove-dev DPKG is earlier than 1.5.0.12.dfsg1-0etch1' test_ref='oval:org.debian.oval:tst:1300'/>
            <criterion comment='icedove-dbg DPKG is earlier than 1.5.0.12.dfsg1-0etch1' test_ref='oval:org.debian.oval:tst:1301'/>
            <criterion comment='icedove-gnome-support DPKG is earlier than 1.5.0.12.dfsg1-0etch1' test_ref='oval:org.debian.oval:tst:1302'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1306' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>xulrunner</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1362' ref_id='CVE-2007-1362'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2867' ref_id='CVE-2007-2867'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2868' ref_id='CVE-2007-2868'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2869' ref_id='CVE-2007-2869'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2870' ref_id='CVE-2007-2870'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2871' ref_id='CVE-2007-2871'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-06-12</date>
          <moreinfo>
Several remote vulnerabilities have been discovered in Xulrunner, a
runtime environment for XUL applications. The Common Vulnerabilities
and Exposures project identifies the following problems:
Nicolas Derouet discovered that Xulrunner performs insufficient
    validation of cookies, which could lead to denial of service.
Boris Zbarsky, Eli Friedman, Georgi Guninski, Jesse Ruderman, Martijn
    Wargers and Olli Pettay discovered crashes in the layout engine, which
    might allow the execution of arbitrary code.
Brendan Eich, Igor Bukanov, Jesse Ruderman, &lt;q>moz_bug_r_a4&lt;/q> and Wladimir
    Palant discovered crashes in the Javascript engine, which might allow
    the execution of arbitrary code.
&lt;q>Marcel&lt;/q> discovered that malicous web sites can cause massive
    resource consumption through the auto completion feature, resulting
    in denial of service.
&lt;q>moz_bug_r_a4&lt;/q> discovered that adding an event listener through the
     &lt;code>addEventListener()&lt;/code> function allows cross-site scripting.
Chris Thomas discovered that XUL popups can be abused for spoofing
     or phishing attacks.
The oldstable distribution (sarge) doesn't include xulrunner.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libnspr4-dev DPKG is earlier than 1.8.0.12-0etch1' test_ref='oval:org.debian.oval:tst:1303'/>
              <criterion comment='libmozjs-dev DPKG is earlier than 1.8.0.12-0etch1' test_ref='oval:org.debian.oval:tst:1304'/>
              <criterion comment='libsmjs-dev DPKG is earlier than 1.8.0.12-0etch1' test_ref='oval:org.debian.oval:tst:1305'/>
              <criterion comment='libmozillainterfaces-java DPKG is earlier than 1.8.0.12-0etch1' test_ref='oval:org.debian.oval:tst:1306'/>
              <criterion comment='libxul-common DPKG is earlier than 1.8.0.12-0etch1' test_ref='oval:org.debian.oval:tst:1307'/>
              <criterion comment='libsmjs1 DPKG is earlier than 1.8.0.12-0etch1' test_ref='oval:org.debian.oval:tst:1308'/>
              <criterion comment='libxul-dev DPKG is earlier than 1.8.0.12-0etch1' test_ref='oval:org.debian.oval:tst:1309'/>
              <criterion comment='libnss3-dev DPKG is earlier than 1.8.0.12-0etch1' test_ref='oval:org.debian.oval:tst:1310'/>
            </criteria>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libxul0d DPKG is earlier than 1.8.0.12-0etch1' test_ref='oval:org.debian.oval:tst:1311'/>
            <criterion comment='libnss3-0d-dbg DPKG is earlier than 1.8.0.12-0etch1' test_ref='oval:org.debian.oval:tst:1312'/>
            <criterion comment='libmozjs0d-dbg DPKG is earlier than 1.8.0.12-0etch1' test_ref='oval:org.debian.oval:tst:1313'/>
            <criterion comment='libnss3-0d DPKG is earlier than 1.8.0.12-0etch1' test_ref='oval:org.debian.oval:tst:1314'/>
            <criterion comment='spidermonkey-bin DPKG is earlier than 1.8.0.12-0etch1' test_ref='oval:org.debian.oval:tst:1315'/>
            <criterion comment='libnspr4-0d DPKG is earlier than 1.8.0.12-0etch1' test_ref='oval:org.debian.oval:tst:1316'/>
            <criterion comment='libnspr4-0d-dbg DPKG is earlier than 1.8.0.12-0etch1' test_ref='oval:org.debian.oval:tst:1317'/>
            <criterion comment='xulrunner-gnome-support DPKG is earlier than 1.8.0.12-0etch1' test_ref='oval:org.debian.oval:tst:1318'/>
            <criterion comment='libxul0d-dbg DPKG is earlier than 1.8.0.12-0etch1' test_ref='oval:org.debian.oval:tst:1319'/>
            <criterion comment='xulrunner DPKG is earlier than 1.8.0.12-0etch1' test_ref='oval:org.debian.oval:tst:1320'/>
            <criterion comment='libnss3-tools DPKG is earlier than 1.8.0.12-0etch1' test_ref='oval:org.debian.oval:tst:1321'/>
            <criterion comment='python-xpcom DPKG is earlier than 1.8.0.12-0etch1' test_ref='oval:org.debian.oval:tst:1322'/>
            <criterion comment='libmozjs0d DPKG is earlier than 1.8.0.12-0etch1' test_ref='oval:org.debian.oval:tst:1323'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1307' class='vulnerability'>
      <metadata>
        <title>heap overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>openoffice.org</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0245' ref_id='CVE-2007-0245'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-06-12</date>
          <moreinfo>
John Heasman discovered a heap overflow in the routines of OpenOffice.org
that parse RTF files.  A specially crafted RTF file could cause the
filter to overwrite data on the heap, which may lead to the execution
of arbitrary code.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='openoffice.org-dtd-officedocument1.0 DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1324'/>
                <criterion comment='openoffice.org-l10n-cy DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1325'/>
                <criterion comment='openoffice.org-l10n-cs DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1326'/>
                <criterion comment='openoffice.org-help-hu DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1327'/>
                <criterion comment='openoffice.org-l10n-vi DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1328'/>
                <criterion comment='openoffice.org-l10n-ca DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1329'/>
                <criterion comment='openoffice.org-help-en-us DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1330'/>
                <criterion comment='ttf-opensymbol DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1331'/>
                <criterion comment='openoffice.org-l10n-ka DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1332'/>
                <criterion comment='openoffice.org-l10n-km DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1333'/>
                <criterion comment='openoffice.org-l10n-ko DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1334'/>
                <criterion comment='openoffice.org-l10n-pl DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1335'/>
                <criterion comment='broffice.org DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1336'/>
                <criterion comment='openoffice.org-l10n-ku DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1337'/>
                <criterion comment='openoffice.org-l10n-pt DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1338'/>
                <criterion comment='openoffice.org-l10n-xh DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1339'/>
                <criterion comment='openoffice.org-help-it DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1340'/>
                <criterion comment='openoffice.org-help-pl DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1341'/>
                <criterion comment='openoffice.org-l10n-be-by DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1342'/>
                <criterion comment='openoffice.org-l10n-hr DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1343'/>
                <criterion comment='openoffice.org-l10n-hu DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1344'/>
                <criterion comment='openoffice.org-l10n-mk DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1345'/>
                <criterion comment='openoffice.org-l10n-hi DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1346'/>
                <criterion comment='openoffice.org-l10n-sr-cs DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1347'/>
                <criterion comment='openoffice.org-l10n-he DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1348'/>
                <criterion comment='openoffice.org-l10n-en-za DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1349'/>
                <criterion comment='openoffice.org-l10n-as-in DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1350'/>
                <criterion comment='openoffice.org-l10n-ta-in DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1351'/>
                <criterion comment='openoffice.org-l10n-te-in DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1352'/>
                <criterion comment='openoffice.org-help-nl DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1353'/>
                <criterion comment='openoffice.org-l10n-eo DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1354'/>
                <criterion comment='openoffice.org-l10n-el DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1355'/>
                <criterion comment='openoffice.org-l10n-zu DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1356'/>
                <criterion comment='openoffice.org-l10n-hi-in DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1357'/>
                <criterion comment='openoffice.org-l10n-zh-tw DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1358'/>
                <criterion comment='openoffice.org-l10n-za DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1359'/>
                <criterion comment='openoffice.org-l10n-et DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1360'/>
                <criterion comment='openoffice.org-help-fr DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1361'/>
                <criterion comment='openoffice.org-l10n-rw DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1362'/>
                <criterion comment='openoffice.org-l10n-es DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1363'/>
                <criterion comment='openoffice.org-l10n-ru DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1364'/>
                <criterion comment='openoffice.org-l10n-bs DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1365'/>
                <criterion comment='openoffice.org-l10n-br DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1366'/>
                <criterion comment='openoffice.org-l10n-bn DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1367'/>
                <criterion comment='openoffice.org-l10n-bg DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1368'/>
                <criterion comment='openoffice.org-l10n-sl DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1369'/>
                <criterion comment='openoffice.org-l10n-ja DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1370'/>
                <criterion comment='openoffice.org-l10n-en-gb DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1371'/>
                <criterion comment='openoffice.org-l10n-sk DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1372'/>
                <criterion comment='openoffice.org-l10n-st DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1373'/>
                <criterion comment='openoffice.org-l10n-sv DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1374'/>
                <criterion comment='openoffice.org-l10n-ss DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1375'/>
                <criterion comment='openoffice.org-help-sv DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1376'/>
                <criterion comment='openoffice.org-help-dz DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1377'/>
                <criterion comment='openoffice.org-help-da DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1378'/>
                <criterion comment='openoffice.org-help-de DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1379'/>
                <criterion comment='openoffice.org-help-sl DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1380'/>
                <criterion comment='openoffice.org-java-common DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1381'/>
                <criterion comment='openoffice.org-l10n-ga DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1382'/>
                <criterion comment='openoffice.org-l10n-ts DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1383'/>
                <criterion comment='openoffice.org-l10n-tr DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1384'/>
                <criterion comment='openoffice.org-l10n-tn DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1385'/>
                <criterion comment='openoffice.org-l10n-th DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1386'/>
                <criterion comment='openoffice.org-l10n-tg DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1387'/>
                <criterion comment='openoffice.org-help-et DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1388'/>
                <criterion comment='openoffice.org-help-es DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1389'/>
                <criterion comment='openoffice.org-filter-mobiledev DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1390'/>
                <criterion comment='openoffice.org-l10n-or-in DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1391'/>
                <criterion comment='openoffice.org-help-en DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1392'/>
                <criterion comment='openoffice.org-l10n-lt DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1393'/>
                <criterion comment='openoffice.org-l10n-lv DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1394'/>
                <criterion comment='openoffice.org-l10n-de DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1395'/>
                <criterion comment='openoffice.org-l10n-da DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1396'/>
                <criterion comment='openoffice.org-l10n-uk DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1397'/>
                <criterion comment='openoffice.org-l10n-dz DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1398'/>
                <criterion comment='openoffice.org-l10n-lo DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1399'/>
                <criterion comment='openoffice.org-l10n-ml-in DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1400'/>
                <criterion comment='openoffice.org-help-en-gb DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1401'/>
                <criterion comment='openoffice.org-l10n-af DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1402'/>
                <criterion comment='openoffice.org-common DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1403'/>
                <criterion comment='openoffice.org-help-ja DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1404'/>
                <criterion comment='openoffice.org-l10n-zh-cn DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1405'/>
                <criterion comment='openoffice.org-l10n-ve DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1406'/>
                <criterion comment='openoffice.org-help-zh-cn DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1407'/>
                <criterion comment='openoffice.org-l10n-it DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1408'/>
                <criterion comment='openoffice.org-l10n-gu-in DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1409'/>
                <criterion comment='openoffice.org-l10n-in DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1410'/>
                <criterion comment='openoffice.org-help-zh-tw DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1411'/>
                <criterion comment='openoffice.org-help-ru DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1412'/>
                <criterion comment='openoffice.org-l10n-fr DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1413'/>
                <criterion comment='openoffice.org-l10n-pt-br DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1414'/>
                <criterion comment='openoffice.org-help-pt-br DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1415'/>
                <criterion comment='openoffice.org-help-ko DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1416'/>
                <criterion comment='openoffice.org-help-km DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1417'/>
                <criterion comment='openoffice.org-l10n-fa DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1418'/>
                <criterion comment='openoffice.org-l10n-fi DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1419'/>
                <criterion comment='openoffice.org-qa-api-tests DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1420'/>
                <criterion comment='openoffice.org-help-hi-in DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1421'/>
                <criterion comment='openoffice.org-l10n-ns DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1422'/>
                <criterion comment='openoffice.org-l10n-nr DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1423'/>
                <criterion comment='openoffice.org-dev-doc DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1424'/>
                <criterion comment='openoffice.org-l10n-nn DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1425'/>
                <criterion comment='openoffice.org-l10n-nl DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1426'/>
                <criterion comment='openoffice.org-help-cs DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1427'/>
                <criterion comment='openoffice.org-l10n-ne DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1428'/>
                <criterion comment='openoffice.org-l10n-pa-in DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1429'/>
                <criterion comment='openoffice.org-l10n-nb DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1430'/>
              </criteria>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='libmythes-dev DPKG is earlier than 2.0.4.dfsg.2-5etch1' test_ref='oval:org.debian.oval:tst:1431'/>
              </criteria>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
                <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='openoffice.org-filter-so52 DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1432'/>
                <criterion comment='openoffice.org-impress DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1433'/>
                <criterion comment='openoffice.org-evolution DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1434'/>
                <criterion comment='openoffice.org-base DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1435'/>
                <criterion comment='openoffice.org DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1436'/>
                <criterion comment='libmythes-dev DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1437'/>
                <criterion comment='openoffice.org-math DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1438'/>
                <criterion comment='openoffice.org-calc DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1439'/>
                <criterion comment='openoffice.org-qa-tools DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1440'/>
                <criterion comment='openoffice.org-dbg DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1441'/>
                <criterion comment='openoffice.org-gtk DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1442'/>
                <criterion comment='openoffice.org-officebean DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1443'/>
                <criterion comment='python-uno DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1444'/>
                <criterion comment='openoffice.org-gtk-gnome DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1445'/>
                <criterion comment='openoffice.org-core DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1446'/>
                <criterion comment='openoffice.org-dev DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1447'/>
                <criterion comment='openoffice.org-gcj DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1448'/>
                <criterion comment='openoffice.org-kde DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1449'/>
                <criterion comment='openoffice.org-draw DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1450'/>
                <criterion comment='openoffice.org-gnome DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1451'/>
                <criterion comment='openoffice.org-writer DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1452'/>
              </criteria>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported platform section' operator='AND'>
                <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
                <criteria comment='Packages section' operator='OR'>
                  <criterion comment='libmythes-dev DPKG is earlier than 2.0.4.dfsg.2-7etch1' test_ref='oval:org.debian.oval:tst:1458'/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='openoffice.org-l10n-ar DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1459'/>
                <criterion comment='openoffice.org-l10n-cy DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1460'/>
                <criterion comment='openoffice.org DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1461'/>
                <criterion comment='openoffice.org-l10n-da DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1462'/>
                <criterion comment='openoffice.org-l10n-cs DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1463'/>
                <criterion comment='openoffice.org-l10n-af DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1464'/>
                <criterion comment='openoffice.org-l10n-ca DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1465'/>
                <criterion comment='openoffice.org-l10n-en DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1466'/>
                <criterion comment='openoffice.org-l10n-pt-br DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1467'/>
                <criterion comment='openoffice.org-l10n-el DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1468'/>
                <criterion comment='openoffice.org-l10n-gl DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1469'/>
                <criterion comment='openoffice.org-l10n-zu DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1470'/>
                <criterion comment='openoffice.org-thesaurus-en-us DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1471'/>
                <criterion comment='openoffice.org-l10n-kn DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1472'/>
                <criterion comment='openoffice.org-l10n-ko DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1473'/>
                <criterion comment='openoffice.org-l10n-pl DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1474'/>
                <criterion comment='openoffice.org-l10n-it DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1475'/>
                <criterion comment='openoffice.org-l10n-tr DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1476'/>
                <criterion comment='openoffice.org-l10n-zh-tw DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1477'/>
                <criterion comment='openoffice.org-l10n-tn DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1478'/>
                <criterion comment='openoffice.org-l10n-pt DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1479'/>
                <criterion comment='openoffice.org-l10n-et DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1480'/>
                <criterion comment='openoffice.org-l10n-eu DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1481'/>
                <criterion comment='openoffice.org-l10n-es DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1482'/>
                <criterion comment='openoffice.org-l10n-ru DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1483'/>
                <criterion comment='openoffice.org-l10n-th DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1484'/>
                <criterion comment='openoffice.org-l10n-zh-cn DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1485'/>
                <criterion comment='openoffice.org-l10n-fr DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1486'/>
                <criterion comment='ttf-opensymbol DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1487'/>
                <criterion comment='openoffice.org-l10n-ns DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1488'/>
                <criterion comment='openoffice.org-l10n-fi DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1489'/>
                <criterion comment='openoffice.org-l10n-sl DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1490'/>
                <criterion comment='openoffice.org-l10n-lt DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1491'/>
                <criterion comment='openoffice.org-l10n-ja DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1492'/>
                <criterion comment='openoffice.org-l10n-sk DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1493'/>
                <criterion comment='openoffice.org-l10n-de DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1494'/>
                <criterion comment='openoffice.org-l10n-hu DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1495'/>
                <criterion comment='openoffice.org-l10n-hi DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1496'/>
                <criterion comment='openoffice.org-l10n-nn DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1497'/>
                <criterion comment='openoffice.org-l10n-nl DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1498'/>
                <criterion comment='openoffice.org-mimelnk DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1499'/>
                <criterion comment='openoffice.org-l10n-sv DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1500'/>
                <criterion comment='openoffice.org-l10n-he DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1501'/>
                <criterion comment='openoffice.org-l10n-nb DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1502'/>
              </criteria>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
                <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='openoffice.org-dev DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1503'/>
                <criterion comment='openoffice.org-gtk-gnome DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1504'/>
                <criterion comment='openoffice.org-evolution DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1505'/>
                <criterion comment='openoffice.org-bin DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1506'/>
                <criterion comment='openoffice.org-kde DPKG is earlier than 1.1.3-9sarge7' test_ref='oval:org.debian.oval:tst:1507'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1308' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>iceweasel</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1362' ref_id='CVE-2007-1362'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2867' ref_id='CVE-2007-2867'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2868' ref_id='CVE-2007-2868'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2869' ref_id='CVE-2007-2869'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2870' ref_id='CVE-2007-2870'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2871' ref_id='CVE-2007-2871'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-06-14</date>
          <moreinfo>
Several remote vulnerabilities have been discovered in the Iceweasel web
browser, an unbranded version of the Firefox browser. The Common 
Vulnerabilities and Exposures project identifies the following problems:
Nicolas Derouet discovered that Iceweasel performs insufficient 
    validation of cookies, which could lead to denial of service.
Boris Zbarsky, Eli Friedman, Georgi Guninski, Jesse Ruderman, Martijn
    Wargers and Olli Pettay discovered crashes in the layout engine, which
    might allow the execution of arbitrary code.
Brendan Eich, Igor Bukanov, Jesse Ruderman, &lt;q>moz_bug_r_a4&lt;/q> and Wladimir Palant
    discovered crashes in the javascript engine, which might allow the execution of
    arbitrary code.
&lt;q>Marcel&lt;/q> discovered that malicous web sites can cause massive
    resource consumption through the auto completion feature, resulting
    in denial of service.
&lt;q>moz_bug_r_a4&lt;/q> discovered that adding an event listener through the
     &lt;code>addEventListener()&lt;/code> function allows cross-site scripting.
Chris Thomas discovered that XUL popups can be abused for spoofing or
    phishing attacks.
Fixes for the oldstable distribution (sarge) are not available. While there
will be another round of security updates for Mozilla products, Debian doesn't
have the resources to backport further security fixes to the old Mozilla
products. You're strongly encouraged to upgrade to stable as soon as possible.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='mozilla-firefox DPKG is earlier than 2.0.0.4-0etch1' test_ref='oval:org.debian.oval:tst:1508'/>
              <criterion comment='firefox DPKG is earlier than 2.0.0.4-0etch1' test_ref='oval:org.debian.oval:tst:1509'/>
              <criterion comment='firefox-dom-inspector DPKG is earlier than 2.0.0.4-0etch1' test_ref='oval:org.debian.oval:tst:1510'/>
              <criterion comment='iceweasel-dom-inspector DPKG is earlier than 2.0.0.4-0etch1' test_ref='oval:org.debian.oval:tst:1511'/>
              <criterion comment='mozilla-firefox-gnome-support DPKG is earlier than 2.0.0.4-0etch1' test_ref='oval:org.debian.oval:tst:1512'/>
              <criterion comment='mozilla-firefox-dom-inspector DPKG is earlier than 2.0.0.4-0etch1' test_ref='oval:org.debian.oval:tst:1513'/>
              <criterion comment='firefox-gnome-support DPKG is earlier than 2.0.0.4-0etch1' test_ref='oval:org.debian.oval:tst:1514'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:66'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='iceweasel-gnome-support DPKG is earlier than 2.0.0.4-0etch1' test_ref='oval:org.debian.oval:tst:1515'/>
              <criterion comment='iceweasel-dbg DPKG is earlier than 2.0.0.4-0etch1' test_ref='oval:org.debian.oval:tst:1516'/>
              <criterion comment='iceweasel DPKG is earlier than 2.0.0.4-0etch1' test_ref='oval:org.debian.oval:tst:1517'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1309' class='vulnerability'>
      <metadata>
        <title>programming error</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>postgresql-8.1</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2138' ref_id='CVE-2007-2138'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-06-16</date>
          <moreinfo>
It was discovered that the PostgreSQL database performs insufficient
validation of variables passed to privileged SQL statements, so called
&lt;q>security definers&lt;/q>, which could lead to SQL privilege escalation.
The oldstable distribution (sarge) doesn't contain PostgreSQL 8.1.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criterion comment='postgresql-doc-8.1 DPKG is earlier than 8.1.9-0etch1' test_ref='oval:org.debian.oval:tst:1518'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='postgresql-client-8.1 DPKG is earlier than 8.1.9-0etch1' test_ref='oval:org.debian.oval:tst:1519'/>
            <criterion comment='postgresql-8.1 DPKG is earlier than 8.1.9-0etch1' test_ref='oval:org.debian.oval:tst:1520'/>
            <criterion comment='postgresql-pltcl-8.1 DPKG is earlier than 8.1.9-0etch1' test_ref='oval:org.debian.oval:tst:1521'/>
            <criterion comment='libecpg5 DPKG is earlier than 8.1.9-0etch1' test_ref='oval:org.debian.oval:tst:1522'/>
            <criterion comment='postgresql-contrib-8.1 DPKG is earlier than 8.1.9-0etch1' test_ref='oval:org.debian.oval:tst:1523'/>
            <criterion comment='postgresql-server-dev-8.1 DPKG is earlier than 8.1.9-0etch1' test_ref='oval:org.debian.oval:tst:1524'/>
            <criterion comment='libpgtypes2 DPKG is earlier than 8.1.9-0etch1' test_ref='oval:org.debian.oval:tst:1525'/>
            <criterion comment='libecpg-dev DPKG is earlier than 8.1.9-0etch1' test_ref='oval:org.debian.oval:tst:1526'/>
            <criterion comment='postgresql-plpython-8.1 DPKG is earlier than 8.1.9-0etch1' test_ref='oval:org.debian.oval:tst:1527'/>
            <criterion comment='libpq4 DPKG is earlier than 8.1.9-0etch1' test_ref='oval:org.debian.oval:tst:1528'/>
            <criterion comment='libpq-dev DPKG is earlier than 8.1.9-0etch1' test_ref='oval:org.debian.oval:tst:1529'/>
            <criterion comment='postgresql-plperl-8.1 DPKG is earlier than 8.1.9-0etch1' test_ref='oval:org.debian.oval:tst:1530'/>
            <criterion comment='libecpg-compat2 DPKG is earlier than 8.1.9-0etch1' test_ref='oval:org.debian.oval:tst:1531'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1310' class='vulnerability'>
      <metadata>
        <title>integer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>libexif</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4168' ref_id='CVE-2006-4168'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-06-16</date>
          <moreinfo>
A vulnerability has been discovered in libexif, a library to parse EXIF
files, which allows denial of service and possible execution of arbitrary
code via malformed EXIF data.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libexif-dev DPKG is earlier than 0.6.13-5etch1' test_ref='oval:org.debian.oval:tst:1532'/>
              <criterion comment='libexif12 DPKG is earlier than 0.6.13-5etch1' test_ref='oval:org.debian.oval:tst:1533'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
                <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
                <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:63'/>
                <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
                <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:66'/>
                <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
                <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
                <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='libexif10 DPKG is earlier than 0.6.9-6sarge1' test_ref='oval:org.debian.oval:tst:1534'/>
                <criterion comment='libexif-dev DPKG is earlier than 0.6.9-6sarge1' test_ref='oval:org.debian.oval:tst:1535'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1311' class='vulnerability'>
      <metadata>
        <title>programming error</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>postgresql-7.4</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2138' ref_id='CVE-2007-2138'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-06-17</date>
          <moreinfo>
It was discovered that the PostgreSQL database performs insufficient
validation of variables passed to privileged SQL statement called
&lt;q>security definers&lt;/q>, which could lead to SQL privilege escalation.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='postgresql-server-dev-7.4 DPKG is earlier than 7.4.17-0etch1' test_ref='oval:org.debian.oval:tst:1536'/>
                <criterion comment='postgresql-doc-7.4 DPKG is earlier than 7.4.17-0etch1' test_ref='oval:org.debian.oval:tst:1537'/>
              </criteria>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='postgresql-7.4 DPKG is earlier than 7.4.17-0etch1' test_ref='oval:org.debian.oval:tst:1538'/>
              <criterion comment='postgresql-plpython-7.4 DPKG is earlier than 7.4.17-0etch1' test_ref='oval:org.debian.oval:tst:1539'/>
              <criterion comment='postgresql-pltcl-7.4 DPKG is earlier than 7.4.17-0etch1' test_ref='oval:org.debian.oval:tst:1540'/>
              <criterion comment='postgresql-client-7.4 DPKG is earlier than 7.4.17-0etch1' test_ref='oval:org.debian.oval:tst:1541'/>
              <criterion comment='postgresql-plperl-7.4 DPKG is earlier than 7.4.17-0etch1' test_ref='oval:org.debian.oval:tst:1542'/>
              <criterion comment='postgresql-contrib-7.4 DPKG is earlier than 7.4.17-0etch1' test_ref='oval:org.debian.oval:tst:1543'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
              <criterion comment='postgresql-doc DPKG is earlier than 7.4.7-6sarge5' test_ref='oval:org.debian.oval:tst:1544'/>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
                <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
                <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:63'/>
                <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
                <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:66'/>
                <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
                <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
                <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='libpgtcl DPKG is earlier than 7.4.7-6sarge5' test_ref='oval:org.debian.oval:tst:1545'/>
                <criterion comment='postgresql DPKG is earlier than 7.4.7-6sarge5' test_ref='oval:org.debian.oval:tst:1546'/>
                <criterion comment='libecpg4 DPKG is earlier than 7.4.7-6sarge5' test_ref='oval:org.debian.oval:tst:1547'/>
                <criterion comment='postgresql-contrib DPKG is earlier than 7.4.7-6sarge5' test_ref='oval:org.debian.oval:tst:1548'/>
                <criterion comment='libpq3 DPKG is earlier than 7.4.7-6sarge5' test_ref='oval:org.debian.oval:tst:1549'/>
                <criterion comment='libecpg-dev DPKG is earlier than 7.4.7-6sarge5' test_ref='oval:org.debian.oval:tst:1550'/>
                <criterion comment='libpgtcl-dev DPKG is earlier than 7.4.7-6sarge5' test_ref='oval:org.debian.oval:tst:1551'/>
                <criterion comment='postgresql-dev DPKG is earlier than 7.4.7-6sarge5' test_ref='oval:org.debian.oval:tst:1552'/>
                <criterion comment='postgresql-client DPKG is earlier than 7.4.7-6sarge5' test_ref='oval:org.debian.oval:tst:1553'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1312' class='vulnerability'>
      <metadata>
        <title>programming error</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>libapache-mod-jk</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1860' ref_id='CVE-2007-1860'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-06-18</date>
          <moreinfo>
It was discovered that the Apache 1.3 connector for the Tomcat Java
servlet engine decoded request URLs multiple times, which can lead
to information disclosure.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
              <criterion comment='libapache-mod-jk-doc DPKG is earlier than 1.2.18-3etch1' test_ref='oval:org.debian.oval:tst:1554'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libapache-mod-jk DPKG is earlier than 1.2.18-3etch1' test_ref='oval:org.debian.oval:tst:1555'/>
              <criterion comment='libapache2-mod-jk DPKG is earlier than 1.2.18-3etch1' test_ref='oval:org.debian.oval:tst:1556'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
                <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
                <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:63'/>
                <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
                <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:66'/>
                <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
                <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
                <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='libapache-mod-jk DPKG is earlier than 1.2.5-2sarge1' test_ref='oval:org.debian.oval:tst:1557'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1313' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>mplayer</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2948' ref_id='CVE-2007-2948'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-06-19</date>
          <moreinfo>
Stefan Cornelius and Reimar Doeffinger discovered that the MPlayer movie
player performs insufficient boundary checks when accessing CDDB data,
which might lead to the execution of arbitrary code.
The oldstable distribution (sarge) doesn't include MPlayer packages.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criterion comment='mplayer-doc DPKG is earlier than 1.0~rc1-12etch1' test_ref='oval:org.debian.oval:tst:1558'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='mplayer DPKG is earlier than 1.0~rc1-12etch1' test_ref='oval:org.debian.oval:tst:1559'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1314' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>open-iscsi</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3099' ref_id='CVE-2007-3099'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3100' ref_id='CVE-2007-3100'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-06-19</date>
          <moreinfo>
Several local and remote vulnerabilities have been discovered in
open-iscsi, a transport-independent iSCSI implementation. The Common
Vulnerabilities and Exposures project identifies the following problems:
Olaf Kirch discovered that due to a programming error access to the
    management interface socket was insufficiently protected, which allows
    denial of service.
Olaf Kirch discovered that access to a semaphore used in the logging
    code was insufficiently protected, allowing denial of service.
The oldstable distribution (sarge) doesn't include open-iscsi.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='open-iscsi DPKG is earlier than 2.0.730-1etch1' test_ref='oval:org.debian.oval:tst:1560'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1315' class='vulnerability'>
      <metadata>
        <title>missing input validation</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>libphp-phpmailer</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3215' ref_id='CVE-2007-3215'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-06-21</date>
          <moreinfo>
Thor Larholm discovered that libphp-phpmailer, an email transfer class
for PHP, performs insufficient input validition if configured to use
Sendmail. This allows the execution of arbitrary shell commands.
The oldstable distribution (sarge) doesn't include libphp-phpmailer.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criterion comment='libphp-phpmailer DPKG is earlier than 1.73-2etch1' test_ref='oval:org.debian.oval:tst:1561'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1316' class='vulnerability'>
      <metadata>
        <title>denial of service</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>emacs21</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2833' ref_id='CVE-2007-2833'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-06-21</date>
          <moreinfo>
It has been discovered that emacs, the GNU Emacs editor, will crash when
processing certain types of images.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='emacs21-el DPKG is earlier than 21.4a+1-3etch1' test_ref='oval:org.debian.oval:tst:1562'/>
              <criterion comment='emacs DPKG is earlier than 21.4a+1-3etch1' test_ref='oval:org.debian.oval:tst:1563'/>
              <criterion comment='emacs21-common DPKG is earlier than 21.4a+1-3etch1' test_ref='oval:org.debian.oval:tst:1564'/>
            </criteria>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='emacs21-nox DPKG is earlier than 21.4a+1-3etch1' test_ref='oval:org.debian.oval:tst:1565'/>
            <criterion comment='emacs21-bin-common DPKG is earlier than 21.4a+1-3etch1' test_ref='oval:org.debian.oval:tst:1566'/>
            <criterion comment='emacs21 DPKG is earlier than 21.4a+1-3etch1' test_ref='oval:org.debian.oval:tst:1567'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1317' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>tinymux</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1655' ref_id='CVE-2007-1655'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-06-23</date>
          <moreinfo>
duskwave discovered that tinymux, a text-based multi-user virtual world server,
performs insufficient boundary checks when working with user-supplied data,
which might lead to the execution of arbitrary code.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='tinymux DPKG is earlier than 2.4.3.31-1etch1' test_ref='oval:org.debian.oval:tst:1568'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1318' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>ekg</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2370' ref_id='CVE-2005-2370'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2448' ref_id='CVE-2005-2448'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1663' ref_id='CVE-2007-1663'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1664' ref_id='CVE-2007-1664'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1665' ref_id='CVE-2007-1665'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-06-22</date>
          <moreinfo>
Several remote vulnerabilities have been discovered in ekg, a console
Gadu Gadu client. The Common Vulnerabilities and Exposures project
identifies the following problems:
It was discovered that memory alignment errors may allow remote
    attackers to cause a denial of service on certain architectures
    such as sparc. This only affects Debian Sarge.
It was discovered that several endianess errors may allow remote
    attackers to cause a denial of service. This only affects 
    Debian Sarge.
It was discovered that a memory leak in handling image messages may
    lead to denial of service. This only affects Debian Etch.
It was discovered that a null pointer deference in the token OCR code
    may lead to denial of service. This only affects Debian Etch.
It was discovered that a memory leak in the token OCR code may lead
    to denial of service. This only affects Debian Etch.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='ekg DPKG is earlier than 1.7~rc2-1etch1' test_ref='oval:org.debian.oval:tst:1569'/>
              <criterion comment='libgadu-dev DPKG is earlier than 1.7~rc2-1etch1' test_ref='oval:org.debian.oval:tst:1570'/>
              <criterion comment='libgadu3 DPKG is earlier than 1.7~rc2-1etch1' test_ref='oval:org.debian.oval:tst:1571'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
                <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
                <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
                <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:66'/>
                <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
                <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
                <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
                <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='ekg DPKG is earlier than 1.5+20050411-7' test_ref='oval:org.debian.oval:tst:1572'/>
                <criterion comment='libgadu-dev DPKG is earlier than 1.5+20050411-7' test_ref='oval:org.debian.oval:tst:1573'/>
                <criterion comment='libgadu3 DPKG is earlier than 1.5+20050411-7' test_ref='oval:org.debian.oval:tst:1574'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1319' class='vulnerability'>
      <metadata>
        <title>memory leaks</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>maradns</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3114' ref_id='CVE-2007-3114'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3115' ref_id='CVE-2007-3115'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3116' ref_id='CVE-2007-3116'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-06-23</date>
          <moreinfo>
Several remote vulnerabilities have been discovered in MaraDNS, a simple
security-aware Domain Name Service server. The Common Vulnerabilities and
Exposures project identifies the following problems:
It was discovered that malformed DNS requests can trigger memory
    leaks, allowing denial of service.
It was discovered that malformed DNS requests can trigger memory
    leaks, allowing denial of service.
It was discovered that malformed DNS requests can trigger memory
    leaks, allowing denial of service.
The oldstable distribution (sarge) is not affected by these problems.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='maradns DPKG is earlier than 1.2.12.04-1etch1' test_ref='oval:org.debian.oval:tst:1575'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1320' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>clamav</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2650' ref_id='CVE-2007-2650'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3023' ref_id='CVE-2007-3023'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3024' ref_id='CVE-2007-3024'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3122' ref_id='CVE-2007-3122'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3123' ref_id='CVE-2007-3123'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-06-23</date>
          <moreinfo>
Several remote vulnerabilities have been discovered in the Clam anti-virus
toolkit. The Common Vulnerabilities and Exposures project identifies the
following problems:
It was discovered that the OLE2 parser can be tricked into an infinite
    loop and memory exhaustion.
It was discovered that the NsPack decompression code performed
    insufficient sanitising on an internal length variable, resulting in
    a potential buffer overflow.
It was discovered that temporary files were created with insecure
    permissions, resulting in information disclosure.
It was discovered that the decompression code for RAR archives allows
    bypassing a scan of a RAR archive due to insufficient validity checks.
It was discovered that the decompression code for RAR archives performs
    insufficient validation of header values, resulting in a buffer overflow.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='clamav-docs DPKG is earlier than 0.90.1-3etch3' test_ref='oval:org.debian.oval:tst:1576'/>
                <criterion comment='clamav-testfiles DPKG is earlier than 0.90.1-3etch3' test_ref='oval:org.debian.oval:tst:1577'/>
                <criterion comment='clamav-base DPKG is earlier than 0.90.1-3etch3' test_ref='oval:org.debian.oval:tst:1578'/>
              </criteria>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libclamav-dev DPKG is earlier than 0.90.1-3etch3' test_ref='oval:org.debian.oval:tst:1579'/>
              <criterion comment='clamav DPKG is earlier than 0.90.1-3etch3' test_ref='oval:org.debian.oval:tst:1580'/>
              <criterion comment='clamav-dbg DPKG is earlier than 0.90.1-3etch3' test_ref='oval:org.debian.oval:tst:1581'/>
              <criterion comment='libclamav2 DPKG is earlier than 0.90.1-3etch3' test_ref='oval:org.debian.oval:tst:1582'/>
              <criterion comment='clamav-daemon DPKG is earlier than 0.90.1-3etch3' test_ref='oval:org.debian.oval:tst:1583'/>
              <criterion comment='clamav-milter DPKG is earlier than 0.90.1-3etch3' test_ref='oval:org.debian.oval:tst:1584'/>
              <criterion comment='clamav-freshclam DPKG is earlier than 0.90.1-3etch3' test_ref='oval:org.debian.oval:tst:1585'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='clamav-docs DPKG is earlier than 0.84-2.sarge.17' test_ref='oval:org.debian.oval:tst:1586'/>
                <criterion comment='clamav-testfiles DPKG is earlier than 0.84-2.sarge.17' test_ref='oval:org.debian.oval:tst:1587'/>
                <criterion comment='clamav-base DPKG is earlier than 0.84-2.sarge.17' test_ref='oval:org.debian.oval:tst:1588'/>
              </criteria>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
                <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
                <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:63'/>
                <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
                <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:66'/>
                <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
                <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
                <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='libclamav-dev DPKG is earlier than 0.84-2.sarge.17' test_ref='oval:org.debian.oval:tst:1589'/>
                <criterion comment='clamav-daemon DPKG is earlier than 0.84-2.sarge.17' test_ref='oval:org.debian.oval:tst:1590'/>
                <criterion comment='clamav DPKG is earlier than 0.84-2.sarge.17' test_ref='oval:org.debian.oval:tst:1591'/>
                <criterion comment='libclamav1 DPKG is earlier than 0.84-2.sarge.17' test_ref='oval:org.debian.oval:tst:1592'/>
                <criterion comment='clamav-milter DPKG is earlier than 0.84-2.sarge.17' test_ref='oval:org.debian.oval:tst:1593'/>
                <criterion comment='clamav-freshclam DPKG is earlier than 0.84-2.sarge.17' test_ref='oval:org.debian.oval:tst:1594'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1321' class='vulnerability'>
      <metadata>
        <title>programming error</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>evolution-data-server</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3257' ref_id='CVE-2007-3257'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-06-23</date>
          <moreinfo>
It was discovered that the IMAP code in the Evolution Data Server
performs insufficient sanitising of a value later used an array index,
which can lead to the execution of arbitrary code.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criterion comment='evolution-data-server-common DPKG is earlier than 1.6.3-5etch1' test_ref='oval:org.debian.oval:tst:1595'/>
          </criteria>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libcamel1.2-8 DPKG is earlier than 1.6.3-5etch1' test_ref='oval:org.debian.oval:tst:1596'/>
            <criterion comment='libebook1.2-5 DPKG is earlier than 1.6.3-5etch1' test_ref='oval:org.debian.oval:tst:1597'/>
            <criterion comment='libedata-book1.2-2 DPKG is earlier than 1.6.3-5etch1' test_ref='oval:org.debian.oval:tst:1598'/>
            <criterion comment='libecal1.2-dev DPKG is earlier than 1.6.3-5etch1' test_ref='oval:org.debian.oval:tst:1599'/>
            <criterion comment='evolution-data-server-dev DPKG is earlier than 1.6.3-5etch1' test_ref='oval:org.debian.oval:tst:1600'/>
            <criterion comment='evolution-data-server DPKG is earlier than 1.6.3-5etch1' test_ref='oval:org.debian.oval:tst:1601'/>
            <criterion comment='libegroupwise1.2-dev DPKG is earlier than 1.6.3-5etch1' test_ref='oval:org.debian.oval:tst:1602'/>
            <criterion comment='libedata-book1.2-dev DPKG is earlier than 1.6.3-5etch1' test_ref='oval:org.debian.oval:tst:1603'/>
            <criterion comment='libegroupwise1.2-10 DPKG is earlier than 1.6.3-5etch1' test_ref='oval:org.debian.oval:tst:1604'/>
            <criterion comment='libexchange-storage1.2-1 DPKG is earlier than 1.6.3-5etch1' test_ref='oval:org.debian.oval:tst:1605'/>
            <criterion comment='libedataserverui1.2-dev DPKG is earlier than 1.6.3-5etch1' test_ref='oval:org.debian.oval:tst:1606'/>
            <criterion comment='libedata-cal1.2-5 DPKG is earlier than 1.6.3-5etch1' test_ref='oval:org.debian.oval:tst:1607'/>
            <criterion comment='libedataserver1.2-dev DPKG is earlier than 1.6.3-5etch1' test_ref='oval:org.debian.oval:tst:1608'/>
            <criterion comment='evolution-data-server-dbg DPKG is earlier than 1.6.3-5etch1' test_ref='oval:org.debian.oval:tst:1609'/>
            <criterion comment='libedata-cal1.2-dev DPKG is earlier than 1.6.3-5etch1' test_ref='oval:org.debian.oval:tst:1610'/>
            <criterion comment='libcamel1.2-dev DPKG is earlier than 1.6.3-5etch1' test_ref='oval:org.debian.oval:tst:1611'/>
            <criterion comment='libexchange-storage1.2-dev DPKG is earlier than 1.6.3-5etch1' test_ref='oval:org.debian.oval:tst:1612'/>
            <criterion comment='libedataserver1.2-7 DPKG is earlier than 1.6.3-5etch1' test_ref='oval:org.debian.oval:tst:1613'/>
            <criterion comment='libecal1.2-6 DPKG is earlier than 1.6.3-5etch1' test_ref='oval:org.debian.oval:tst:1614'/>
            <criterion comment='libebook1.2-dev DPKG is earlier than 1.6.3-5etch1' test_ref='oval:org.debian.oval:tst:1615'/>
            <criterion comment='libedataserverui1.2-6 DPKG is earlier than 1.6.3-5etch1' test_ref='oval:org.debian.oval:tst:1616'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1322' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>wireshark</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3390' ref_id='CVE-2007-3390'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3392' ref_id='CVE-2007-3392'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3393' ref_id='CVE-2007-3393'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-06-27</date>
          <moreinfo>
Several remote vulnerabilities have been discovered in the Wireshark
network traffic analyzer, which may lead to denial of service. The Common
Vulnerabilities and Exposures project identifies the following problems:
Off-by-one overflows were discovered in the iSeries dissector.
The MMS and SSL dissectors could be forced into an infinite loop.
An off-by-one overflow was discovered in the DHCP/BOOTP dissector.
The oldstable distribution (sarge) is not affected by these problems.
(In Sarge Wireshark used to be called Ethereal).</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='wireshark-dev DPKG is earlier than 0.99.4-5.etch.0' test_ref='oval:org.debian.oval:tst:1617'/>
              <criterion comment='tshark DPKG is earlier than 0.99.4-5.etch.0' test_ref='oval:org.debian.oval:tst:1618'/>
              <criterion comment='ethereal-dev DPKG is earlier than 0.99.4-5.etch.0' test_ref='oval:org.debian.oval:tst:1619'/>
              <criterion comment='tethereal DPKG is earlier than 0.99.4-5.etch.0' test_ref='oval:org.debian.oval:tst:1620'/>
              <criterion comment='wireshark-common DPKG is earlier than 0.99.4-5.etch.0' test_ref='oval:org.debian.oval:tst:1621'/>
              <criterion comment='ethereal DPKG is earlier than 0.99.4-5.etch.0' test_ref='oval:org.debian.oval:tst:1622'/>
              <criterion comment='ethereal-common DPKG is earlier than 0.99.4-5.etch.0' test_ref='oval:org.debian.oval:tst:1623'/>
              <criterion comment='wireshark DPKG is earlier than 0.99.4-5.etch.0' test_ref='oval:org.debian.oval:tst:1624'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1323' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>krb5</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2442' ref_id='CVE-2007-2442'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2443' ref_id='CVE-2007-2443'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2798' ref_id='CVE-2007-2798'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-06-28</date>
          <moreinfo>
Several remote vulnerabilities have been discovered in the MIT reference
implementation of the Kerberos network authentication protocol suite,
which may lead to the execution of arbitrary code. The Common 
Vulnerabilities and Exposures project identifies the following problems:
Wei Wang discovered that the free of an uninitialised pointer in the
    Kerberos RPC library may lead to the execution of arbitrary code.
Wei Wang discovered that insufficient input sanitising in the
    Kerberos RPC library may lead to the execution of arbitrary code.
It was discovered that a buffer overflow in the  Kerberos
    administration daemon may lead to the execution of arbitrary code.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
              <criterion comment='krb5-doc DPKG is earlier than 1.4.4-7etch2' test_ref='oval:org.debian.oval:tst:1625'/>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
                <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
                <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
                <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
                <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
                <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='krb5-rsh-server DPKG is earlier than 1.4.4-7etch2' test_ref='oval:org.debian.oval:tst:1626'/>
                <criterion comment='krb5-telnetd DPKG is earlier than 1.4.4-7etch2' test_ref='oval:org.debian.oval:tst:1627'/>
                <criterion comment='libkrb53 DPKG is earlier than 1.4.4-7etch2' test_ref='oval:org.debian.oval:tst:1628'/>
                <criterion comment='libkrb5-dev DPKG is earlier than 1.4.4-7etch2' test_ref='oval:org.debian.oval:tst:1629'/>
                <criterion comment='krb5-ftpd DPKG is earlier than 1.4.4-7etch2' test_ref='oval:org.debian.oval:tst:1630'/>
                <criterion comment='krb5-admin-server DPKG is earlier than 1.4.4-7etch2' test_ref='oval:org.debian.oval:tst:1631'/>
                <criterion comment='libkadm55 DPKG is earlier than 1.4.4-7etch2' test_ref='oval:org.debian.oval:tst:1632'/>
                <criterion comment='libkrb5-dbg DPKG is earlier than 1.4.4-7etch2' test_ref='oval:org.debian.oval:tst:1633'/>
                <criterion comment='krb5-user DPKG is earlier than 1.4.4-7etch2' test_ref='oval:org.debian.oval:tst:1634'/>
                <criterion comment='krb5-clients DPKG is earlier than 1.4.4-7etch2' test_ref='oval:org.debian.oval:tst:1635'/>
                <criterion comment='krb5-kdc DPKG is earlier than 1.4.4-7etch2' test_ref='oval:org.debian.oval:tst:1636'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
              <criterion comment='krb5-doc DPKG is earlier than 1.3.6-2sarge5' test_ref='oval:org.debian.oval:tst:1637'/>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
                <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
                <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:63'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
                <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
                <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
                <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='krb5-rsh-server DPKG is earlier than 1.3.6-2sarge5' test_ref='oval:org.debian.oval:tst:1638'/>
                <criterion comment='krb5-telnetd DPKG is earlier than 1.3.6-2sarge5' test_ref='oval:org.debian.oval:tst:1639'/>
                <criterion comment='libkrb53 DPKG is earlier than 1.3.6-2sarge5' test_ref='oval:org.debian.oval:tst:1640'/>
                <criterion comment='libkrb5-dev DPKG is earlier than 1.3.6-2sarge5' test_ref='oval:org.debian.oval:tst:1641'/>
                <criterion comment='krb5-ftpd DPKG is earlier than 1.3.6-2sarge5' test_ref='oval:org.debian.oval:tst:1642'/>
                <criterion comment='krb5-admin-server DPKG is earlier than 1.3.6-2sarge5' test_ref='oval:org.debian.oval:tst:1643'/>
                <criterion comment='libkadm55 DPKG is earlier than 1.3.6-2sarge5' test_ref='oval:org.debian.oval:tst:1644'/>
                <criterion comment='krb5-user DPKG is earlier than 1.3.6-2sarge5' test_ref='oval:org.debian.oval:tst:1645'/>
                <criterion comment='krb5-clients DPKG is earlier than 1.3.6-2sarge5' test_ref='oval:org.debian.oval:tst:1646'/>
                <criterion comment='krb5-kdc DPKG is earlier than 1.3.6-2sarge5' test_ref='oval:org.debian.oval:tst:1647'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1324' class='vulnerability'>
      <metadata>
        <title>missing input sanitising</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>hiki</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2836' ref_id='CVE-2007-2836'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-06-28</date>
          <moreinfo>
Kazuhiro Nishiyama found a vulnerability in hiki, a Wiki engine written
in Ruby, which could allow a remote attacker to delete arbitrary files
which are writable to the Hiki user, via a specially crafted session
parameter.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criterion comment='hiki DPKG is earlier than 0.8.6-1etch1' test_ref='oval:org.debian.oval:tst:1648'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1325' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>evolution</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1002' ref_id='CVE-2007-1002'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3257' ref_id='CVE-2007-3257'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-06-29</date>
          <moreinfo>
Several remote vulnerabilities have been discovered in Evolution, a
groupware suite with mail client and organizer. The Common Vulnerabilities
and Exposures project identifies the following problems:
Ulf Härnhammar discovered that a format string vulnerability in
    the handling of shared calendars may allow the execution of arbitrary
    code.
It was discovered that the IMAP code in the Evolution Data Server
    performs insufficient sanitising of a value later used an array index,
    which can lead to the execution of arbitrary code.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
              <criterion comment='evolution-common DPKG is earlier than 2.6.3-6etch1' test_ref='oval:org.debian.oval:tst:1649'/>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
                <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
                <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
                <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
                <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
                <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
                <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='evolution-dbg DPKG is earlier than 2.6.3-6etch1' test_ref='oval:org.debian.oval:tst:1650'/>
                <criterion comment='evolution DPKG is earlier than 2.6.3-6etch1' test_ref='oval:org.debian.oval:tst:1651'/>
                <criterion comment='evolution-dev DPKG is earlier than 2.6.3-6etch1' test_ref='oval:org.debian.oval:tst:1652'/>
                <criterion comment='evolution-plugins DPKG is earlier than 2.6.3-6etch1' test_ref='oval:org.debian.oval:tst:1653'/>
                <criterion comment='evolution-plugins-experimental DPKG is earlier than 2.6.3-6etch1' test_ref='oval:org.debian.oval:tst:1654'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
                <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
                <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:63'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
                <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
                <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
                <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='evolution DPKG is earlier than 2.0.4-2sarge2' test_ref='oval:org.debian.oval:tst:1655'/>
                <criterion comment='evolution-dev DPKG is earlier than 2.0.4-2sarge2' test_ref='oval:org.debian.oval:tst:1656'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1326' class='vulnerability'>
      <metadata>
        <title>insecure temporary files</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>fireflier-server</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2837' ref_id='CVE-2007-2837'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-07-01</date>
          <moreinfo>
Steve Kemp from the Debian Security Audit project discovered that 
fireflier-server, an interactive firewall rule creation tool, uses temporary 
files in an unsafe manner which may be exploited to remove arbitrary files from 
the local system.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='fireflier-client-gtk DPKG is earlier than 1.1.6-3etch1' test_ref='oval:org.debian.oval:tst:1657'/>
              <criterion comment='fireflier-server DPKG is earlier than 1.1.6-3etch1' test_ref='oval:org.debian.oval:tst:1658'/>
              <criterion comment='fireflier-client-qt DPKG is earlier than 1.1.6-3etch1' test_ref='oval:org.debian.oval:tst:1659'/>
              <criterion comment='fireflier-client-kde DPKG is earlier than 1.1.6-3etch1' test_ref='oval:org.debian.oval:tst:1660'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1327' class='vulnerability'>
      <metadata>
        <title>insecure temporary files</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>gsambad</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2838' ref_id='CVE-2007-2838'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-07-01</date>
          <moreinfo>
Steve Kemp from the Debian Security Audit project discovered that gsambad,
a GTK+ configuration tool for samba, uses temporary files in an unsafe
manner which may be exploited to truncate arbitrary files from the local system.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='gsambad DPKG is earlier than 0.1.4-2etch1' test_ref='oval:org.debian.oval:tst:1661'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1328' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>unicon-imc2</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2835' ref_id='CVE-2007-2835'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-07-01</date>
          <moreinfo>
Steve Kemp from the Debian Security Audit project discovered that
unicon-imc2, a Chinese input method library, makes unsafe use of
an environmental variable, which may be exploited to execute arbitrary
code.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='unicon-imc2 DPKG is earlier than 3.0.4-11etch1' test_ref='oval:org.debian.oval:tst:1662'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1330' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>php5</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1399' ref_id='CVE-2007-1399'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1864' ref_id='CVE-2007-1864'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-07-07</date>
          <moreinfo>
Several remote vulnerabilities have been discovered in PHP, a
server-side, HTML-embedded scripting language, which may lead to the
execution of arbitrary code. The Common Vulnerabilities and Exposures
project identifies the following problems:
Stefan Esser discovered that a buffer overflow in the zip extension
    allows the execution of arbitrary code.
It was discovered that a buffer overflow in the xmlrpc extension
    allows the execution of arbitrary code.
The oldstable distribution (sarge) doesn't include php5.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='php-pear DPKG is earlier than 5.2.0-8+etch7' test_ref='oval:org.debian.oval:tst:1663'/>
              <criterion comment='php5 DPKG is earlier than 5.2.0-8+etch7' test_ref='oval:org.debian.oval:tst:1664'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libapache-mod-php5 DPKG is earlier than 5.2.0-8+etch7' test_ref='oval:org.debian.oval:tst:1665'/>
              <criterion comment='php5-recode DPKG is earlier than 5.2.0-8+etch7' test_ref='oval:org.debian.oval:tst:1666'/>
              <criterion comment='php5-cgi DPKG is earlier than 5.2.0-8+etch7' test_ref='oval:org.debian.oval:tst:1667'/>
              <criterion comment='php5-curl DPKG is earlier than 5.2.0-8+etch7' test_ref='oval:org.debian.oval:tst:1668'/>
              <criterion comment='php5-snmp DPKG is earlier than 5.2.0-8+etch7' test_ref='oval:org.debian.oval:tst:1669'/>
              <criterion comment='php5-mysql DPKG is earlier than 5.2.0-8+etch7' test_ref='oval:org.debian.oval:tst:1670'/>
              <criterion comment='php5-odbc DPKG is earlier than 5.2.0-8+etch7' test_ref='oval:org.debian.oval:tst:1671'/>
              <criterion comment='php5-xsl DPKG is earlier than 5.2.0-8+etch7' test_ref='oval:org.debian.oval:tst:1672'/>
              <criterion comment='php5-gd DPKG is earlier than 5.2.0-8+etch7' test_ref='oval:org.debian.oval:tst:1673'/>
              <criterion comment='libapache2-mod-php5 DPKG is earlier than 5.2.0-8+etch7' test_ref='oval:org.debian.oval:tst:1674'/>
              <criterion comment='php5-mhash DPKG is earlier than 5.2.0-8+etch7' test_ref='oval:org.debian.oval:tst:1675'/>
              <criterion comment='php5-tidy DPKG is earlier than 5.2.0-8+etch7' test_ref='oval:org.debian.oval:tst:1676'/>
              <criterion comment='php5-mcrypt DPKG is earlier than 5.2.0-8+etch7' test_ref='oval:org.debian.oval:tst:1677'/>
              <criterion comment='php5-dev DPKG is earlier than 5.2.0-8+etch7' test_ref='oval:org.debian.oval:tst:1678'/>
              <criterion comment='php5-pgsql DPKG is earlier than 5.2.0-8+etch7' test_ref='oval:org.debian.oval:tst:1679'/>
              <criterion comment='php5-xmlrpc DPKG is earlier than 5.2.0-8+etch7' test_ref='oval:org.debian.oval:tst:1680'/>
              <criterion comment='php5-imap DPKG is earlier than 5.2.0-8+etch7' test_ref='oval:org.debian.oval:tst:1681'/>
              <criterion comment='php5-sqlite DPKG is earlier than 5.2.0-8+etch7' test_ref='oval:org.debian.oval:tst:1682'/>
              <criterion comment='php5-ldap DPKG is earlier than 5.2.0-8+etch7' test_ref='oval:org.debian.oval:tst:1683'/>
              <criterion comment='php5-cli DPKG is earlier than 5.2.0-8+etch7' test_ref='oval:org.debian.oval:tst:1684'/>
              <criterion comment='php5-sybase DPKG is earlier than 5.2.0-8+etch7' test_ref='oval:org.debian.oval:tst:1685'/>
              <criterion comment='php5-pspell DPKG is earlier than 5.2.0-8+etch7' test_ref='oval:org.debian.oval:tst:1686'/>
              <criterion comment='php5-common DPKG is earlier than 5.2.0-8+etch7' test_ref='oval:org.debian.oval:tst:1687'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='php5-interbase DPKG is earlier than 5.2.0-8+etch7' test_ref='oval:org.debian.oval:tst:1688'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1331' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>php4</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4486' ref_id='CVE-2006-4486'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0207' ref_id='CVE-2006-0207'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1864' ref_id='CVE-2007-1864'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-07-07</date>
          <moreinfo>
Several remote vulnerabilities have been discovered in PHP, a
server-side, HTML-embedded scripting language, which may lead to the
execution of arbitrary code. The Common Vulnerabilities and Exposures
project identifies the following problems:
Stefan Esser discovered HTTP response splitting vulnerabilities
    in the session extension. This only affects Debian 3.1 (Sarge).
Stefan Esser discovered that an integer overflow in memory allocation
    routines allows the bypass of memory limit restrictions. This only
    affects Debian 3.1 (Sarge) on 64 bit architectures.
It was discovered that a buffer overflow in the xmlrpc extension
    allows the execution of arbitrary code.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='php4 DPKG is earlier than 4.4.4-8+etch4' test_ref='oval:org.debian.oval:tst:1689'/>
                <criterion comment='php4-pear DPKG is earlier than 4.4.4-8+etch4' test_ref='oval:org.debian.oval:tst:1690'/>
              </criteria>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
                <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
                <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
                <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
                <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
                <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
                <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='libapache-mod-php4 DPKG is earlier than 4.4.4-8+etch4' test_ref='oval:org.debian.oval:tst:1691'/>
                <criterion comment='php4-recode DPKG is earlier than 4.4.4-8+etch4' test_ref='oval:org.debian.oval:tst:1692'/>
                <criterion comment='php4-xslt DPKG is earlier than 4.4.4-8+etch4' test_ref='oval:org.debian.oval:tst:1693'/>
                <criterion comment='php4-mcal DPKG is earlier than 4.4.4-8+etch4' test_ref='oval:org.debian.oval:tst:1694'/>
                <criterion comment='php4-domxml DPKG is earlier than 4.4.4-8+etch4' test_ref='oval:org.debian.oval:tst:1695'/>
                <criterion comment='php4-mhash DPKG is earlier than 4.4.4-8+etch4' test_ref='oval:org.debian.oval:tst:1696'/>
                <criterion comment='php4-odbc DPKG is earlier than 4.4.4-8+etch4' test_ref='oval:org.debian.oval:tst:1697'/>
                <criterion comment='libapache2-mod-php4 DPKG is earlier than 4.4.4-8+etch4' test_ref='oval:org.debian.oval:tst:1698'/>
                <criterion comment='php4-cli DPKG is earlier than 4.4.4-8+etch4' test_ref='oval:org.debian.oval:tst:1699'/>
                <criterion comment='php4-mcrypt DPKG is earlier than 4.4.4-8+etch4' test_ref='oval:org.debian.oval:tst:1700'/>
                <criterion comment='php4-gd DPKG is earlier than 4.4.4-8+etch4' test_ref='oval:org.debian.oval:tst:1701'/>
                <criterion comment='php4-mysql DPKG is earlier than 4.4.4-8+etch4' test_ref='oval:org.debian.oval:tst:1702'/>
                <criterion comment='php4-imap DPKG is earlier than 4.4.4-8+etch4' test_ref='oval:org.debian.oval:tst:1703'/>
                <criterion comment='php4-cgi DPKG is earlier than 4.4.4-8+etch4' test_ref='oval:org.debian.oval:tst:1704'/>
                <criterion comment='php4-pgsql DPKG is earlier than 4.4.4-8+etch4' test_ref='oval:org.debian.oval:tst:1705'/>
                <criterion comment='php4-snmp DPKG is earlier than 4.4.4-8+etch4' test_ref='oval:org.debian.oval:tst:1706'/>
                <criterion comment='php4-dev DPKG is earlier than 4.4.4-8+etch4' test_ref='oval:org.debian.oval:tst:1707'/>
                <criterion comment='php4-pspell DPKG is earlier than 4.4.4-8+etch4' test_ref='oval:org.debian.oval:tst:1708'/>
                <criterion comment='php4-ldap DPKG is earlier than 4.4.4-8+etch4' test_ref='oval:org.debian.oval:tst:1709'/>
                <criterion comment='php4-common DPKG is earlier than 4.4.4-8+etch4' test_ref='oval:org.debian.oval:tst:1710'/>
                <criterion comment='php4-curl DPKG is earlier than 4.4.4-8+etch4' test_ref='oval:org.debian.oval:tst:1711'/>
                <criterion comment='php4-sybase DPKG is earlier than 4.4.4-8+etch4' test_ref='oval:org.debian.oval:tst:1712'/>
              </criteria>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
                <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='php4-interbase DPKG is earlier than 4.4.4-8+etch4' test_ref='oval:org.debian.oval:tst:1713'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='php4 DPKG is earlier than 4.3.10-22' test_ref='oval:org.debian.oval:tst:1714'/>
                <criterion comment='php4-pear DPKG is earlier than 4.3.10-22' test_ref='oval:org.debian.oval:tst:1715'/>
              </criteria>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
                <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
                <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:63'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
                <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
                <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
                <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='php4-sybase DPKG is earlier than 4.3.10-22' test_ref='oval:org.debian.oval:tst:1716'/>
                <criterion comment='libapache-mod-php4 DPKG is earlier than 4.3.10-22' test_ref='oval:org.debian.oval:tst:1717'/>
                <criterion comment='php4-odbc DPKG is earlier than 4.3.10-22' test_ref='oval:org.debian.oval:tst:1718'/>
                <criterion comment='php4-recode DPKG is earlier than 4.3.10-22' test_ref='oval:org.debian.oval:tst:1719'/>
                <criterion comment='php4-dev DPKG is earlier than 4.3.10-22' test_ref='oval:org.debian.oval:tst:1720'/>
                <criterion comment='php4-gd DPKG is earlier than 4.3.10-22' test_ref='oval:org.debian.oval:tst:1721'/>
                <criterion comment='php4-xslt DPKG is earlier than 4.3.10-22' test_ref='oval:org.debian.oval:tst:1722'/>
                <criterion comment='php4-ldap DPKG is earlier than 4.3.10-22' test_ref='oval:org.debian.oval:tst:1723'/>
                <criterion comment='php4-snmp DPKG is earlier than 4.3.10-22' test_ref='oval:org.debian.oval:tst:1724'/>
                <criterion comment='php4-mysql DPKG is earlier than 4.3.10-22' test_ref='oval:org.debian.oval:tst:1725'/>
                <criterion comment='php4-mcal DPKG is earlier than 4.3.10-22' test_ref='oval:org.debian.oval:tst:1726'/>
                <criterion comment='php4-cli DPKG is earlier than 4.3.10-22' test_ref='oval:org.debian.oval:tst:1727'/>
                <criterion comment='php4-common DPKG is earlier than 4.3.10-22' test_ref='oval:org.debian.oval:tst:1728'/>
                <criterion comment='php4-mhash DPKG is earlier than 4.3.10-22' test_ref='oval:org.debian.oval:tst:1729'/>
                <criterion comment='php4-imap DPKG is earlier than 4.3.10-22' test_ref='oval:org.debian.oval:tst:1730'/>
                <criterion comment='php4-curl DPKG is earlier than 4.3.10-22' test_ref='oval:org.debian.oval:tst:1731'/>
                <criterion comment='php4-cgi DPKG is earlier than 4.3.10-22' test_ref='oval:org.debian.oval:tst:1732'/>
                <criterion comment='libapache2-mod-php4 DPKG is earlier than 4.3.10-22' test_ref='oval:org.debian.oval:tst:1733'/>
                <criterion comment='php4-domxml DPKG is earlier than 4.3.10-22' test_ref='oval:org.debian.oval:tst:1734'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1332' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>vlc</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3316' ref_id='CVE-2007-3316'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3467' ref_id='CVE-2007-3467'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3468' ref_id='CVE-2007-3468'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-07-09</date>
          <moreinfo>
Several remote vulnerabilities have been discovered in the VideoLan
multimedia player and streamer, which may lead to the execution of
arbitrary code. The Common Vulnerabilities and Exposures project
identifies the following problems:
David Thiel discovered that several format string vulnerabilities may
    lead to the execution of arbitrary code.
David Thiel discovered an integer overflow in the WAV processing code.
This update also fixes several crashes, which can be triggered through
malformed media files.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='wxvlc DPKG is earlier than 0.8.6-svn20061012.debian-5etch1' test_ref='oval:org.debian.oval:tst:1735'/>
                <criterion comment='vlc-plugin-alsa DPKG is earlier than 0.8.6-svn20061012.debian-5etch1' test_ref='oval:org.debian.oval:tst:1736'/>
              </criteria>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='vlc-plugin-arts DPKG is earlier than 0.8.6-svn20061012.debian-5etch1' test_ref='oval:org.debian.oval:tst:1737'/>
              <criterion comment='vlc DPKG is earlier than 0.8.6-svn20061012.debian-5etch1' test_ref='oval:org.debian.oval:tst:1738'/>
              <criterion comment='mozilla-plugin-vlc DPKG is earlier than 0.8.6-svn20061012.debian-5etch1' test_ref='oval:org.debian.oval:tst:1739'/>
              <criterion comment='vlc-plugin-ggi DPKG is earlier than 0.8.6-svn20061012.debian-5etch1' test_ref='oval:org.debian.oval:tst:1740'/>
              <criterion comment='vlc-plugin-esd DPKG is earlier than 0.8.6-svn20061012.debian-5etch1' test_ref='oval:org.debian.oval:tst:1741'/>
              <criterion comment='libvlc0-dev DPKG is earlier than 0.8.6-svn20061012.debian-5etch1' test_ref='oval:org.debian.oval:tst:1742'/>
              <criterion comment='libvlc0 DPKG is earlier than 0.8.6-svn20061012.debian-5etch1' test_ref='oval:org.debian.oval:tst:1743'/>
              <criterion comment='vlc-nox DPKG is earlier than 0.8.6-svn20061012.debian-5etch1' test_ref='oval:org.debian.oval:tst:1744'/>
              <criterion comment='vlc-plugin-sdl DPKG is earlier than 0.8.6-svn20061012.debian-5etch1' test_ref='oval:org.debian.oval:tst:1745'/>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='vlc-plugin-glide DPKG is earlier than 0.8.6-svn20061012.debian-5etch1' test_ref='oval:org.debian.oval:tst:1746'/>
                <criterion comment='vlc-plugin-svgalib DPKG is earlier than 0.8.6-svn20061012.debian-5etch1' test_ref='oval:org.debian.oval:tst:1747'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
                <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
                <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:63'/>
                <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
                <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:66'/>
                <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
                <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
                <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='vlc-qt DPKG is earlier than 0.8.1.svn20050314-1sarge3' test_ref='oval:org.debian.oval:tst:1748'/>
                <criterion comment='vlc-gtk DPKG is earlier than 0.8.1.svn20050314-1sarge3' test_ref='oval:org.debian.oval:tst:1749'/>
                <criterion comment='vlc-plugin-ggi DPKG is earlier than 0.8.1.svn20050314-1sarge3' test_ref='oval:org.debian.oval:tst:1750'/>
                <criterion comment='gvlc DPKG is earlier than 0.8.1.svn20050314-1sarge3' test_ref='oval:org.debian.oval:tst:1751'/>
                <criterion comment='vlc-plugin-arts DPKG is earlier than 0.8.1.svn20050314-1sarge3' test_ref='oval:org.debian.oval:tst:1752'/>
                <criterion comment='vlc DPKG is earlier than 0.8.1.svn20050314-1sarge3' test_ref='oval:org.debian.oval:tst:1753'/>
                <criterion comment='wxvlc DPKG is earlier than 0.8.1.svn20050314-1sarge3' test_ref='oval:org.debian.oval:tst:1754'/>
                <criterion comment='mozilla-plugin-vlc DPKG is earlier than 0.8.1.svn20050314-1sarge3' test_ref='oval:org.debian.oval:tst:1755'/>
                <criterion comment='qvlc DPKG is earlier than 0.8.1.svn20050314-1sarge3' test_ref='oval:org.debian.oval:tst:1756'/>
                <criterion comment='gnome-vlc DPKG is earlier than 0.8.1.svn20050314-1sarge3' test_ref='oval:org.debian.oval:tst:1757'/>
                <criterion comment='vlc-esd DPKG is earlier than 0.8.1.svn20050314-1sarge3' test_ref='oval:org.debian.oval:tst:1758'/>
                <criterion comment='libvlc0-dev DPKG is earlier than 0.8.1.svn20050314-1sarge3' test_ref='oval:org.debian.oval:tst:1759'/>
                <criterion comment='vlc-plugin-alsa DPKG is earlier than 0.8.1.svn20050314-1sarge3' test_ref='oval:org.debian.oval:tst:1760'/>
                <criterion comment='vlc-plugin-sdl DPKG is earlier than 0.8.1.svn20050314-1sarge3' test_ref='oval:org.debian.oval:tst:1761'/>
                <criterion comment='vlc-ggi DPKG is earlier than 0.8.1.svn20050314-1sarge3' test_ref='oval:org.debian.oval:tst:1762'/>
                <criterion comment='vlc-gnome DPKG is earlier than 0.8.1.svn20050314-1sarge3' test_ref='oval:org.debian.oval:tst:1763'/>
                <criterion comment='kvlc DPKG is earlier than 0.8.1.svn20050314-1sarge3' test_ref='oval:org.debian.oval:tst:1764'/>
                <criterion comment='vlc-alsa DPKG is earlier than 0.8.1.svn20050314-1sarge3' test_ref='oval:org.debian.oval:tst:1765'/>
                <criterion comment='vlc-plugin-esd DPKG is earlier than 0.8.1.svn20050314-1sarge3' test_ref='oval:org.debian.oval:tst:1766'/>
                <criterion comment='vlc-sdl DPKG is earlier than 0.8.1.svn20050314-1sarge3' test_ref='oval:org.debian.oval:tst:1767'/>
              </criteria>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='vlc-glide DPKG is earlier than 0.8.1.svn20050314-1sarge3' test_ref='oval:org.debian.oval:tst:1768'/>
                <criterion comment='vlc-plugin-glide DPKG is earlier than 0.8.1.svn20050314-1sarge3' test_ref='oval:org.debian.oval:tst:1769'/>
                <criterion comment='vlc-plugin-svgalib DPKG is earlier than 0.8.1.svn20050314-1sarge3' test_ref='oval:org.debian.oval:tst:1770'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1333' class='vulnerability'>
      <metadata>
        <title>missing input validation</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>libcurl3-gnutls</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3564' ref_id='CVE-2007-3564'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-07-18</date>
          <moreinfo>
It has been discovered that the GnuTLS certificate verification methods
implemented in libcurl-gnutls, a solid, usable, and portable multi-protocol
file transfer library, did not check for expired or invalid dates.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criterion comment='libcurl3-dev DPKG is earlier than 7.15.5-1etch1' test_ref='oval:org.debian.oval:tst:1771'/>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libcurl3-gnutls DPKG is earlier than 7.15.5-1etch1' test_ref='oval:org.debian.oval:tst:1772'/>
              <criterion comment='libcurl3-dbg DPKG is earlier than 7.15.5-1etch1' test_ref='oval:org.debian.oval:tst:1773'/>
              <criterion comment='libcurl3-gnutls-dev DPKG is earlier than 7.15.5-1etch1' test_ref='oval:org.debian.oval:tst:1774'/>
              <criterion comment='libcurl3 DPKG is earlier than 7.15.5-1etch1' test_ref='oval:org.debian.oval:tst:1775'/>
              <criterion comment='curl DPKG is earlier than 7.15.5-1etch1' test_ref='oval:org.debian.oval:tst:1776'/>
              <criterion comment='libcurl3-openssl-dev DPKG is earlier than 7.15.5-1etch1' test_ref='oval:org.debian.oval:tst:1777'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1335' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>gimp</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4519' ref_id='CVE-2006-4519'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2949' ref_id='CVE-2007-2949'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-07-18</date>
          <moreinfo>
Several remote vulnerabilities have been discovered in Gimp, the GNU Image
Manipulation Program, which might lead to the execution of arbitrary code.
The Common Vulnerabilities and Exposures project identifies the following
problems:
Sean Larsson discovered several integer overflows in the processing
    code for DICOM, PNM, PSD, RAS, XBM and XWD images, which might lead
    to the execution of arbitrary code if a user is tricked into opening
    such a malformed media file.
Stefan Cornelius discovered an integer overflow in the processing
    code for PSD images, which might lead to the execution of arbitrary
    code if a user is tricked into opening such a malformed media file.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='libgimp2.0-doc DPKG is earlier than 2.2.13-1etch4' test_ref='oval:org.debian.oval:tst:1778'/>
                <criterion comment='gimp-data DPKG is earlier than 2.2.13-1etch4' test_ref='oval:org.debian.oval:tst:1779'/>
              </criteria>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
                <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
                <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
                <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
                <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
                <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
                <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='libgimp2.0 DPKG is earlier than 2.2.13-1etch4' test_ref='oval:org.debian.oval:tst:1780'/>
                <criterion comment='gimp-svg DPKG is earlier than 2.2.13-1etch4' test_ref='oval:org.debian.oval:tst:1781'/>
                <criterion comment='gimp-helpbrowser DPKG is earlier than 2.2.13-1etch4' test_ref='oval:org.debian.oval:tst:1782'/>
                <criterion comment='gimp-python DPKG is earlier than 2.2.13-1etch4' test_ref='oval:org.debian.oval:tst:1783'/>
                <criterion comment='gimp-dbg DPKG is earlier than 2.2.13-1etch4' test_ref='oval:org.debian.oval:tst:1784'/>
                <criterion comment='libgimp2.0-dev DPKG is earlier than 2.2.13-1etch4' test_ref='oval:org.debian.oval:tst:1785'/>
                <criterion comment='gimp DPKG is earlier than 2.2.13-1etch4' test_ref='oval:org.debian.oval:tst:1786'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='libgimp2.0-doc DPKG is earlier than 2.2.6-1sarge4' test_ref='oval:org.debian.oval:tst:1787'/>
                <criterion comment='gimp-data DPKG is earlier than 2.2.6-1sarge4' test_ref='oval:org.debian.oval:tst:1788'/>
                <criterion comment='gimp1.2 DPKG is earlier than 2.2.6-1sarge4' test_ref='oval:org.debian.oval:tst:1789'/>
              </criteria>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
                <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
                <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:63'/>
                <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
                <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
                <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
                <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='libgimp2.0 DPKG is earlier than 2.2.6-1sarge4' test_ref='oval:org.debian.oval:tst:1790'/>
                <criterion comment='gimp-svg DPKG is earlier than 2.2.6-1sarge4' test_ref='oval:org.debian.oval:tst:1791'/>
                <criterion comment='gimp-helpbrowser DPKG is earlier than 2.2.6-1sarge4' test_ref='oval:org.debian.oval:tst:1792'/>
                <criterion comment='gimp-python DPKG is earlier than 2.2.6-1sarge4' test_ref='oval:org.debian.oval:tst:1793'/>
                <criterion comment='libgimp2.0-dev DPKG is earlier than 2.2.6-1sarge4' test_ref='oval:org.debian.oval:tst:1794'/>
                <criterion comment='gimp DPKG is earlier than 2.2.6-1sarge4' test_ref='oval:org.debian.oval:tst:1795'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1336' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>mozilla-firefox</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1282' ref_id='CVE-2007-1282'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0994' ref_id='CVE-2007-0994'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0995' ref_id='CVE-2007-0995'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0996' ref_id='CVE-2007-0996'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0981' ref_id='CVE-2007-0981'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0008' ref_id='CVE-2007-0008'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0009' ref_id='CVE-2007-0009'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0775' ref_id='CVE-2007-0775'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0778' ref_id='CVE-2007-0778'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0045' ref_id='CVE-2007-0045'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6077' ref_id='CVE-2006-6077'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-07-22</date>
          <moreinfo>
Several remote vulnerabilities have been discovered in Mozilla Firefox.
This will be the last security update of Mozilla-based products for
the oldstable (sarge) distribution of Debian. We recommend to upgrade
to stable (etch) as soon as possible.
The Common Vulnerabilities and Exposures project identifies the following
vulnerabilities:
It was discovered that an integer overflow in text/enhanced message
    parsing allows the execution of arbitrary code.
It was discovered that a regression in the Javascript engine allows
    the execution of Javascript with elevated privileges.
It was discovered that incorrect parsing of invalid HTML characters
    allows the bypass of content filters.
It was discovered that insecure child frame handling allows cross-site
    scripting.
It was discovered that Firefox handles URI with a null byte in the
    hostname insecurely.
It was discovered that a buffer overflow in the NSS code allows the
    execution of arbitrary code.
It was discovered that a buffer overflow in the NSS code allows the
    execution of arbitrary code.
It was discovered that multiple programming errors in the layout engine
    allow the execution of arbitrary code.
It was discovered that the page cache calculates hashes in an insecure
    manner.
It was discovered that the password manager allows the disclosure of
    passwords.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:63'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:66'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='mozilla-firefox-gnome-support DPKG is earlier than 1.0.4-2sarge17' test_ref='oval:org.debian.oval:tst:1796'/>
              <criterion comment='mozilla-firefox-dom-inspector DPKG is earlier than 1.0.4-2sarge17' test_ref='oval:org.debian.oval:tst:1797'/>
              <criterion comment='mozilla-firefox DPKG is earlier than 1.0.4-2sarge17' test_ref='oval:org.debian.oval:tst:1798'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='mozilla-firefox-gnome-support DPKG is earlier than 1.0.4-2sarge15' test_ref='oval:org.debian.oval:tst:1799'/>
              <criterion comment='mozilla-firefox-dom-inspector DPKG is earlier than 1.0.4-2sarge15' test_ref='oval:org.debian.oval:tst:1800'/>
              <criterion comment='mozilla-firefox DPKG is earlier than 1.0.4-2sarge15' test_ref='oval:org.debian.oval:tst:1801'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1337' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>xulrunner</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3089' ref_id='CVE-2007-3089'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3285' ref_id='CVE-2007-3285'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3656' ref_id='CVE-2007-3656'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3734' ref_id='CVE-2007-3734'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3735' ref_id='CVE-2007-3735'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3736' ref_id='CVE-2007-3736'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3737' ref_id='CVE-2007-3737'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3738' ref_id='CVE-2007-3738'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-07-22</date>
          <moreinfo>
Several remote vulnerabilities have been discovered in Xulrunner, a
runtime environment for XUL applications. The Common Vulnerabilities
and Exposures project identifies the following problems:
Ronen Zilberman and Michal Zalewski discovered that a timing race
    allows the injection of content into about:blank frames.
Michal Zalewski discovered that same-origin policies for wyciwyg://
    documents are insufficiently enforced.
Bernd Mielke, Boris Zbarsky, David Baron, Daniel Veditz, Jesse Ruderman,
    Lukas Loehrer, Martijn Wargers, Mats Palmgren, Olli Pettay, Paul
    Nickerson and Vladimir Sukhoy discovered crashes in the layout engine,
    which might allow the execution of arbitrary code.
Asaf Romano, Jesse Ruderman and Igor Bukanov discovered crashes in the
    javascript engine, which might allow the execution of arbitrary code.
&lt;q>moz_bug_r_a4&lt;/q> discovered that the addEventListener() and setTimeout()
    functions allow cross-site scripting.
&lt;q>moz_bug_r_a4&lt;/q> discovered that a programming error in event handling
    allows privilege escalation.
&lt;q>shutdown&lt;/q> and &lt;q>moz_bug_r_a4&lt;/q> discovered that the XPCNativeWrapper allows
    the execution of arbitrary code.
The oldstable distribution (sarge) doesn't include xulrunner.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libnspr4-dev DPKG is earlier than 1.8.0.13~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1802'/>
              <criterion comment='libmozjs-dev DPKG is earlier than 1.8.0.13~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1803'/>
              <criterion comment='libsmjs-dev DPKG is earlier than 1.8.0.13~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1804'/>
              <criterion comment='libmozillainterfaces-java DPKG is earlier than 1.8.0.13~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1805'/>
              <criterion comment='libxul-common DPKG is earlier than 1.8.0.13~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1806'/>
              <criterion comment='libsmjs1 DPKG is earlier than 1.8.0.13~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1807'/>
              <criterion comment='libxul-dev DPKG is earlier than 1.8.0.13~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1808'/>
              <criterion comment='libnss3-dev DPKG is earlier than 1.8.0.13~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1809'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libxul0d DPKG is earlier than 1.8.0.13~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1810'/>
              <criterion comment='libnss3-0d-dbg DPKG is earlier than 1.8.0.13~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1811'/>
              <criterion comment='libmozjs0d-dbg DPKG is earlier than 1.8.0.13~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1812'/>
              <criterion comment='libnss3-0d DPKG is earlier than 1.8.0.13~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1813'/>
              <criterion comment='spidermonkey-bin DPKG is earlier than 1.8.0.13~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1814'/>
              <criterion comment='libnspr4-0d-dbg DPKG is earlier than 1.8.0.13~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1815'/>
              <criterion comment='xulrunner-gnome-support DPKG is earlier than 1.8.0.13~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1816'/>
              <criterion comment='python-xpcom DPKG is earlier than 1.8.0.13~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1817'/>
              <criterion comment='libxul0d-dbg DPKG is earlier than 1.8.0.13~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1818'/>
              <criterion comment='xulrunner DPKG is earlier than 1.8.0.13~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1819'/>
              <criterion comment='libnss3-tools DPKG is earlier than 1.8.0.13~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1820'/>
              <criterion comment='libmozjs0d DPKG is earlier than 1.8.0.13~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1821'/>
              <criterion comment='libnspr4-0d DPKG is earlier than 1.8.0.13~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1822'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:66'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libxul0d DPKG is earlier than 1.8.0.12-0etch1' test_ref='oval:org.debian.oval:tst:1823'/>
              <criterion comment='libnss3-0d-dbg DPKG is earlier than 1.8.0.12-0etch1' test_ref='oval:org.debian.oval:tst:1824'/>
              <criterion comment='libmozjs0d-dbg DPKG is earlier than 1.8.0.12-0etch1' test_ref='oval:org.debian.oval:tst:1825'/>
              <criterion comment='libnss3-0d DPKG is earlier than 1.8.0.12-0etch1' test_ref='oval:org.debian.oval:tst:1826'/>
              <criterion comment='spidermonkey-bin DPKG is earlier than 1.8.0.12-0etch1' test_ref='oval:org.debian.oval:tst:1827'/>
              <criterion comment='libnspr4-0d-dbg DPKG is earlier than 1.8.0.12-0etch1' test_ref='oval:org.debian.oval:tst:1828'/>
              <criterion comment='xulrunner-gnome-support DPKG is earlier than 1.8.0.12-0etch1' test_ref='oval:org.debian.oval:tst:1829'/>
              <criterion comment='libxul0d-dbg DPKG is earlier than 1.8.0.12-0etch1' test_ref='oval:org.debian.oval:tst:1830'/>
              <criterion comment='libmozjs0d DPKG is earlier than 1.8.0.12-0etch1' test_ref='oval:org.debian.oval:tst:1831'/>
              <criterion comment='xulrunner DPKG is earlier than 1.8.0.12-0etch1' test_ref='oval:org.debian.oval:tst:1832'/>
              <criterion comment='libnss3-tools DPKG is earlier than 1.8.0.12-0etch1' test_ref='oval:org.debian.oval:tst:1833'/>
              <criterion comment='python-xpcom DPKG is earlier than 1.8.0.12-0etch1' test_ref='oval:org.debian.oval:tst:1834'/>
              <criterion comment='libnspr4-0d DPKG is earlier than 1.8.0.12-0etch1' test_ref='oval:org.debian.oval:tst:1835'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1338' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>iceweasel</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3089' ref_id='CVE-2007-3089'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3656' ref_id='CVE-2007-3656'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3734' ref_id='CVE-2007-3734'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3735' ref_id='CVE-2007-3735'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3736' ref_id='CVE-2007-3736'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3737' ref_id='CVE-2007-3737'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3738' ref_id='CVE-2007-3738'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-07-23</date>
          <moreinfo>
Several remote vulnerabilities have been discovered in the Iceweasel web
browser, an unbranded version of the Firefox browser. The Common 
Vulnerabilities and Exposures project identifies the following problems:
Ronen Zilberman and Michal Zalewski discovered that a timing race
    allows the injection of content into about:blank frames.
Michal Zalewski discovered that same-origin policies for wyciwyg://
    documents are insufficiently enforced.
Bernd Mielke, Boris Zbarsky, David Baron, Daniel Veditz, Jesse Ruderman,
    Lukas Loehrer, Martijn Wargers, Mats Palmgren, Olli Pettay, Paul
    Nickerson and Vladimir Sukhoy discovered crashes in the layout engine,
    which might allow the execution of arbitrary code.
Asaf Romano, Jesse Ruderman and Igor Bukanov discovered crashes in the
    javascript engine, which might allow the execution of arbitrary code.
&lt;q>moz_bug_r_a4&lt;/q> discovered that the addEventListener() and setTimeout()
    functions allow cross-site scripting.
&lt;q>moz_bug_r_a4&lt;/q> discovered that a programming error in event handling
    allows privilege escalation.
&lt;q>shutdown&lt;/q> and &lt;q>moz_bug_r_a4&lt;/q> discovered that the XPCNativeWrapper allows
    the execution of arbitrary code.
The Mozilla products in the oldstable distribution (sarge) are no longer
supported with security updates. You're strongly encouraged to upgrade to
stable as soon as possible.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='mozilla-firefox DPKG is earlier than 2.0.0.5-0etch1' test_ref='oval:org.debian.oval:tst:1836'/>
              <criterion comment='firefox DPKG is earlier than 2.0.0.5-0etch1' test_ref='oval:org.debian.oval:tst:1837'/>
              <criterion comment='firefox-dom-inspector DPKG is earlier than 2.0.0.5-0etch1' test_ref='oval:org.debian.oval:tst:1838'/>
              <criterion comment='iceweasel-dom-inspector DPKG is earlier than 2.0.0.5-0etch1' test_ref='oval:org.debian.oval:tst:1839'/>
              <criterion comment='mozilla-firefox-gnome-support DPKG is earlier than 2.0.0.5-0etch1' test_ref='oval:org.debian.oval:tst:1840'/>
              <criterion comment='mozilla-firefox-dom-inspector DPKG is earlier than 2.0.0.5-0etch1' test_ref='oval:org.debian.oval:tst:1841'/>
              <criterion comment='firefox-gnome-support DPKG is earlier than 2.0.0.5-0etch1' test_ref='oval:org.debian.oval:tst:1842'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='iceweasel-gnome-support DPKG is earlier than 2.0.0.5-0etch1' test_ref='oval:org.debian.oval:tst:1843'/>
              <criterion comment='iceweasel-dbg DPKG is earlier than 2.0.0.5-0etch1' test_ref='oval:org.debian.oval:tst:1844'/>
              <criterion comment='iceweasel DPKG is earlier than 2.0.0.5-0etch1' test_ref='oval:org.debian.oval:tst:1845'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1339' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>iceape</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3089' ref_id='CVE-2007-3089'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3656' ref_id='CVE-2007-3656'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3734' ref_id='CVE-2007-3734'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3735' ref_id='CVE-2007-3735'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3736' ref_id='CVE-2007-3736'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3737' ref_id='CVE-2007-3737'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3738' ref_id='CVE-2007-3738'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-07-23</date>
          <moreinfo>
Several remote vulnerabilities have been discovered in the Iceape internet
suite, an unbranded version of the Seamonkey Internet Suite. The Common
Vulnerabilities and Exposures project identifies the following problems:
Ronen Zilberman and Michal Zalewski discovered that a timing race
    allows the injection of content into about:blank frames.
Michal Zalewski discovered that same-origin policies for wyciwyg://
    documents are insufficiently enforced.
Bernd Mielke, Boris Zbarsky, David Baron, Daniel Veditz, Jesse Ruderman,
    Lukas Loehrer, Martijn Wargers, Mats Palmgren, Olli Pettay, Paul
    Nickerson and Vladimir Sukhoy discovered crashes in the layout engine,
    which might allow the execution of arbitrary code.
Asaf Romano, Jesse Ruderman and Igor Bukanov discovered crashes in the
    javascript engine, which might allow the execution of arbitrary code.
&lt;q>moz_bug_r_a4&lt;/q> discovered that the addEventListener() and setTimeout()
    functions allow cross-site scripting.
&lt;q>moz_bug_r_a4&lt;/q> discovered that a programming error in event handling
    allows privilege escalation.
&lt;q>shutdown&lt;/q> and &lt;q>moz_bug_r_a4&lt;/q> discovered that the XPCNativeWrapper allows
    the execution of arbitrary code.
The Mozilla products in the oldstable distribution (sarge) are no longer
supported with security updates. You're strongly encouraged to upgrade to
stable as soon as possible.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='mozilla-calendar DPKG is earlier than 1.8+1.0.10~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1846'/>
              <criterion comment='mozilla-chatzilla DPKG is earlier than 1.8+1.0.10~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1847'/>
              <criterion comment='iceape DPKG is earlier than 1.0.10~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1848'/>
              <criterion comment='iceape-chatzilla DPKG is earlier than 1.0.10~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1849'/>
              <criterion comment='iceape-dev DPKG is earlier than 1.0.10~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1850'/>
              <criterion comment='mozilla-psm DPKG is earlier than 1.8+1.0.10~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1851'/>
              <criterion comment='mozilla-mailnews DPKG is earlier than 1.8+1.0.10~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1852'/>
              <criterion comment='mozilla-dom-inspector DPKG is earlier than 1.8+1.0.10~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1853'/>
              <criterion comment='mozilla-js-debugger DPKG is earlier than 1.8+1.0.10~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1854'/>
              <criterion comment='mozilla-browser DPKG is earlier than 1.8+1.0.10~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1855'/>
              <criterion comment='mozilla-dev DPKG is earlier than 1.8+1.0.10~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1856'/>
              <criterion comment='mozilla DPKG is earlier than 1.8+1.0.10~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1857'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='iceape-dbg DPKG is earlier than 1.0.10~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1858'/>
              <criterion comment='iceape-dom-inspector DPKG is earlier than 1.0.10~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1859'/>
              <criterion comment='iceape-mailnews DPKG is earlier than 1.0.10~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1860'/>
              <criterion comment='iceape-browser DPKG is earlier than 1.0.10~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1861'/>
              <criterion comment='iceape-calendar DPKG is earlier than 1.0.10~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1862'/>
              <criterion comment='iceape-gnome-support DPKG is earlier than 1.0.10~pre070720-0etch1' test_ref='oval:org.debian.oval:tst:1863'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1340' class='vulnerability'>
      <metadata>
        <title>null pointer dereference</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>clamav</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3725' ref_id='CVE-2007-3725'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-07-24</date>
          <moreinfo>
A NULL pointer dereference has been discovered in the RAR VM of Clam
Antivirus (ClamAV) which allows user-assisted remote attackers to
cause a denial of service via a specially crafted RAR archives.
We are currently unable to provide fixed packages for the MIPS
architectures.  Those packages will be installed in the security
archive when they become available.
The old stable distribution (sarge) is not affected by this problem.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='clamav-docs DPKG is earlier than 0.90.1-3etch4' test_ref='oval:org.debian.oval:tst:1864'/>
              <criterion comment='clamav-testfiles DPKG is earlier than 0.90.1-3etch4' test_ref='oval:org.debian.oval:tst:1865'/>
              <criterion comment='clamav-base DPKG is earlier than 0.90.1-3etch4' test_ref='oval:org.debian.oval:tst:1866'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libclamav-dev DPKG is earlier than 0.90.1-3etch4' test_ref='oval:org.debian.oval:tst:1867'/>
              <criterion comment='clamav DPKG is earlier than 0.90.1-3etch4' test_ref='oval:org.debian.oval:tst:1868'/>
              <criterion comment='clamav-dbg DPKG is earlier than 0.90.1-3etch4' test_ref='oval:org.debian.oval:tst:1869'/>
              <criterion comment='libclamav2 DPKG is earlier than 0.90.1-3etch4' test_ref='oval:org.debian.oval:tst:1870'/>
              <criterion comment='clamav-daemon DPKG is earlier than 0.90.1-3etch4' test_ref='oval:org.debian.oval:tst:1871'/>
              <criterion comment='clamav-milter DPKG is earlier than 0.90.1-3etch4' test_ref='oval:org.debian.oval:tst:1872'/>
              <criterion comment='clamav-freshclam DPKG is earlier than 0.90.1-3etch4' test_ref='oval:org.debian.oval:tst:1873'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1341' class='vulnerability'>
      <metadata>
        <title>design error</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>bind9</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2926' ref_id='CVE-2007-2926'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-07-25</date>
          <moreinfo>
This update provides fixed packages for the oldstable distribution (sarge).
For reference the original advisory text:
Amit Klein discovered that the BIND name server generates predictable 
DNS query IDs, which may lead to cache poisoning attacks.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
              <criterion comment='bind9-doc DPKG is earlier than 9.3.4-2etch1' test_ref='oval:org.debian.oval:tst:1874'/>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
                <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
                <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
                <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
                <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
                <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='dnsutils DPKG is earlier than 9.3.4-2etch1' test_ref='oval:org.debian.oval:tst:1875'/>
                <criterion comment='libbind-dev DPKG is earlier than 9.3.4-2etch1' test_ref='oval:org.debian.oval:tst:1876'/>
                <criterion comment='libdns22 DPKG is earlier than 9.3.4-2etch1' test_ref='oval:org.debian.oval:tst:1877'/>
                <criterion comment='libisccfg1 DPKG is earlier than 9.3.4-2etch1' test_ref='oval:org.debian.oval:tst:1878'/>
                <criterion comment='libisccc0 DPKG is earlier than 9.3.4-2etch1' test_ref='oval:org.debian.oval:tst:1879'/>
                <criterion comment='libisc11 DPKG is earlier than 9.3.4-2etch1' test_ref='oval:org.debian.oval:tst:1880'/>
                <criterion comment='libbind9-0 DPKG is earlier than 9.3.4-2etch1' test_ref='oval:org.debian.oval:tst:1881'/>
                <criterion comment='lwresd DPKG is earlier than 9.3.4-2etch1' test_ref='oval:org.debian.oval:tst:1882'/>
                <criterion comment='bind9 DPKG is earlier than 9.3.4-2etch1' test_ref='oval:org.debian.oval:tst:1883'/>
                <criterion comment='liblwres9 DPKG is earlier than 9.3.4-2etch1' test_ref='oval:org.debian.oval:tst:1884'/>
                <criterion comment='bind9-host DPKG is earlier than 9.3.4-2etch1' test_ref='oval:org.debian.oval:tst:1885'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
              <criterion comment='bind9-doc DPKG is earlier than 9.2.4-1sarge3' test_ref='oval:org.debian.oval:tst:1886'/>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
                <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
                <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:63'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
                <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
                <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
                <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='dnsutils DPKG is earlier than 9.2.4-1sarge3' test_ref='oval:org.debian.oval:tst:1887'/>
                <criterion comment='libbind-dev DPKG is earlier than 9.2.4-1sarge3' test_ref='oval:org.debian.oval:tst:1888'/>
                <criterion comment='libisccfg0 DPKG is earlier than 9.2.4-1sarge3' test_ref='oval:org.debian.oval:tst:1889'/>
                <criterion comment='libisccc0 DPKG is earlier than 9.2.4-1sarge3' test_ref='oval:org.debian.oval:tst:1890'/>
                <criterion comment='libisc7 DPKG is earlier than 9.2.4-1sarge3' test_ref='oval:org.debian.oval:tst:1891'/>
                <criterion comment='lwresd DPKG is earlier than 9.2.4-1sarge3' test_ref='oval:org.debian.oval:tst:1892'/>
                <criterion comment='liblwres1 DPKG is earlier than 9.2.4-1sarge3' test_ref='oval:org.debian.oval:tst:1893'/>
                <criterion comment='bind9-host DPKG is earlier than 9.2.4-1sarge3' test_ref='oval:org.debian.oval:tst:1894'/>
                <criterion comment='bind9 DPKG is earlier than 9.2.4-1sarge3' test_ref='oval:org.debian.oval:tst:1895'/>
                <criterion comment='libdns16 DPKG is earlier than 9.2.4-1sarge3' test_ref='oval:org.debian.oval:tst:1896'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1342' class='vulnerability'>
      <metadata>
        <title>race condition</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>xfs</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3103' ref_id='CVE-2007-3103'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-07-30</date>
          <moreinfo>
It was discovered that a race condition in the init.d script of the X Font
Server allows the modification of file permissions of arbitrary files if
the local administrator can be tricked into restarting the X font server.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='xfs DPKG is earlier than 1.0.1-6' test_ref='oval:org.debian.oval:tst:1897'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1343' class='vulnerability'>
      <metadata>
        <title>integer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>file</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2799' ref_id='CVE-2007-2799'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-07-31</date>
          <moreinfo>
Colin Percival discovered an integer overflow in file, a file type
classification tool, which may lead to the execution of arbitrary code.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libmagic-dev DPKG is earlier than 4.17-5etch2' test_ref='oval:org.debian.oval:tst:1898'/>
              <criterion comment='python-magic DPKG is earlier than 4.17-5etch2' test_ref='oval:org.debian.oval:tst:1899'/>
              <criterion comment='libmagic1 DPKG is earlier than 4.17-5etch2' test_ref='oval:org.debian.oval:tst:1900'/>
              <criterion comment='file DPKG is earlier than 4.17-5etch2' test_ref='oval:org.debian.oval:tst:1901'/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
                <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
                <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:63'/>
                <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
                <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:66'/>
                <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
                <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
                <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='libmagic-dev DPKG is earlier than 4.12-1sarge2' test_ref='oval:org.debian.oval:tst:1902'/>
                <criterion comment='libmagic1 DPKG is earlier than 4.12-1sarge2' test_ref='oval:org.debian.oval:tst:1903'/>
                <criterion comment='file DPKG is earlier than 4.12-1sarge2' test_ref='oval:org.debian.oval:tst:1904'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1344' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>iceweasel</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3844' ref_id='CVE-2007-3844'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3845' ref_id='CVE-2007-3845'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-08-03</date>
          <moreinfo>
Several remote vulnerabilities have been discovered in the Iceweasel web
browser, an unbranded version of the Firefox browser. The Common 
Vulnerabilities and Exposures project identifies the following problems:
&lt;q>moz_bug_r_a4&lt;/q> discovered that a regression in the handling of
    &lt;q>about:blank&lt;/q> windows used by addons may lead to an attacker being
    able to modify the content of web sites.
Jesper Johansson discovered that missing sanitising of double-quotes
    and spaces in URIs passed to external programs may allow an attacker
    to pass arbitrary arguments to the helper program if the user is
    tricked into opening a malformed web page.
The Mozilla products in the oldstable distribution (sarge) are no longer
supported with security updates.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='mozilla-firefox DPKG is earlier than 2.0.0.6-0etch1' test_ref='oval:org.debian.oval:tst:1905'/>
              <criterion comment='firefox DPKG is earlier than 2.0.0.6-0etch1' test_ref='oval:org.debian.oval:tst:1906'/>
              <criterion comment='firefox-dom-inspector DPKG is earlier than 2.0.0.6-0etch1' test_ref='oval:org.debian.oval:tst:1907'/>
              <criterion comment='iceweasel-dom-inspector DPKG is earlier than 2.0.0.6-0etch1' test_ref='oval:org.debian.oval:tst:1908'/>
              <criterion comment='mozilla-firefox-gnome-support DPKG is earlier than 2.0.0.6-0etch1' test_ref='oval:org.debian.oval:tst:1909'/>
              <criterion comment='mozilla-firefox-dom-inspector DPKG is earlier than 2.0.0.6-0etch1' test_ref='oval:org.debian.oval:tst:1910'/>
              <criterion comment='firefox-gnome-support DPKG is earlier than 2.0.0.6-0etch1' test_ref='oval:org.debian.oval:tst:1911'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='iceweasel-gnome-support DPKG is earlier than 2.0.0.6-0etch1' test_ref='oval:org.debian.oval:tst:1912'/>
              <criterion comment='iceweasel-dbg DPKG is earlier than 2.0.0.6-0etch1' test_ref='oval:org.debian.oval:tst:1913'/>
              <criterion comment='iceweasel DPKG is earlier than 2.0.0.6-0etch1' test_ref='oval:org.debian.oval:tst:1914'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1345' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>xulrunner</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3844' ref_id='CVE-2007-3844'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3845' ref_id='CVE-2007-3845'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-08-04</date>
          <moreinfo>
Several remote vulnerabilities have been discovered in Xulrunner, a
runtime environment for XUL applications. The Common Vulnerabilities
and Exposures project identifies the following problems:
&lt;q>moz_bug_r_a4&lt;/q> discovered that a regression in the handling of
    &lt;q>about:blank&lt;/q> windows used by addons may lead to an attacker being
    able to modify the content of web sites.
Jesper Johansson discovered that missing sanitising of double-quotes
    and spaces in URIs passed to external programs may allow an attacker
    to pass arbitrary arguments to the helper program if the user is
    tricked into opening a malformed web page.
The oldstable distribution (sarge) doesn't include xulrunner.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libnspr4-dev DPKG is earlier than 1.8.0.13~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1915'/>
              <criterion comment='libmozjs-dev DPKG is earlier than 1.8.0.13~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1916'/>
              <criterion comment='libsmjs-dev DPKG is earlier than 1.8.0.13~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1917'/>
              <criterion comment='libmozillainterfaces-java DPKG is earlier than 1.8.0.13~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1918'/>
              <criterion comment='libxul-common DPKG is earlier than 1.8.0.13~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1919'/>
              <criterion comment='libsmjs1 DPKG is earlier than 1.8.0.13~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1920'/>
              <criterion comment='libxul-dev DPKG is earlier than 1.8.0.13~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1921'/>
              <criterion comment='libnss3-dev DPKG is earlier than 1.8.0.13~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1922'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libxul0d DPKG is earlier than 1.8.0.13~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1923'/>
              <criterion comment='libnss3-0d-dbg DPKG is earlier than 1.8.0.13~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1924'/>
              <criterion comment='libmozjs0d-dbg DPKG is earlier than 1.8.0.13~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1925'/>
              <criterion comment='libnss3-0d DPKG is earlier than 1.8.0.13~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1926'/>
              <criterion comment='spidermonkey-bin DPKG is earlier than 1.8.0.13~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1927'/>
              <criterion comment='libnspr4-0d-dbg DPKG is earlier than 1.8.0.13~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1928'/>
              <criterion comment='xulrunner-gnome-support DPKG is earlier than 1.8.0.13~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1929'/>
              <criterion comment='python-xpcom DPKG is earlier than 1.8.0.13~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1930'/>
              <criterion comment='libxul0d-dbg DPKG is earlier than 1.8.0.13~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1931'/>
              <criterion comment='xulrunner DPKG is earlier than 1.8.0.13~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1932'/>
              <criterion comment='libnss3-tools DPKG is earlier than 1.8.0.13~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1933'/>
              <criterion comment='libmozjs0d DPKG is earlier than 1.8.0.13~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1934'/>
              <criterion comment='libnspr4-0d DPKG is earlier than 1.8.0.13~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1935'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1346' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>iceape</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3844' ref_id='CVE-2007-3844'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3845' ref_id='CVE-2007-3845'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-08-04</date>
          <moreinfo>
Several remote vulnerabilities have been discovered in the Iceape internet
suite, an unbranded version of the Seamonkey Internet Suite. The Common
Vulnerabilities and Exposures project identifies the following problems:
&lt;q>moz_bug_r_a4&lt;/q> discovered that a regression in the handling of
    &lt;q>about:blank&lt;/q> windows used by addons may lead to an attacker being
    able to modify the content of web sites.
Jesper Johansson discovered that missing sanitising of double-quotes
    and spaces in URIs passed to external programs may allow an attacker
    to pass arbitrary arguments to the helper program if the user is
    tricked into opening a malformed web page.
The Mozilla products in the oldstable distribution (sarge) are no longer
supported with security updates.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture independet section' operator='AND'>
            <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='mozilla-calendar DPKG is earlier than 1.8+1.0.10~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1936'/>
              <criterion comment='mozilla-chatzilla DPKG is earlier than 1.8+1.0.10~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1937'/>
              <criterion comment='iceape DPKG is earlier than 1.0.10~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1938'/>
              <criterion comment='iceape-chatzilla DPKG is earlier than 1.0.10~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1939'/>
              <criterion comment='iceape-dev DPKG is earlier than 1.0.10~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1940'/>
              <criterion comment='mozilla-psm DPKG is earlier than 1.8+1.0.10~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1941'/>
              <criterion comment='mozilla-mailnews DPKG is earlier than 1.8+1.0.10~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1942'/>
              <criterion comment='mozilla-dom-inspector DPKG is earlier than 1.8+1.0.10~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1943'/>
              <criterion comment='mozilla-js-debugger DPKG is earlier than 1.8+1.0.10~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1944'/>
              <criterion comment='mozilla-browser DPKG is earlier than 1.8+1.0.10~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1945'/>
              <criterion comment='mozilla-dev DPKG is earlier than 1.8+1.0.10~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1946'/>
              <criterion comment='mozilla DPKG is earlier than 1.8+1.0.10~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1947'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='iceape-dbg DPKG is earlier than 1.0.10~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1948'/>
              <criterion comment='iceape-dom-inspector DPKG is earlier than 1.0.10~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1949'/>
              <criterion comment='iceape-mailnews DPKG is earlier than 1.0.10~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1950'/>
              <criterion comment='iceape-browser DPKG is earlier than 1.0.10~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1951'/>
              <criterion comment='iceape-calendar DPKG is earlier than 1.0.10~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1952'/>
              <criterion comment='iceape-gnome-support DPKG is earlier than 1.0.10~pre070720-0etch3' test_ref='oval:org.debian.oval:tst:1953'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1347' class='vulnerability'>
      <metadata>
        <title>integer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>xpdf</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3387' ref_id='CVE-2007-3387'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-08-04</date>
          <moreinfo>
It was discovered that an integer overflow in the xpdf PDF viewer may lead
to the execution of arbitrary code if a malformed PDF file is opened.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='xpdf-common DPKG is earlier than 3.01-9etch1' test_ref='oval:org.debian.oval:tst:1954'/>
                <criterion comment='xpdf DPKG is earlier than 3.01-9etch1' test_ref='oval:org.debian.oval:tst:1955'/>
              </criteria>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
                <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
                <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
                <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:66'/>
                <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
                <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
                <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='xpdf-utils DPKG is earlier than 3.01-9etch1' test_ref='oval:org.debian.oval:tst:1956'/>
                <criterion comment='xpdf-reader DPKG is earlier than 3.01-9etch1' test_ref='oval:org.debian.oval:tst:1957'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='xpdf-common DPKG is earlier than 3.00-13.7' test_ref='oval:org.debian.oval:tst:1958'/>
                <criterion comment='xpdf DPKG is earlier than 3.00-13.7' test_ref='oval:org.debian.oval:tst:1959'/>
              </criteria>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
                <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
                <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:63'/>
                <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
                <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:66'/>
                <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
                <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
                <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='xpdf-utils DPKG is earlier than 3.00-13.7' test_ref='oval:org.debian.oval:tst:1960'/>
                <criterion comment='xpdf-reader DPKG is earlier than 3.00-13.7' test_ref='oval:org.debian.oval:tst:1961'/>
              </criteria>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='xpdf-utils DPKG is earlier than 3.00-13.6' test_ref='oval:org.debian.oval:tst:1962'/>
                <criterion comment='xpdf-reader DPKG is earlier than 3.00-13.6' test_ref='oval:org.debian.oval:tst:1963'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1348' class='vulnerability'>
      <metadata>
        <title>integer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>poppler</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3387' ref_id='CVE-2007-3387'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-08-04</date>
          <moreinfo>
It was discovered that an integer overflow in the xpdf PDF viewer may lead
to the execution of arbitrary code if a malformed PDF file is opened.
poppler includes a copy of the xpdf code and required an update as well.
The oldstable distribution (sarge) doesn't include poppler.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:66'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='poppler-utils DPKG is earlier than 0.4.5-5.1etch1' test_ref='oval:org.debian.oval:tst:1964'/>
              <criterion comment='libpoppler0c2 DPKG is earlier than 0.4.5-5.1etch1' test_ref='oval:org.debian.oval:tst:1965'/>
              <criterion comment='libpoppler-dev DPKG is earlier than 0.4.5-5.1etch1' test_ref='oval:org.debian.oval:tst:1966'/>
              <criterion comment='libpoppler-qt-dev DPKG is earlier than 0.4.5-5.1etch1' test_ref='oval:org.debian.oval:tst:1967'/>
              <criterion comment='libpoppler0c2-glib DPKG is earlier than 0.4.5-5.1etch1' test_ref='oval:org.debian.oval:tst:1968'/>
              <criterion comment='libpoppler-glib-dev DPKG is earlier than 0.4.5-5.1etch1' test_ref='oval:org.debian.oval:tst:1969'/>
              <criterion comment='libpoppler0c2-qt DPKG is earlier than 0.4.5-5.1etch1' test_ref='oval:org.debian.oval:tst:1970'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1349' class='vulnerability'>
      <metadata>
        <title>integer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>libextractor</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3387' ref_id='CVE-2007-3387'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-08-05</date>
          <moreinfo>
It was discovered that an integer overflow in the xpdf PDF viewer may lead
to the execution of arbitrary code if a malformed PDF file is opened.
libextractor includes a copy of the xpdf code and required an update
as well.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:63'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:66'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='libextractor1-dev DPKG is earlier than 0.4.2-2sarge6' test_ref='oval:org.debian.oval:tst:1971'/>
              <criterion comment='extract DPKG is earlier than 0.4.2-2sarge6' test_ref='oval:org.debian.oval:tst:1972'/>
              <criterion comment='libextractor1 DPKG is earlier than 0.4.2-2sarge6' test_ref='oval:org.debian.oval:tst:1973'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1350' class='vulnerability'>
      <metadata>
        <title>integer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>tetex-bin</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3387' ref_id='CVE-2007-3387'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-08-06</date>
          <moreinfo>
It was discovered that an integer overflow in the xpdf PDF viewer may lead
to the execution of arbitrary code if a malformed PDF file is opened.
tetex-bin includes a copy of the xpdf code and required an update as
well.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Packages section' operator='OR'>
            <criterion comment='libkpathsea-dev DPKG is earlier than 2.0.2-30sarge5' test_ref='oval:org.debian.oval:tst:1974'/>
            <criterion comment='libkpathsea3 DPKG is earlier than 2.0.2-30sarge5' test_ref='oval:org.debian.oval:tst:1975'/>
            <criterion comment='tetex-bin DPKG is earlier than 2.0.2-30sarge5' test_ref='oval:org.debian.oval:tst:1976'/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1351' class='vulnerability'>
      <metadata>
        <title>buffer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>bochs</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2893' ref_id='CVE-2007-2893'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-08-07</date>
          <moreinfo>
Tavis Ormandy discovered that bochs, a highly portable IA-32 PC emulator,
is vulnerable to a buffer overflow in the emulated NE2000 network device
driver, which may lead to privilege escalation.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='bochsbios DPKG is earlier than 2.3-2etch1' test_ref='oval:org.debian.oval:tst:1977'/>
                <criterion comment='bochs-doc DPKG is earlier than 2.3-2etch1' test_ref='oval:org.debian.oval:tst:1978'/>
              </criteria>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='bochs-x DPKG is earlier than 2.3-2etch1' test_ref='oval:org.debian.oval:tst:1979'/>
              <criterion comment='bochs-term DPKG is earlier than 2.3-2etch1' test_ref='oval:org.debian.oval:tst:1980'/>
              <criterion comment='bochs-wx DPKG is earlier than 2.3-2etch1' test_ref='oval:org.debian.oval:tst:1981'/>
              <criterion comment='bximage DPKG is earlier than 2.3-2etch1' test_ref='oval:org.debian.oval:tst:1982'/>
              <criterion comment='bochs DPKG is earlier than 2.3-2etch1' test_ref='oval:org.debian.oval:tst:1983'/>
              <criterion comment='bochs-sdl DPKG is earlier than 2.3-2etch1' test_ref='oval:org.debian.oval:tst:1984'/>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='bochs-svga DPKG is earlier than 2.3-2etch1' test_ref='oval:org.debian.oval:tst:1985'/>
                <criterion comment='sb16ctrl-bochs DPKG is earlier than 2.3-2etch1' test_ref='oval:org.debian.oval:tst:1986'/>
              </criteria>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported platform section' operator='AND'>
                <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
                <criteria comment='Packages section' operator='OR'>
                  <criterion comment='bochs-svga DPKG is earlier than 2.3-2etch1' test_ref='oval:org.debian.oval:tst:1987'/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='bochsbios DPKG is earlier than 2.1.1+20041109-3sarge1' test_ref='oval:org.debian.oval:tst:1988'/>
                <criterion comment='bochs-doc DPKG is earlier than 2.1.1+20041109-3sarge1' test_ref='oval:org.debian.oval:tst:1989'/>
              </criteria>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='bochs-x DPKG is earlier than 2.1.1+20041109-3sarge1' test_ref='oval:org.debian.oval:tst:1990'/>
              <criterion comment='bochs-term DPKG is earlier than 2.1.1+20041109-3sarge1' test_ref='oval:org.debian.oval:tst:1991'/>
              <criterion comment='bochs-wx DPKG is earlier than 2.1.1+20041109-3sarge1' test_ref='oval:org.debian.oval:tst:1992'/>
              <criterion comment='bximage DPKG is earlier than 2.1.1+20041109-3sarge1' test_ref='oval:org.debian.oval:tst:1993'/>
              <criterion comment='bochs DPKG is earlier than 2.1.1+20041109-3sarge1' test_ref='oval:org.debian.oval:tst:1994'/>
              <criterion comment='bochs-sdl DPKG is earlier than 2.1.1+20041109-3sarge1' test_ref='oval:org.debian.oval:tst:1995'/>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='bochs-svga DPKG is earlier than 2.1.1+20041109-3sarge1' test_ref='oval:org.debian.oval:tst:1996'/>
                <criterion comment='sb16ctrl-bochs DPKG is earlier than 2.1.1+20041109-3sarge1' test_ref='oval:org.debian.oval:tst:1997'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1352' class='vulnerability'>
      <metadata>
        <title>integer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>pdfkit.framework</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3387' ref_id='CVE-2007-3387'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-08-07</date>
          <moreinfo>
It was discovered that an integer overflow in the xpdf PDF viewer may lead
to the execution of arbitrary code if a malformed PDF file is opened.
pdfkit.framework includes a copy of the xpdf code and required an update
as well.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:63'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:66'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='pdfkit.framework DPKG is earlier than 0.8-2sarge4' test_ref='oval:org.debian.oval:tst:1998'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1353' class='vulnerability'>
      <metadata>
        <title>integer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>tcpdump</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3798' ref_id='CVE-2007-3798'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-08-11</date>
          <moreinfo>
It was discovered that an integer overflow in the BGP dissector of tcpdump,
a powerful tool for network monitoring and data acquisition, may lead to
the execution of arbitrary code.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
                <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
                <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
                <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
                <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
                <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
                <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='tcpdump DPKG is earlier than 3.9.5-2etch1' test_ref='oval:org.debian.oval:tst:1999'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='tcpdump DPKG is earlier than 3.8.3-5sarge3' test_ref='oval:org.debian.oval:tst:2000'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1354' class='vulnerability'>
      <metadata>
        <title>integer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>gpdf</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3387' ref_id='CVE-2007-3387'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-08-13</date>
          <moreinfo>
It was discovered that an integer overflow in xpdf PDF viewer may lead
to the execution of arbitrary code if a malformed PDF file is opened.
gpdf includes a copy of the xpdf code and requires an update as well.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Release section' operator='AND'>
        <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
        <criteria comment='Architecture section' operator='OR'>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
              <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
              <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
              <criterion comment='m68k architecture' test_ref='oval:org.debian.oval:tst:63'/>
              <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
              <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
              <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:66'/>
              <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
              <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
              <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
              <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='gpdf DPKG is earlier than 2.8.2-1.2sarge6' test_ref='oval:org.debian.oval:tst:2001'/>
            </criteria>
          </criteria>
          <criteria comment='Architecture depended section' operator='AND'>
            <criteria comment='Supported architectures section' operator='OR'>
              <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
            </criteria>
            <criteria comment='Packages section' operator='OR'>
              <criterion comment='gpdf DPKG is earlier than 2.8.2-1.2sarge5' test_ref='oval:org.debian.oval:tst:2002'/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1355' class='vulnerability'>
      <metadata>
        <title>integer overflow</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>kdegraphics</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3387' ref_id='CVE-2007-3387'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-08-13</date>
          <moreinfo>
It was discovered that an integer overflow in the xpdf PDF viewer may lead
to the execution of arbitrary code if a malformed PDF file is opened.
kpdf includes a copy of the xpdf code and required an update as well.</moreinfo>
        </debian>
      </metadata>
      <criteria comment='Platform section' operator='OR'>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 4.0 is installed' test_ref='oval:org.debian.oval:tst:393'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='kdegraphics DPKG is earlier than 3.5.5-3etch1' test_ref='oval:org.debian.oval:tst:2003'/>
                <criterion comment='kdegraphics-doc-html DPKG is earlier than 3.5.5-3etch1' test_ref='oval:org.debian.oval:tst:2004'/>
              </criteria>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
                <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
                <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
                <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
                <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
                <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
                <criterion comment='hppa architecture' test_ref='oval:org.debian.oval:tst:68'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='kdegraphics-kfile-plugins DPKG is earlier than 3.5.5-3etch1' test_ref='oval:org.debian.oval:tst:2005'/>
                <criterion comment='ksvg DPKG is earlier than 3.5.5-3etch1' test_ref='oval:org.debian.oval:tst:2006'/>
                <criterion comment='libkscan-dev DPKG is earlier than 3.5.5-3etch1' test_ref='oval:org.debian.oval:tst:2007'/>
                <criterion comment='kgamma DPKG is earlier than 3.5.5-3etch1' test_ref='oval:org.debian.oval:tst:2008'/>
                <criterion comment='libkscan1 DPKG is earlier than 3.5.5-3etch1' test_ref='oval:org.debian.oval:tst:2009'/>
                <criterion comment='kpovmodeler DPKG is earlier than 3.5.5-3etch1' test_ref='oval:org.debian.oval:tst:2010'/>
                <criterion comment='kooka DPKG is earlier than 3.5.5-3etch1' test_ref='oval:org.debian.oval:tst:2011'/>
                <criterion comment='kdegraphics-dev DPKG is earlier than 3.5.5-3etch1' test_ref='oval:org.debian.oval:tst:2012'/>
                <criterion comment='kghostview DPKG is earlier than 3.5.5-3etch1' test_ref='oval:org.debian.oval:tst:2013'/>
                <criterion comment='kfaxview DPKG is earlier than 3.5.5-3etch1' test_ref='oval:org.debian.oval:tst:2014'/>
                <criterion comment='kviewshell DPKG is earlier than 3.5.5-3etch1' test_ref='oval:org.debian.oval:tst:2015'/>
                <criterion comment='kview DPKG is earlier than 3.5.5-3etch1' test_ref='oval:org.debian.oval:tst:2016'/>
                <criterion comment='kfax DPKG is earlier than 3.5.5-3etch1' test_ref='oval:org.debian.oval:tst:2017'/>
                <criterion comment='ksnapshot DPKG is earlier than 3.5.5-3etch1' test_ref='oval:org.debian.oval:tst:2018'/>
                <criterion comment='kmrml DPKG is earlier than 3.5.5-3etch1' test_ref='oval:org.debian.oval:tst:2019'/>
                <criterion comment='kpdf DPKG is earlier than 3.5.5-3etch1' test_ref='oval:org.debian.oval:tst:2020'/>
                <criterion comment='kcoloredit DPKG is earlier than 3.5.5-3etch1' test_ref='oval:org.debian.oval:tst:2021'/>
                <criterion comment='kiconedit DPKG is earlier than 3.5.5-3etch1' test_ref='oval:org.debian.oval:tst:2022'/>
                <criterion comment='kruler DPKG is earlier than 3.5.5-3etch1' test_ref='oval:org.debian.oval:tst:2023'/>
                <criterion comment='kuickshow DPKG is earlier than 3.5.5-3etch1' test_ref='oval:org.debian.oval:tst:2024'/>
                <criterion comment='kdvi DPKG is earlier than 3.5.5-3etch1' test_ref='oval:org.debian.oval:tst:2025'/>
                <criterion comment='kdegraphics-dbg DPKG is earlier than 3.5.5-3etch1' test_ref='oval:org.debian.oval:tst:2026'/>
                <criterion comment='kolourpaint DPKG is earlier than 3.5.5-3etch1' test_ref='oval:org.debian.oval:tst:2027'/>
                <criterion comment='kamera DPKG is earlier than 3.5.5-3etch1' test_ref='oval:org.debian.oval:tst:2028'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment='Release section' operator='AND'>
          <criterion comment='Debian 3.1 is installed' test_ref='oval:org.debian.oval:tst:1'/>
          <criteria comment='Architecture section' operator='OR'>
            <criteria comment='Architecture independet section' operator='AND'>
              <criterion comment='all architecture' test_ref='oval:org.debian.oval:tst:2'/>
              <criterion comment='kdegraphics DPKG is earlier than 3.3.2-2sarge5' test_ref='oval:org.debian.oval:tst:2029'/>
            </criteria>
            <criteria comment='Architecture depended section' operator='AND'>
              <criteria comment='Supported architectures section' operator='OR'>
                <criterion comment='s390 architecture' test_ref='oval:org.debian.oval:tst:54'/>
                <criterion comment='amd64 architecture' test_ref='oval:org.debian.oval:tst:62'/>
                <criterion comment='sparc architecture' test_ref='oval:org.debian.oval:tst:53'/>
                <criterion comment='powerpc architecture' test_ref='oval:org.debian.oval:tst:56'/>
                <criterion comment='i386 architecture' test_ref='oval:org.debian.oval:tst:55'/>
                <criterion comment='mips architecture' test_ref='oval:org.debian.oval:tst:66'/>
                <criterion comment='ia64 architecture' test_ref='oval:org.debian.oval:tst:65'/>
                <criterion comment='alpha architecture' test_ref='oval:org.debian.oval:tst:94'/>
                <criterion comment='mipsel architecture' test_ref='oval:org.debian.oval:tst:67'/>
                <criterion comment='arm architecture' test_ref='oval:org.debian.oval:tst:64'/>
              </criteria>
              <criteria comment='Packages section' operator='OR'>
                <criterion comment='kdegraphics-kfile-plugins DPKG is earlier than 3.3.2-2sarge5' test_ref='oval:org.debian.oval:tst:2030'/>
                <criterion comment='ksvg DPKG is earlier than 3.3.2-2sarge5' test_ref='oval:org.debian.oval:tst:2031'/>
                <criterion comment='libkscan-dev DPKG is earlier than 3.3.2-2sarge5' test_ref='oval:org.debian.oval:tst:2032'/>
                <criterion comment='kgamma DPKG is earlier than 3.3.2-2sarge5' test_ref='oval:org.debian.oval:tst:2033'/>
                <criterion comment='libkscan1 DPKG is earlier than 3.3.2-2sarge5' test_ref='oval:org.debian.oval:tst:2034'/>
                <criterion comment='kpovmodeler DPKG is earlier than 3.3.2-2sarge5' test_ref='oval:org.debian.oval:tst:2035'/>
                <criterion comment='kooka DPKG is earlier than 3.3.2-2sarge5' test_ref='oval:org.debian.oval:tst:2036'/>
                <criterion comment='kdegraphics-dev DPKG is earlier than 3.3.2-2sarge5' test_ref='oval:org.debian.oval:tst:2037'/>
                <criterion comment='kghostview DPKG is earlier than 3.3.2-2sarge5' test_ref='oval:org.debian.oval:tst:2038'/>
                <criterion comment='kviewshell DPKG is earlier than 3.3.2-2sarge5' test_ref='oval:org.debian.oval:tst:2039'/>
                <criterion comment='kview DPKG is earlier than 3.3.2-2sarge5' test_ref='oval:org.debian.oval:tst:2040'/>
                <criterion comment='kfax DPKG is earlier than 3.3.2-2sarge5' test_ref='oval:org.debian.oval:tst:2041'/>
                <criterion comment='ksnapshot DPKG is earlier than 3.3.2-2sarge5' test_ref='oval:org.debian.oval:tst:2042'/>
                <criterion comment='kmrml DPKG is earlier than 3.3.2-2sarge5' test_ref='oval:org.debian.oval:tst:2043'/>
                <criterion comment='kpdf DPKG is earlier than 3.3.2-2sarge5' test_ref='oval:org.debian.oval:tst:2044'/>
                <criterion comment='kcoloredit DPKG is earlier than 3.3.2-2sarge5' test_ref='oval:org.debian.oval:tst:2045'/>
                <criterion comment='kiconedit DPKG is earlier than 3.3.2-2sarge5' test_ref='oval:org.debian.oval:tst:2046'/>
                <criterion comment='kruler DPKG is earlier than 3.3.2-2sarge5' test_ref='oval:org.debian.oval:tst:2047'/>
                <criterion comment='kuickshow DPKG is earlier than 3.3.2-2sarge5' test_ref='oval:org.debian.oval:tst:2048'/>
                <criterion comment='kdvi DPKG is earlier than 3.3.2-2sarge5' test_ref='oval:org.debian.oval:tst:2049'/>
                <criterion comment='kolourpaint DPKG is earlier than 3.3.2-2sarge5' test_ref='oval:org.debian.oval:tst:2050'/>
                <criterion comment='kamera DPKG is earlier than 3.3.2-2sarge5' test_ref='oval:org.debian.oval:tst:2051'/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version='1' id='oval:org.debian:def:1356' class='vulnerability'>
      <metadata>
        <title>several vulnerabilities</title>
        <affected family='unix'>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>linux-2.6</product>
        </affected>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1353' ref_id='CVE-2007-1353'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2172' ref_id='CVE-2007-2172'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2453' ref_id='CVE-2007-2453'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2525' ref_id='CVE-2007-2525'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2876' ref_id='CVE-2007-2876'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3513' ref_id='CVE-2007-3513'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3642' ref_id='CVE-2007-3642'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3848' ref_id='CVE-2007-3848'/>
        <reference source='CVE' ref_url='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3851' ref_id='CVE-2007-3851'/>
        <description>What information can i put there?</description>
        <debian>
          <date>2007-08-15</date>
          <moreinfo>

                 
Several local and remote vulnerabilities have been discovered in the Linux
kernel that may lead to a denial of service or the execution of arbitrary
code. The Common Vulnerabilities and Exposures project identifies the
following p